Incode Technologies
Incode Technologies sells an end to end identity verification and biometric authentication platform to banks, credit unions, neobanks, fintechs and government agencies, covering document capture, facial matching, passive liveness, deepfake detection and database checks for customer identification and onboarding. Its distinguishing choice is building the entire model stack in house rather than assembling third party components, which lets it retrain against a specific fraud threat in days and puts its biometrics into independent government benchmarks under its own name.
In June 2024 it acquired MetaMap, an identity verification and trust orchestration platform that had raised more than eighty four million dollars in primary equity, and which continues to operate as a named product line with its own published service status reporting. MetaMap is built on a different principle from the in house stack described above, chaining configurable verification steps across government registries, financial records and biometric checks, and it brings a deep bench of Latin American and African government database connections spanning Mexican, Colombian, Argentine, Nigerian, Kenyan and Ugandan national registries.
Capability Axes
Capability grades
15 of 15 axes rated · 9 graded A or B
Incode builds its facial recognition, passive liveness, document authentication and deepfake detection models itself rather than reselling components, and makes that vertical integration the centre of its pitch, arguing that most competitors assemble third party parts and therefore cannot retrain quickly against a new attack.
It reports processing more than 4.1 billion identity checks a year against a proprietary set of more than 400 million identity profiles used to keep improving the models. Remove the models and nothing is left, which is the clearest possible pass of the removal test.
This is the weakest dimension of an otherwise well evidenced vendor, and the weakest oversight showing in the lane. The platform is marketed as fully automated end to end verification, which is an accurate description of the value proposition and also the whole of the public disclosure. Nothing describes a manual review queue, a case management surface, an escalation path for a borderline capture, or how a human adjudicator reopens a decision. A failed liveness or face match can cost an applicant a bank account, so the absence of a described review and appeal route is a substantive omission rather than a documentation quibble.
Owning the entire model stack is a structural advantage for a model risk reviewer, because Incode can answer questions about training, architecture and retraining without deferring to suppliers, and it states retraining against a specific threat takes days. External measurement exists through the government biometric evaluations and the laboratory attack detection certification, which is more than most peers can point to.
The formal package is still absent: no model documentation, no validation summary, no drift monitoring description and no stated position on supporting a customer's own validation under supervisory model risk guidance.
The evidence is of a better type than the category norm because much of it comes from adversarial third party testing rather than customer testimonial. Incode submits its biometrics to the National Institute of Standards and Technology face recognition evaluations and cites top tier placement with a 99 percent success rate, holds iBeta passive liveness certification at both level one and level two, and states it was the first company in the world to pass level one for passive liveness.
It has been named a leader in the Gartner Magic Quadrant for identity verification in two consecutive years. Third party compilations report deployment at nine of the ten largest United States banks. One honest wrinkle: Incode's own frequently asked questions page advises readers not to cite specific award names or rankings without verifying currency, which is unusual candour about the shelf life of its own claims.
Independent validation of safety relevant performance is genuinely strong. Passive liveness is certified by an accredited laboratory at both level one and level two against the international presentation attack detection standard, deepfake analysis and synthetic identity signals are named capabilities, and owning the full stack means a threat specific retrain takes days rather than waiting on a supplier. The stewardship gap sits in the data flywheel.
The proprietary set of more than 400 million identity profiles is described as accumulating from checks run across the customer base and feeding continuous model improvement, and nothing public states whether one institution's biometric data improves models serving another, whether a customer can decline that use, or how long profiles persist.
Privacy preservation is a stated design goal, with an architecture described as processing biometric data without storing it on customer owned infrastructure and marketing that emphasises minimising data exposure. That is the right instinct, and it is not backed by public documentation a bank privacy office could review.
The specific gap for a biometrics vendor operating at United States scale is state biometric privacy law, where Illinois, Texas and Washington impose distinct consent, retention and destruction duties and Illinois carries a private right of action. Nothing public addresses that regime, nor the Gramm Leach Bliley service provider position, nor retention terms for the identity profile set.
Security disclosure amounts to a single line repeated in the site footer stating service organisation control type two certification and 256 bit transport encryption, alongside the accredited laboratory attack detection certifications which are performance rather than security attestations. There is no trust centre, no certifications page, no scope statement and no audit period.
Information security management certification and European data protection alignment appear only in third party compilations rather than on the vendor's own site. Incode's own frequently asked questions page tells readers to verify current certifications directly with the company, which is a fair warning and also a concession that the public record cannot be relied on.
Incode is a technology supplier holding no financial licence, the expected posture in this category. Product material is written directly against customer identification programme, know your customer and anti money laundering obligations with government sourced verification, and developer documentation covers embedding into core banking, digital account opening and lending origination systems where those duties bite.
Deployment into federal and state agencies and border management implies passage through public procurement vetting, though no specific named authorisation is published, so this rests on footprint rather than on a citable admission.
Submitting biometrics to the National Institute of Standards and Technology evaluations is the most meaningful bias related step available in this field, because those evaluations measure demographic differentials by design and publish results the vendor does not control. That places Incode ahead of peers whose fairness position rests on marketing copy.
It stops short of the top grade because Incode surfaces only a headline accuracy figure rather than the demographic breakdown its own submissions generate, publishes no bias testing methodology of its own, and offers no analysis of how error rates vary across the more than 200 countries where document quality and capture conditions differ sharply.
Submitting biometrics to independent government evaluation is a form of accountability most competitors avoid, since the results are published by a party Incode does not control and can be cited against it. That is verification, not recourse. No accuracy guarantee, no remediation commitment, and no described appeal path for an applicant whose face match or liveness check fails, which is the gap that matters given the product is marketed as fully automated end to end.
Incode makes supply chain a selling point rather than a disclosure obligation, stating that it builds facial recognition, liveness, document authentication and deepfake detection in house and arguing that competitors assembling third party components cannot retrain quickly against new attacks. For a buyer that means an unusually short chain with one accountable party, and it is a claim the government evaluation submissions partly corroborate. What is still missing is the explicit statement: no subprocessor list, and no confirmation that nothing is externally sourced.
Public developer documentation is specific about financial services rather than generic, with dedicated guidance for embedding verification into core banking platforms, digital account opening flows and lending origination systems so an applicant never leaves the institution's own experience. Modular interfaces cover document checks, biometrics, fraud signals and compliance workflow, and integrations exist inside partner decisioning platforms.
What is not evident is the surrounding operational transparency the strongest vendors in this lane publish, with no public service status page, no changelog and no named partner directory of comparable breadth.
Delivery is cloud hosted software as a service operating across more than 200 countries. The one substantive residency relevant claim is architectural, that biometric data is processed without being stored on customer owned infrastructure, which the company frames as simplifying global compliance.
Beyond that, hosting regions, in country residency options, data transfer mechanisms and the subprocessor footprint are not enumerated anywhere public, which is a meaningful omission for a vendor handling biometric identifiers across jurisdictions with sharply different rules.
Sales run through an enterprise motion with no published rates, tiers, minimums or trial path, and every route on the site terminates in a contact form. The company describes its model as enterprise business to business and states it does not sell to individuals. Nothing indicates a self serve or transparently priced entry point, so a buyer cannot size a deal without entering a sales process.
Financial services coverage is broken out across banking, credit unions, neobanks, fintechs, loans and payments, crypto, insurance and investment, each addressed as a distinct onboarding problem rather than a single vertical page. Both remote and in person onboarding are supported, which matters for branch based institutions that most digital first vendors cannot serve. Reach is reported across more than 200 countries, and the platform extends beyond finance into government including border management, healthcare, gaming and telecommunications.
What Changed
Material product, regulatory, evidence and commercial changes at Incode Technologies, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
Incode's platform release, deployed to its Demo environment on 14 September, adds eKYC data sources for the United Kingdom, the Netherlands and Finland. The same release removes a deprecated identity search endpoint, which now returns an error.
Incode's September platform release adds two direct eKYC data sources in Latin America, Civil Register 2 for Mexico and Credit Bureau 1 for Argentina. The release also introduces a Greenhouse integration for identity verification and business verification flows, adds nationality as a prefill source, and updates the issue selection picker used in manual review.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Incode Technologies
The closest documented capability profiles to Incode Technologies in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Regulatory Status and Licensure
Documents Autonomy and Oversight Model where Incode Technologies does not
Documents Autonomy and Oversight Model where Incode Technologies does not
Documents Autonomy and Oversight Model where Incode Technologies does not
Documents Security Certifications and Trust Center where Incode Technologies does not
Documents Autonomy and Oversight Model and Security Certifications and Trust Center where Incode Technologies does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.