AML, KYC & Financial Crime
I

Incode Technologies

Incode Technologies sells an end to end identity verification and biometric authentication platform to banks, credit unions, neobanks, fintechs and government agencies, covering document capture, facial matching, passive liveness, deepfake detection and database checks for customer identification and onboarding. Its distinguishing choice is building the entire model stack in house rather than assembling third party components, which lets it retrain against a specific fraud threat in days and puts its biometrics into independent government benchmarks under its own name.

In June 2024 it acquired MetaMap, an identity verification and trust orchestration platform that had raised more than eighty four million dollars in primary equity, and which continues to operate as a named product line with its own published service status reporting. MetaMap is built on a different principle from the in house stack described above, chaining configurable verification steps across government registries, financial records and biometric checks, and it brings a deep bench of Latin American and African government database connections spanning Mexican, Colombian, Argentine, Nigerian, Kenyan and Ugandan national registries.

Last VerifiedAugust 20, 2026
Compare Incode Technologies with other vendors
Founded
Headquarters
San Francisco, California, United States
Website
www.incode.com
Categories
aml-kyc-financial-crime, fraud-and-transaction-risk
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 9 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

Incode builds its facial recognition, passive liveness, document authentication and deepfake detection models itself rather than reselling components, and makes that vertical integration the centre of its pitch, arguing that most competitors assemble third party parts and therefore cannot retrain quickly against a new attack.

It reports processing more than 4.1 billion identity checks a year against a proprietary set of more than 400 million identity profiles used to keep improving the models. Remove the models and nothing is left, which is the clearest possible pass of the removal test.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

This is the weakest dimension of an otherwise well evidenced vendor, and the weakest oversight showing in the lane. The platform is marketed as fully automated end to end verification, which is an accurate description of the value proposition and also the whole of the public disclosure. Nothing describes a manual review queue, a case management surface, an escalation path for a borderline capture, or how a human adjudicator reopens a decision. A failed liveness or face match can cost an applicant a bank account, so the absence of a described review and appeal route is a substantive omission rather than a documentation quibble.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

Owning the entire model stack is a structural advantage for a model risk reviewer, because Incode can answer questions about training, architecture and retraining without deferring to suppliers, and it states retraining against a specific threat takes days. External measurement exists through the government biometric evaluations and the laboratory attack detection certification, which is more than most peers can point to.

The formal package is still absent: no model documentation, no validation summary, no drift monitoring description and no stated position on supporting a customer's own validation under supervisory model risk guidance.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

The evidence is of a better type than the category norm because much of it comes from adversarial third party testing rather than customer testimonial. Incode submits its biometrics to the National Institute of Standards and Technology face recognition evaluations and cites top tier placement with a 99 percent success rate, holds iBeta passive liveness certification at both level one and level two, and states it was the first company in the world to pass level one for passive liveness.

It has been named a leader in the Gartner Magic Quadrant for identity verification in two consecutive years. Third party compilations report deployment at nine of the ten largest United States banks. One honest wrinkle: Incode's own frequently asked questions page advises readers not to cite specific award names or rankings without verifying currency, which is unusual candour about the shelf life of its own claims.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

Independent validation of safety relevant performance is genuinely strong. Passive liveness is certified by an accredited laboratory at both level one and level two against the international presentation attack detection standard, deepfake analysis and synthetic identity signals are named capabilities, and owning the full stack means a threat specific retrain takes days rather than waiting on a supplier. The stewardship gap sits in the data flywheel.

The proprietary set of more than 400 million identity profiles is described as accumulating from checks run across the customer base and feeding continuous model improvement, and nothing public states whether one institution's biometric data improves models serving another, whether a customer can decline that use, or how long profiles persist.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

Privacy preservation is a stated design goal, with an architecture described as processing biometric data without storing it on customer owned infrastructure and marketing that emphasises minimising data exposure. That is the right instinct, and it is not backed by public documentation a bank privacy office could review.

The specific gap for a biometrics vendor operating at United States scale is state biometric privacy law, where Illinois, Texas and Washington impose distinct consent, retention and destruction duties and Illinois carries a private right of action. Nothing public addresses that regime, nor the Gramm Leach Bliley service provider position, nor retention terms for the identity profile set.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

Security disclosure amounts to a single line repeated in the site footer stating service organisation control type two certification and 256 bit transport encryption, alongside the accredited laboratory attack detection certifications which are performance rather than security attestations. There is no trust centre, no certifications page, no scope statement and no audit period.

Information security management certification and European data protection alignment appear only in third party compilations rather than on the vendor's own site. Incode's own frequently asked questions page tells readers to verify current certifications directly with the company, which is a fair warning and also a concession that the public record cannot be relied on.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

Incode is a technology supplier holding no financial licence, the expected posture in this category. Product material is written directly against customer identification programme, know your customer and anti money laundering obligations with government sourced verification, and developer documentation covers embedding into core banking, digital account opening and lending origination systems where those duties bite.

Deployment into federal and state agencies and border management implies passage through public procurement vetting, though no specific named authorisation is published, so this rests on footprint rather than on a citable admission.

AI Governance and Bias Disclosure
BB on AI Governance and Bias DisclosureAn independent demographic evaluation the vendor has submitted to, such as the NIST face evaluation class, or a governance framework with named process behind it.
Vendor Published

Submitting biometrics to the National Institute of Standards and Technology evaluations is the most meaningful bias related step available in this field, because those evaluations measure demographic differentials by design and publish results the vendor does not control. That places Incode ahead of peers whose fairness position rests on marketing copy.

It stops short of the top grade because Incode surfaces only a headline accuracy figure rather than the demographic breakdown its own submissions generate, publishes no bias testing methodology of its own, and offers no analysis of how error rates vary across the more than 200 countries where document quality and capture conditions differ sharply.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

Submitting biometrics to independent government evaluation is a form of accountability most competitors avoid, since the results are published by a party Incode does not control and can be cited against it. That is verification, not recourse. No accuracy guarantee, no remediation commitment, and no described appeal path for an applicant whose face match or liveness check fails, which is the gap that matters given the product is marketed as fully automated end to end.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

Incode makes supply chain a selling point rather than a disclosure obligation, stating that it builds facial recognition, liveness, document authentication and deepfake detection in house and arguing that competitors assembling third party components cannot retrain quickly against new attacks. For a buyer that means an unusually short chain with one accountable party, and it is a claim the government evaluation submissions partly corroborate. What is still missing is the explicit statement: no subprocessor list, and no confirmation that nothing is externally sourced.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Public developer documentation is specific about financial services rather than generic, with dedicated guidance for embedding verification into core banking platforms, digital account opening flows and lending origination systems so an applicant never leaves the institution's own experience. Modular interfaces cover document checks, biometrics, fraud signals and compliance workflow, and integrations exist inside partner decisioning platforms.

What is not evident is the surrounding operational transparency the strongest vendors in this lane publish, with no public service status page, no changelog and no named partner directory of comparable breadth.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Delivery is cloud hosted software as a service operating across more than 200 countries. The one substantive residency relevant claim is architectural, that biometric data is processed without being stored on customer owned infrastructure, which the company frames as simplifying global compliance.

Beyond that, hosting regions, in country residency options, data transfer mechanisms and the subprocessor footprint are not enumerated anywhere public, which is a meaningful omission for a vendor handling biometric identifiers across jurisdictions with sharply different rules.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

Sales run through an enterprise motion with no published rates, tiers, minimums or trial path, and every route on the site terminates in a contact form. The company describes its model as enterprise business to business and states it does not sell to individuals. Nothing indicates a self serve or transparently priced entry point, so a buyer cannot size a deal without entering a sales process.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

Financial services coverage is broken out across banking, credit unions, neobanks, fintechs, loans and payments, crypto, insurance and investment, each addressed as a distinct onboarding problem rather than a single vertical page. Both remote and in person onboarding are supported, which matters for branch based institutions that most digital first vendors cannot serve. Reach is reported across more than 200 countries, and the platform extends beyond finance into government including border management, healthcare, gaming and telecommunications.

Tracked Since Listing

What Changed

Material product, regulatory, evidence and commercial changes at Incode Technologies, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.

Sep 14, 2026Product / capabilityPartially verified

Incode's platform release, deployed to its Demo environment on 14 September, adds eKYC data sources for the United Kingdom, the Netherlands and Finland. The same release removes a deprecated identity search endpoint, which now returns an error.

Bears on: Institution and Segment CoverageSource
Sep 7, 2026Product / capability

Incode's September platform release adds two direct eKYC data sources in Latin America, Civil Register 2 for Mexico and Credit Bureau 1 for Argentina. The release also introduces a Greenhouse integration for identity verification and business verification flows, adds nationality as a prefill source, and updates the issue selection picker used in manual review.

Bears on: Institution and Segment CoverageSource
Our read on these changes →Tracked since Sep 2026
Head to Head

Compared With

Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Alternatives to Incode Technologies

The closest documented capability profiles to Incode Technologies in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Stronger documented coverage on Regulatory Status and Licensure

Documents Autonomy and Oversight Model where Incode Technologies does not

Documents Autonomy and Oversight Model where Incode Technologies does not

Documents Autonomy and Oversight Model where Incode Technologies does not

Documents Security Certifications and Trust Center where Incode Technologies does not

Documents Autonomy and Oversight Model and Security Certifications and Trust Center where Incode Technologies does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 549 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 21, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746