AML, KYC & Financial Crime
I

Incode Technologies

Incode Technologies sells an end to end identity verification and biometric authentication platform to banks, credit unions, neobanks, fintechs and government agencies, covering document capture, facial matching, passive liveness, deepfake detection and database checks for customer identification and onboarding. Its distinguishing choice is building the entire model stack in house rather than assembling third party components, which lets it retrain against a specific fraud threat in days and puts its biometrics into independent government benchmarks under its own name.

Founded
Headquarters
San Francisco, California, United States
Website
www.incode.com
Categories
aml-kyc-financial-crime, fraud-and-transaction-risk
Assessment

Capability Axes

AI Capability
AI Centrality
A
Vendor Published

Incode builds its facial recognition, passive liveness, document authentication and deepfake detection models itself rather than reselling components, and makes that vertical integration the centre of its pitch, arguing that most competitors assemble third party parts and therefore cannot retrain quickly against a new attack.

It reports processing more than 4.1 billion identity checks a year against a proprietary set of more than 400 million identity profiles used to keep improving the models. Remove the models and nothing is left, which is the clearest possible pass of the removal test.

Autonomy and Oversight Model
C
Vendor Published

This is the weakest dimension of an otherwise well evidenced vendor, and the weakest oversight showing in the lane. The platform is marketed as fully automated end to end verification, which is an accurate description of the value proposition and also the whole of the public disclosure. Nothing describes a manual review queue, a case management surface, an escalation path for a borderline capture, or how a human adjudicator reopens a decision. A failed liveness or face match can cost an applicant a bank account, so the absence of a described review and appeal route is a substantive omission rather than a documentation quibble.

Model Risk Management and Transparency
B
Vendor Published

Owning the entire model stack is a structural advantage for a model risk reviewer, because Incode can answer questions about training, architecture and retraining without deferring to suppliers, and it states retraining against a specific threat takes days. External measurement exists through the government biometric evaluations and the laboratory attack detection certification, which is more than most peers can point to.

The formal package is still absent: no model documentation, no validation summary, no drift monitoring description and no stated position on supporting a customer's own validation under supervisory model risk guidance.

Operational and Outcome Evidence
A
Vendor Published

The evidence is of a better type than the category norm because much of it comes from adversarial third party testing rather than customer testimonial. Incode submits its biometrics to the National Institute of Standards and Technology face recognition evaluations and cites top tier placement with a 99 percent success rate, holds iBeta passive liveness certification at both level one and level two, and states it was the first company in the world to pass level one for passive liveness.

It has been named a leader in the Gartner Magic Quadrant for identity verification in two consecutive years. Third party compilations report deployment at nine of the ten largest United States banks. One honest wrinkle: Incode's own frequently asked questions page advises readers not to cite specific award names or rankings without verifying currency, which is unusual candour about the shelf life of its own claims.

AI Safety and Data Stewardship
B
Vendor Published

Independent validation of safety relevant performance is genuinely strong. Passive liveness is certified by an accredited laboratory at both level one and level two against the international presentation attack detection standard, deepfake analysis and synthetic identity signals are named capabilities, and owning the full stack means a threat specific retrain takes days rather than waiting on a supplier. The stewardship gap sits in the data flywheel.

The proprietary set of more than 400 million identity profiles is described as accumulating from checks run across the customer base and feeding continuous model improvement, and nothing public states whether one institution's biometric data improves models serving another, whether a customer can decline that use, or how long profiles persist.

Regulatory and Compliance
GLBA and Data Privacy Posture
C
Vendor Published

Privacy preservation is a stated design goal, with an architecture described as processing biometric data without storing it on customer owned infrastructure and marketing that emphasises minimising data exposure. That is the right instinct, and it is not backed by public documentation a bank privacy office could review.

The specific gap for a biometrics vendor operating at United States scale is state biometric privacy law, where Illinois, Texas and Washington impose distinct consent, retention and destruction duties and Illinois carries a private right of action. Nothing public addresses that regime, nor the Gramm Leach Bliley service provider position, nor retention terms for the identity profile set.

Security Certifications and Trust Center
C
Vendor Published

Security disclosure amounts to a single line repeated in the site footer stating service organisation control type two certification and 256 bit transport encryption, alongside the accredited laboratory attack detection certifications which are performance rather than security attestations. There is no trust centre, no certifications page, no scope statement and no audit period.

Information security management certification and European data protection alignment appear only in third party compilations rather than on the vendor's own site. Incode's own frequently asked questions page tells readers to verify current certifications directly with the company, which is a fair warning and also a concession that the public record cannot be relied on.

Regulatory Status and Licensure
B
Vendor Published

Incode is a technology supplier holding no financial licence, the expected posture in this category. Product material is written directly against customer identification programme, know your customer and anti money laundering obligations with government sourced verification, and developer documentation covers embedding into core banking, digital account opening and lending origination systems where those duties bite.

Deployment into federal and state agencies and border management implies passage through public procurement vetting, though no specific named authorisation is published, so this rests on footprint rather than on a citable admission.

AI Governance and Bias Disclosure
B
Vendor Published

Submitting biometrics to the National Institute of Standards and Technology evaluations is the most meaningful bias related step available in this field, because those evaluations measure demographic differentials by design and publish results the vendor does not control. That places Incode ahead of peers whose fairness position rests on marketing copy.

It stops short of the top grade because Incode surfaces only a headline accuracy figure rather than the demographic breakdown its own submissions generate, publishes no bias testing methodology of its own, and offers no analysis of how error rates vary across the more than 200 countries where document quality and capture conditions differ sharply.

Integration and Deployment
Core Systems and Integration Depth
B
Vendor Published

Public developer documentation is specific about financial services rather than generic, with dedicated guidance for embedding verification into core banking platforms, digital account opening flows and lending origination systems so an applicant never leaves the institution's own experience. Modular interfaces cover document checks, biometrics, fraud signals and compliance workflow, and integrations exist inside partner decisioning platforms.

What is not evident is the surrounding operational transparency the strongest vendors in this lane publish, with no public service status page, no changelog and no named partner directory of comparable breadth.

Deployment Model and Data Residency
C
Vendor Published

Delivery is cloud hosted software as a service operating across more than 200 countries. The one substantive residency relevant claim is architectural, that biometric data is processed without being stored on customer owned infrastructure, which the company frames as simplifying global compliance.

Beyond that, hosting regions, in country residency options, data transfer mechanisms and the subprocessor footprint are not enumerated anywhere public, which is a meaningful omission for a vendor handling biometric identifiers across jurisdictions with sharply different rules.

Commercial
Commercial Transparency
C
Vendor Published

Sales run through an enterprise motion with no published rates, tiers, minimums or trial path, and every route on the site terminates in a contact form. The company describes its model as enterprise business to business and states it does not sell to individuals. Nothing indicates a self serve or transparently priced entry point, so a buyer cannot size a deal without entering a sales process.

Institution and Segment Coverage
A
Vendor Published

Financial services coverage is broken out across banking, credit unions, neobanks, fintechs, loans and payments, crypto, insurance and investment, each addressed as a distinct onboarding problem rather than a single vertical page. Both remote and in person onboarding are supported, which matters for branch based institutions that most digital first vendors cannot serve. Reach is reported across more than 200 countries, and the platform extends beyond finance into government including border management, healthcare, gaming and telecommunications.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

AI FinTech Index

An independent reference for evaluating AI vendors in financial services. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 8, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746