Microblink
Microblink builds computer vision and biometric models for identity document capture, authentication and verification, sold to banks, lenders, fintechs and payment providers as software development kits and as a hosted platform. Its product line covers BlinkID for document capture and data extraction, BlinkID Verify for automated document authentication, BlinkCard for payment card capture, and the Microblink Platform, which adds biometric matching, liveness, watchlist screening and a configurable Decision Command Center for know your customer and anti money laundering workflows.
The company reports more than twelve billion documents processed, support for over two thousand five hundred document types from more than one hundred and fifty countries, and more than four hundred and fifty customers. Capture runs on the device through eighteen client side machine learning models, which removes network dependency from the capture step.
Named financial services deployments include First Abu Dhabi Bank for identity scanning during know your customer verification and Banco Azteca for account opening and loan applications across multiple mobile applications, alongside an automotive lending platform in Mexico reporting a ninety eight percent verification success rate. In a March 2026 evaluation run by the United States Department of Homeland Security Science and Technology Directorate at the Maryland Test Facility, Microblink was the only one of seven tested document validation systems to meet high performing benchmarks on every measured accuracy metric. The company was founded in Croatia and is headquartered in New York, with research and development in Zagreb.
Capability Axes
Capability grades
15 of 15 axes rated · 10 graded A or B
The product is the models. Document capture runs eighteen client side machine learning models that harmonise to select the sharpest usable frame without a fixed bounding box, and document authentication, biometric matching and liveness are all model driven. The company states it develops its artificial intelligence in house using proprietary data and a dedicated machine learning team, and that it owns and builds the whole stack in order to guarantee performance.
Twelve years of computer vision research sits behind the software development kits. Remove the models and there is no product at all, not a reduced one, which is the cleanest possible pass of the removal test and places Microblink with Incode at the top of this axis.
Better than the closest peer and short of the top grade. Microblink names a buyer operated control surface, a Decision Command Center providing policy controls over identity workflows, and states that the certainty and threshold for each individual security check can be tuned by the customer. That is a named mechanism sitting before the decision rather than an assertion that governance exists, and it means the institution rather than the vendor sets the operating point.
What is still missing is the half that protects the applicant: nothing describes a manual review queue, a case management surface, an escalation route for a borderline capture, or how a human adjudicator reopens an automated rejection. The published false reject rate makes that omission concrete rather than theoretical.
This is the strongest showing on this axis anywhere in the index and it still stops at the same gate as its closest peer. A March 2026 evaluation by the United States Department of Homeland Security Science and Technology Directorate, run at the Maryland Test Facility using genuine and fraudulent government issued documents, produced published figures in both directions: a zero percent system error rate, a three point one five percent document false reject rate and a zero point eight eight percent document false accept rate, against a ten percent threshold for a high performing system.
Microblink was the only one of seven vendors to stay inside the threshold on every metric and the only one to hold both the fraud and the friction side simultaneously. That satisfies independent external measurement and error quantified in both directions, two separate qualifying properties.
It is held at the middle grade for the same reason as Incode, because the formal package is absent: no model documentation, no validation summary, no drift monitoring description, and no stated position on supporting a buyer's own validation under supervisory model risk guidance. The gate for the top grade on this axis is now clearly visible and it is not external testing, it is whether the vendor helps the institution validate the model itself.
This clears the bar on both routes at once. Named customers carry quantified outcomes, including an automotive lending platform in Mexico reporting a ninety eight percent verification success rate and a stated ninety four percent first time success rate on document verification.
More importantly the evidence includes an independent party with nothing to gain: a United States government evaluation conducted at an accredited test facility, in which the vendor was assessed under an anonymised identifier alongside six competitors. Volume claims are also unusually specific at more than twelve billion documents processed. The combination of a blind third party assessment and named institutional customers with figures is the strongest evidence profile seen in this sweep.
The safety side is well developed and independently recognised. The company runs a dedicated fraud laboratory that simulates emerging generative fraud before it appears in the wild, for which it has received an industry award, and it ships deepfake, synthetic identity and injection attack detection alongside liveness. Owning the full model stack means a threat specific retrain does not wait on a supplier. The stewardship half is the gap, and it is the same one recorded against Incode.
The company states it trains on proprietary data while processing more than twelve billion documents on behalf of customers, and nothing public states whether documents captured for one institution improve models serving another, whether a customer can decline that use, or how long captured identity data persists.
A dedicated security and privacy page and published material on privacy information management standards put Microblink ahead of most peers in this lane on presentation, and the product includes data validation and anonymisation as named capabilities. On device capture is also a real privacy reducing architecture rather than a claim. The substance a bank privacy office would need is still not there.
The specific gap for any biometric vendor operating at United States scale is state biometric privacy law, where Illinois, Texas and Washington impose distinct consent, retention and destruction duties and Illinois carries a private right of action. Nothing public addresses that regime, the service provider position under United States financial privacy law, or retention terms for captured identity documents and biometric templates.
Considerably better than the lane norm and clearly documented. Information security management certification was issued by a named independent certification body, with a stated scope covering development, integration, support, sale and service management of computer vision technology and explicitly encompassing both the United States and Croatian offices, which is a real scope statement rather than a badge.
The company also states it conducts regular service organisation control type two audits under the relevant attestation standards, and it names a head of information security. A dedicated security and privacy page carries all of this.
Short of the top grade because the certification version cited publicly is the superseded edition from an award dated 2021 with no current certificate or audit period published, there is no trust centre where a buyer can request the attestation reports, and no subprocessor list.
Microblink is a technology supplier holding no financial licence, which is the expected and appropriate posture for this category. Product material is written directly against customer identification, know your customer and anti money laundering obligations, with the platform described as combining document, data and watchlist checks specifically to meet those duties, and separate material addresses age verification duties.
The company also submitted its technology to a United States federal government evaluation programme, which is a government assessment of the product itself rather than a marketing claim. It stops short of the top grade because that was a technology evaluation and not a supervised live test by a financial regulator, and because no named authorisation, registration or regulator engagement is published.
The distinction that decides this grade is worth stating plainly, because the vendor's strong external testing invites the wrong conclusion. External measurement of accuracy is not external measurement of fairness. The government evaluation tested document validation against genuine and fraudulent identity documents, not demographic differentials in performance, which is a different question requiring a different test.
Incode reaches the middle grade on this axis because it submits face recognition to evaluations that measure demographic differentials by design. Nothing located shows Microblink publishing a demographic breakdown, a bias testing methodology, or any analysis of how error rates vary across the more than one hundred and fifty countries whose documents it reads, where document design, print quality and capture conditions differ sharply. A three point one five percent false reject rate is an average, and an average conceals exactly the variation this axis exists to surface.
Publishing an error rate does something no other vendor in this index has done: it converts an abstract recourse gap into a countable population. A three point one five percent document false reject rate means roughly one in thirty two legitimate applicants is wrongly rejected, and at the volumes this vendor reports that is a large number of real people refused an account or a loan by a model. Nothing public describes what happens to any of them.
There is no accuracy guarantee, no remediation commitment, no stated appeal route, and no allocation of responsibility between the vendor supplying the decision and the institution acting on it. The transparency is genuine and it is pointed at the buyer, not at the person the decision lands on.
Microblink makes vertical integration an explicit selling point, stating that it owns and builds its stack so that it can guarantee performance, and that it develops its artificial intelligence in house with proprietary data and its own machine learning specialists rather than assembling third party components. For a buyer that means a short chain with a single accountable party, and the government evaluation partly corroborates the claim because the tested system is the vendor's own.
This is the pattern already recorded across the index: building in house produces a strong ownership claim and a weak disclosure. What is missing is the explicit statement, with no subprocessor list, no confirmation that no component is externally sourced, and no model or version identifier a bank could record against a decision.
Integration is a stated strength and the claims are specific rather than generic: clean application programming interfaces, lightweight software development kits, low latency, streamlined documentation, and most customers completing a first verification inside a day with a dedicated technical project manager assigned from the outset.
A customer quote describes deploying the same component across multiple mobile applications and several distinct use cases including account opening and loan applications. On device execution reduces the integration surface further. It falls short of the top grade because the published material describes ease of embedding rather than named depth into core banking, origination or decisioning platforms, and no partner directory, public service status page or changelog was located.
The strongest version of this grade rather than an empty one. There is a genuine architectural fact here: capture and initial processing run on the end user device through client side models, which the company frames as removing network dependency from the critical step, and it claims global infrastructure that respects data sovereignty. The information security certificate scope names operations in two countries.
But the server side is where the residency question actually bites, since document authentication, biometric matching and watchlist screening run in the platform, and no hosting regions, in country residency options, data transfer mechanisms or subprocessor footprint are enumerated anywhere public. For a vendor processing identity documents and biometric identifiers across more than one hundred and fifty jurisdictions, an assurance about sovereignty is not a residency commitment.
Sales run through an enterprise motion. No rates, tiers, volume bands, minimum commitments or published trial terms were located, and every route on the site terminates in a demo request or a contact form. Free trial access to the software development kits is offered for evaluation, which helps a developer assess fit but does not let a buyer size a contract. Pricing for a document capture product is normally per verification, and nothing public indicates the unit or the band.
Financial services is described by a third party evaluator as the most developed vertical with the most concrete customer evidence, and the vendor runs dedicated service pages for bank identity verification and for biometric authentication in regulated financial onboarding. Named institutions span a large Gulf bank, a Mexican retail bank covering both account opening and lending, and an automotive lending platform.
Reach is wide, with more than four hundred and fifty customers and documents from over one hundred and fifty countries. It sits below the top grade because the financial services segmentation is not broken out by institution type the way the strongest vendors in this lane do, and because a material part of the business sits outside finance entirely, including receipt capture for retail and consumer data and identity scanning for digital notarisation.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Microblink
The closest documented capability profiles to Microblink in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than Microblink
Documents GLBA and Data Privacy Posture where Microblink does not
Stronger documented coverage on Institution and Segment Coverage
Stronger documented coverage on Institution and Segment Coverage
A lighter documented profile than Microblink
Documents AI Governance and Bias Disclosure where Microblink does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.