Ondato
Ondato provides a single compliance platform, marketed as an operating system for know your customer work, covering identity verification, business onboarding, anti money laundering screening, transaction monitoring, risk scoring, case management and age verification. It was founded in Vilnius in 2016 by Liudas Kanapienis, who remains chief executive, and Andrej Vistorskij, moved its headquarters to London while retaining research and development in Vilnius, and operates from the United Kingdom, Lithuania and Poland with more than three hundred clients.
Funding came through a pre seed round from an accelerator fund followed by seed and seed extension rounds led by OTB Ventures with LitCapital, totalling roughly six and a half million euros. Verification methods span document capture with an optical character recognition engine, biometric face matching, liveness detection, chip reading from electronic documents and matching against a database of individuals previously flagged for fraud. A separate product provides live video interaction between an agent and a customer for regulated onboarding where a face to face check is required, which distinguishes it from vendors offering only an application programming interface.
Buyers span digital banks, crowdfunding platforms, lenders, gaming operators, e-commerce and legal services, concentrated in the European Union. Prices are published per verification and by product on a public pricing page. Certification confirmed by the company itself covers information security management and presentation attack detection testing at both levels, alongside European electronic identification conformity certificates and stated adherence to the related technical standards.
Capability Axes
Capability grades
15 of 15 axes rated · 10 graded A or B
Models are load bearing for the verification layer and a substantial platform sits underneath them. Optical character recognition, biometric face matching, liveness detection, fraud database matching and automated risk scoring are all model driven, and the company states verifications complete in under thirty seconds without manual intervention.
But the product is positioned as a compliance operating system rather than a verification engine, and stripping the models leaves a real remainder: sanctions and watchlist screening by list matching, case management, configurable onboarding forms, electronic signature, audit trails and a live video branch product where a human agent conducts the check. That is a working compliance platform, which places this a grade below the pure proofing vendors in the same tier.
There is a real human channel and it is a product rather than an assurance. The live video branch conducts identity checks through direct interaction between an agent and the customer, described as combining live video with document checks and facial matching and offering either human or machine assisted validation, which is a named mechanism with a clear position in the flow. Case management and session video recording provide an audit surface a supervisor can work from.
What keeps this below the top grade is that the human channel is a separate high assurance product rather than oversight of the automated path, and the default path is explicitly described as completing without manual intervention. Nothing published sets an escalation rule, a confidence threshold, a review sampling rate, or a route by which a rejected person can have a decision reconsidered.
One qualifying property is clearly present: independent external measurement of the biometric layer through presentation attack detection testing at both level one and level two against the international standard, reinforced by European conformity certificates assessed against the related technical standards.
Against that, the headline accuracy claim of 99.8 percent across 192 countries is self reported, carries no published methodology, no test set description and no breakdown by document type or region, and a third party evaluator has publicly noted it is not independently audited. A single self reported accuracy figure is not error quantified in both directions and does not qualify on its own.
As with every other vendor in this tier, there is no model documentation, no validation summary, no drift monitoring description and no stated position on supporting a customer's own model validation.
Evidence exists and is weaker than the lane leaders in one specific respect: attribution. The company publishes customer testimonials with case study links, but the quotations located are attributed by description rather than by company name, appearing as a leading national crowdfunding platform or a fully digital bank for small and medium enterprises. Reported outcomes are similarly unquantified, describing simplified onboarding and reduced operational cost without figures.
Standing on a major software review platform is strong and independently generated. Independent certification bodies and a European testing institute have assessed the product, which is third party assurance with something at stake. The accuracy claim is self reported. A named customer with a quantified outcome would move this to the top grade and none was located.
The safety side is externally checked, with presentation attack detection testing at both levels covering the liveness layer and European conformity assessment of the remote authentication method. The stewardship side contains an arrangement that deserves naming: the platform matches a user's biometrics against a database of individuals previously flagged for fraud, in order to detect repeat attempts using the same face or fingerprint.
That is a shared negative biometric list operating across the customer base, a smaller relative of the consortium model, and it means a determination made in one institution's onboarding can follow a person into another's. Nothing public states who contributes to that database, what evidence threshold places a person on it, how long an entry persists, whether an entry can be challenged or removed, or whether the person is ever told.
Data protection alignment is stated and processing is described as taking place within the European Union, which suits the vendor's mainly European customer base, and infrastructure is described as continuously monitored. Beyond that the record is thin. There is no privacy management system certification, unlike a direct competitor in the same tier, so the privacy claim rests on assertion where the security claim rests on a certificate.
Independent evaluation notes that export and retention controls are not described in public detail. No retention period is published for identity documents, selfies, liveness video, session recordings or entries in the fraud database, no deletion process is described, and there is no service provider position under United States financial privacy law for a vendor that verifies social security numbers.
Certification is real and stated by the company on its own security and questions pages: information security management certification, presentation attack detection testing at both level one and level two against the international biometric standard, European electronic identification conformity certificates, stated adherence to the associated technical standards, and continuous infrastructure monitoring. That combination is well above the category norm.
It stops short of the top grade on documentation quality rather than on substance. The certification is cited to the superseded 2013 edition of the standard rather than the current one, no certificate number, issuing body, accreditation chain, scope statement or audit date is published, and there is no portal for requesting reports.
A caution is recorded here deliberately: third party review sites additionally credit this vendor with service organisation control, payment card industry and health privacy certifications, none of which appear in the company's own material, and one of those is not a certification that exists in the form claimed.
Ondato holds no financial licence, the expected posture for a technology supplier. Its regulatory footing rests on European electronic identification conformity certificates and stated conformance with the associated technical standards for identity proofing, which the company presents as what permits it to serve regulated businesses in the European Union, and this is a formal assessment of the product rather than a marketing claim.
Product material is written against the relevant European anti money laundering directive and the newer markets in crypto assets regime. It stops short of the top grade because no financial regulator has supervised or tested the decisioning, which is the standard set by CleverChain, and because the conformity claims are stated without certificate references a buyer could verify independently.
Fairness is the one dimension this vendor leaves entirely unaddressed, and the product shape makes that consequential. The published accuracy claim spans a very wide country range, which means it necessarily averages across document designs, print qualities, issuing authorities and capture conditions that are known to perform unevenly, yet no breakdown by document type, issuing country, device quality or skin tone accompanies it.
No bias testing methodology is published and no demographic analysis of verification or rejection rates exists. Presentation attack detection testing, which the vendor does hold at both levels, measures resistance to spoofing, which is a separate question from whether the system treats different populations alike.
The shared fraud database raises a second and unexamined fairness question, because a negative biometric list can concentrate on particular nationalities, document types or regions, and no assessment of that risk is offered.
Nothing published faces the person being verified. There is no accuracy guarantee, no remediation commitment, no stated appeal route for a rejected applicant, and no allocation of responsibility between the vendor supplying the verification result and the institution acting on it.
The fraud database sharpens the omission, because an individual placed on a shared negative biometric list can be refused across multiple institutions using the platform with no described mechanism to learn of the entry, contest it or have it removed. Session video recording produces an evidence trail, but it is generated for the institution's audit needs rather than as a record the affected person can access or rely on.
No base model, provider, version or externally sourced component is named for the optical character recognition engine, the face matching model, the liveness detection or the risk scoring. The technology is presented as the company's own without an explicit statement that nothing is externally sourced, so a buyer can neither verify a short supply chain nor identify a dependency.
There is no subprocessor list and no model or version identifier that an institution could record against a verification in order to establish later which system produced a decision. A third party description credits the age verification tooling as benchmarked against a national standards body, but the vendor's own material does not carry that claim and it is not clear whose models the benchmark would refer to, so it is not credited here.
Integration routes are broad and documented, covering a representational state transfer interface, mobile and web software development kits, low code and no code options, configurable webhooks, logic branching, workflow configuration and full interface customisation, with a hosted flow available for teams without engineering capacity. Chip reading from electronic identity documents is supported, which requires device level integration rather than a simple upload.
What holds this below the top grade is twofold: nothing published describes named integration into core banking, account opening or lending origination platforms, and independent review material repeatedly flags integration complexity as a recurring concern, which is a signal in the opposite direction from the vendor's own ease of setup claims.
Delivery is hosted software as a service through an interface, software development kits and a hosted flow, with data processing stated to occur in the European Union, which is a jurisdiction level statement rather than a residency commitment.
No hosting regions are enumerated, no in country residency option is offered or described, no data transfer mechanism is set out for customers outside the European Union despite verification coverage claimed across a very wide country range, and no subprocessor list is published. Independent evaluation of residency controls reaches the same conclusion. For a product that captures identity documents, facial biometrics and recorded video sessions, the absence of enumerated hosting detail is a substantive gap rather than a documentation one.
Well above the category norm and short of the best in the lane. A dedicated public pricing page states a per verification range for identity verification, a starting figure for business verification and a separate low starting rate for age verification, so a buyer can establish the unit of billing and a plausible band before contacting sales.
What is absent is the structure around those numbers: volume thresholds are not published, so the position within the range cannot be predicted, there is no self serve plan a customer can start or change alone, no free tier or trial terms are stated, and the enterprise tier resolves to a conversation. Nothing is published about whether failed or fraudulent verification attempts are billed, which is the single question that most affects the real cost of an identity product.
Coverage is genuine and mid sized rather than broad. More than three hundred clients are reported, verification is claimed across a very wide country range, and segments span digital banks, crowdfunding platforms, lenders, payment firms, gaming operators, e-commerce, legal services, insurance and public sector bodies, with the live video branch product aimed specifically at banks and law firms where a face to face check is a regulatory requirement.
The footprint is concentrated in the European Union with offices in three countries. It sits below the top grade because there is no evidence of deployment at large multinational financial institutions, the named institution types are small and mid sized regulated businesses, and segment material describes industries served rather than distinct institutional problems.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to Ondato
The closest documented capability profiles to Ondato in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Institution and Segment Coverage and Autonomy and Oversight Model
Stronger documented coverage on Operational and Outcome Evidence
A lighter documented profile than Ondato
Documents Model Supply Chain Disclosure where Ondato does not
A lighter documented profile than Ondato
Documents GLBA and Data Privacy Posture and Model Supply Chain Disclosure where Ondato does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.