AML, KYC & Financial Crime
P

Prove

Prove verifies people through the phone rather than through a document and a selfie, and that choice is the whole architecture. The premise is that a mobile number held in someone's name for years, tied to a SIM in a device they physically possess, is a harder credential to forge than an image, because defeating it requires buying a phone in the victim's name, paying for it over time and mimicking their usage. The company's chief executive states the position directly, arguing that a model can fabricate a face or clone a voice but cannot replicate a decade of real behaviour, and describes the approach as deterministic identity.

Underneath sits the Prove Identity Graph, a registry the company puts at more than a billion privacy preserving identity tokens covering roughly 90 percent of digitally active adults across 227 countries, fed by telecom signals, bank and public records and over a decade of proprietary data, and processing more than 30 billion verification events a year. Signals are orchestrated by the Prove Global Fraud Policy, an internal defence engine that combines possession, ownership, SIM and device trust, identity matching, address intelligence and mobile network analysis into a single pass or fail outcome. The name is easily misread: it is a policy engine, not an insurance policy.

The financial lines are separately built products rather than a vertical page, which is why they are what this record grades. Pre Fill populates an application from verified data and bundles sanctions, watchlist and politically exposed person screening at no additional charge. Account Opening activates a bank account from a name and phone number. Unified Authentication replaces one time passcode flows. Know Your Payee verifies a payment recipient before funds move. An agentic suite verifies AI agents and binds signed consent into a token that travels with each agent action. Healthcare, gaming and marketplace lines are sold from the same graph and are excluded here.

Distribution runs through banking infrastructure: a cloud marketplace listing, a core banking exchange, and partnerships with digital banking and lending origination platforms. Named financial customers include two United States global banks, a card network, a card issuer and a national bank. The company is Prove Identity, Inc. of New York, founded 2008 as Payfone by Rodger Desai and Brad Rosenfeld.

Last VerifiedAugust 25, 2026
Compare Prove with other vendors
Founded
2008
Headquarters
New York, United States
Website
www.prove.com
Categories
aml-kyc-financial-crime, fraud-and-transaction-risk, payments-intelligence
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 5 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

The vendor argues against its own placement on this axis, deliberately and in public, and the argument holds. Its chief executive frames the product as deterministic identity and puts the case that a model can fabricate a face or clone a voice but cannot replicate a decade of real digital behaviour, positioning the company against probabilistic verification rather than as an example of it. Structurally that is accurate.

The load bearing assets are a registry of identity tokens, cryptographic proof that a person possesses a particular device, and telecom derived facts about how long a number has been held and whether the subscriber identity module recently changed. Those are lookups and cryptographic checks, not inferences. Strip the models and phone possession verification, subscriber identity module change detection and the token registry all survive intact, which is the product.

Learned components are real but sit around the edge: behavioural signals accumulated over time, mobile network and address intelligence, and the orchestration layer that resolves many signals into one pass or fail outcome. The newer agentic suite adds model dependent work. The core remains a data asset with cryptography over it.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Bounded by architecture rather than by policy, and the boundary is a real one. The product returns a determination to an institution and stops there. It does not open the account, decline the applicant, close an alert or generate a filing, and the customer institution makes and owns the decision that follows.

The agentic suite points the same way, since its function is to verify that an agent is authorised rather than to act as an agent itself, which places it on the control side of the autonomy question rather than the acting side. Against that stands the shape of the output.

The Global Fraud Policy resolves many signals into a single pass or fail indicator now delivered through the older interfaces as well as the platform, and a binary of that kind invites an institution to wire it straight through to an onboarding decision with no intermediate judgement.

Nothing published describes an override path, a manual review route for a failed verification, or what the vendor expects an institution to do before acting on a fail, and nothing states what a wrongly failed applicant is told. The bound is genuine; it is a consequence of the product's shape rather than a commitment the vendor has made.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

Outcome figures in quantity, with one honest qualifier and no method behind any of them. The qualifier deserves credit because it is rare: the fraud reduction claim is stated as 75 percent relative to attack rate rather than as a bare percentage, which acknowledges that a reduction figure is meaningless without the baseline it is measured against, and most of this segment does not bother.

Other published results are similarly specific, including up to 79 percent faster onboarding, 35 percent lower abandonment and an 87 percent instant verification success rate at a named issuer. What is absent is everything a risk function would need to rely on them.

Two passes located no accuracy figure, no false positive or false negative rate, no recall against a known fraud set, no validation methodology, no sample or observation period, and no model documentation of the kind a bank must hold on a vendor model feeding its customer identification programme.

That last gap is the notable one, because the vendor states deployment inside 19 of the top 20 United States banks, every one of which owes its supervisor an account of how this model performs, and none of that account is public.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

The deepest evidence base graded in this lane, on named institutions and quantified results at scale. Financial customers appear by name rather than by tier, including two United States global banks, a card network, a major card issuer, a co branded card programme and a national bank, with executives on the record: the president of one card programme and a senior vice president for digital credit at an issuer.

Case studies carry multiple metrics each rather than a single headline, including a 90 percent application pass rate with implementation completed in 48 hours, a 35 percent reduction in drop off with an 87 percent instant verification success rate, and complete elimination of bot attacks at a wallet.

Platform scale is stated specifically: more than 30 billion verification events annually, roughly 90 percent of digitally active adults, 227 countries, and 47 million accounts opened in one year through a single product. Corroboration is independent and current: a growth list placement, a World Economic Forum community selection, national press coverage, a cloud marketplace listing, and strategic investment from the venture arms of a large insurer and a large card issuer. The reservation is drift: the institutional claim appears across surfaces as eight of the top ten, nine of the top ten and 19 of the top 20, and brand counts range from 1,000 to 2,000.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

One design commitment worth crediting, and the usual absences everywhere else. The commitment is in the agentic suite, where the vendor describes binding cryptographically signed consent into an identity token that travels with every agent action.

That is a real architectural control rather than a policy promise, because it makes the question of whether an agent was authorised answerable after the fact from the token instead of from a log the vendor controls, and it is more than most vendors moving into agent verification have specified.

The vendor also publishes substantial technical writing on the threats it defends against, covering injection attacks, deepfakes, recycled numbers, subscriber identity module swaps and passkey syncing weaknesses, which demonstrates the threat model even where it does not evidence the controls. Across two passes nothing was located on red teaming, evaluation methodology, incident disclosure or an acceptable use boundary.

The specific stewardship gap is training: the platform observes an enormous share of United States adults and the vendor states that its foundation compounds with every interaction, and nothing published says whether customer data, consumer verification outcomes or behavioural history train its models, or how a consumer would know.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

The most complete consumer privacy surface graded in this segment, with one structural question left unanswered. Published and reachable without contact: a privacy notice, full terms of service, a modern slavery statement, a dedicated data subject rights portal operated on a third party privacy platform, and a working do not sell or share my information route, which is the operative control under Californian privacy law rather than a statement about it.

The architecture supports the posture rather than merely asserting it, since the subscriber identity module acts as a proxy and identities are held as tokens, so a customer can recognise a person without the underlying identifiers moving, and the onboarding flow is built on explicit consumer consent before verified fields are returned. The unanswered question is upstream and is the one that matters most for this design.

The product rests on telecom derived facts about consumers, how long a number has been held, whether the module changed, what the mobile network knows, and nothing published describes the legal basis on which that carrier data reaches the vendor or what those consumers were told. The Gramm Leach Bliley Act itself appears nowhere despite deployment inside most large United States banks.

Security Certifications and Trust Center
CC on Security Certifications and Trust CenterA single footer line, or certifications asserted without being enumerated, which is weaker than naming them because it invites an assumption a buyer cannot check.
Vendor Published

A disclosure failure rather than a security one, and the distinction is worth drawing carefully. The vendor is deployed inside 19 of the top 20 United States banks, a card network and a major issuer, and no institution of that kind onboards a vendor holding tokenised identity records without an attestation report, a penetration test and a full security review. The controls therefore almost certainly exist and have been examined repeatedly by demanding parties. None of it is public.

The website footer carries seven unlabelled badge images that cannot be read as credentials by a person or a crawler, no framework is named in text anywhere, and across two passes no trust centre, downloadable certificate, attestation report, penetration test summary, subprocessor list or security page was located. The only security language on the public surface is the phrase bank grade security, which has no defined meaning and is not a credential.

The consequence is practical rather than theoretical: a smaller institution without the leverage to demand documents in procurement cannot establish from the public record what this vendor holds, and neither can anyone assessing it from outside.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

An unregulated supplier with strong regulatory literacy and one conspicuous unanswered status question. The literacy is real and specific rather than decorative: published material engages customer identification programme requirements and taxpayer identification rules by name, the stablecoin legislation's anti money laundering provisions, deposit insurance guidance on digital banking, a mobile industry standard for network based verification and an authentication standards body, and the company sits on an industry identity coalition.

That is more substantive regulatory engagement than most vendors publish. It holds no financial services authorisation and claims none, which is correct and not overstated. The unanswered question is the one a bank's counsel asks first about a vendor of this type in the United States.

When identity and fraud signals derived partly from telecom and public records inform whether a consumer is granted an account, whether the supplier is acting as a consumer reporting agency, and therefore whether adverse action and dispute rights attach, is a live issue in this category. Across two passes no published position on that status was located.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

The exposure follows directly from the architecture and is not addressed anywhere public. Phone centric verification rewards a long tenured mobile account held in the person's own name on a postpaid contract with a stable usage history, and the vendor says so plainly when it argues that a decade of real behaviour cannot be replicated. The corollary goes unstated.

People who verify worst under that model are those who recently arrived in the country, are young enough to have no history, use prepaid service, sit on a family plan in someone else's name, share a device, or changed numbers after losing a job or leaving a household.

That population overlaps closely with the one already least served by mainstream banking, and this product sits at the gate of account opening at most large United States banks, so a differential pass rate is not an abstract fairness concern but a distribution of access to accounts.

Across two passes no pass rate breakdown by tenure, line type, age or geography was located, no bias testing, no model card, no fairness statement and no position on the European Union artificial intelligence regulation despite stated European operations.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

Terms of service published, which lifts this above the silence common in this segment, and a naming trap that a buyer should not walk into. The trap is the Prove Global Fraud Policy. Read quickly by a compliance or procurement reader, the word policy alongside the word fraud reads as coverage, an instrument that pays when fraud gets through. It is not.

It is an internal defence engine that orchestrates possession, ownership, device trust, identity matching and network signals into a single pass or fail outcome, and it transfers no risk to the vendor whatsoever. Anyone treating it as a warranty in a vendor assessment would be materially wrong, and nothing in its presentation corrects that reading.

Beyond the published terms, two passes located no warranty, indemnity, liability cap, service level with credits or professional indemnity position, and nothing addresses what is owed when a verification wrongly fails a legitimate applicant or wrongly passes a synthetic identity into an account. On the consumer side a working data rights portal exists, which is a privacy mechanism rather than recourse against a verification decision.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The data supply chain is described by category and never by supplier, and the model supply chain is not described at all. On the data side the vendor is unusually explicit about what kinds of input feed the outcome, naming possession and ownership checks, subscriber identity module and device trust, identity matching, address intelligence, mobile virtual network operator analysis, bank and public records, and more than a decade of proprietary history.

Partner disclosure is better than most in one specific area, since the credential exchange names its participating providers for business verification, background screening, credit data and payments outright. What is never named is any carrier or data supplier, and for a product whose distinguishing asset is telecom derived, the identity of the mobile network operators and aggregators behind it is the concentration question: a buyer inheriting this dependency cannot see how many suppliers sit beneath it, in which countries, or what happens to coverage if one relationship changes. On the model side, an agentic suite is now sold and no model provider, family or version is named anywhere across two passes.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

The strongest integration surface graded in this segment, on both the developer side and the banking distribution side. On the developer side everything a buyer needs is public and self serve: complete interface documentation on its own subdomain, a developer portal with free registration and no sales gate, an interface studio for composing custom flows, a public code repository organisation, and client and server side software development kits, with the vendor putting core deployment at five minutes and one named customer reporting total implementation in 48 hours.

Backward compatibility is handled explicitly rather than by breakage, since the newer fraud policy output was extended to the older interfaces without requiring customers to change their integration. On the distribution side the channels are the ones that matter for this buyer: a listing on a major cloud marketplace, a listing on a core banking exchange, and partnerships embedding the product into a digital banking platform and a lending origination platform, which reach institutions through systems they already run rather than as another vendor to onboard.

A credential exchange connects named partner providers for business verification, background checks, credit data and payments. No published connector catalogue enumerating supported core systems was located.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

A hosted interface service with the residency questions unanswered. Across two passes nothing published states the hosting regions available, the tenancy model, whether data can be pinned to a jurisdiction, or what happens to tokens and verification history at contract end.

The available signals are indirect: a documented cloud provider relationship and marketplace listing, a stated European research hub, dedicated United Kingdom and Brazil market presences, and coverage claimed across 227 countries. Presence in a market is not a residency commitment and should not be read as one.

The gap carries more weight here than at a vendor holding less, because the registry contains tokenised identity records for a very large share of United States adults and the vendor states that one in two of them were seen on the platform in a single year, so where that registry physically sits, and which jurisdictions can compel access to it, is a question a bank's third party risk function and a European or Brazilian regulator would both ask. No self hosted, private or in tenancy deployment option is described, which is expected for a network product whose value is the shared registry but should still be stated.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No figure anywhere across two passes, but more commercial substance than a bare contact sales posture. What is published and genuinely useful: know your customer and anti money laundering screening, covering sanctions, watchlists and politically exposed persons, is stated as included at no additional cost within the onboarding products, which is a bundling commitment a buyer can hold the vendor to and which removes a line item competitors charge for separately.

Terms of service are published in full. A free developer account can be opened without a sales conversation, with complete interface documentation and software development kits available, so a technical buyer can evaluate and scope integration effort before any commercial contact, which is a meaningful form of transparency even absent a rate card. A cloud marketplace listing provides a procurement route that can carry private negotiated pricing.

What remains unpublished is everything about the shape of the deal: no unit of billing, no indication whether charging follows verification events, monthly active users, seats or product modules, no tier structure, no contract term and no minimum. For a platform sold on volume at 30 billion events a year, the unit alone would tell a buyer a great deal.

Institution and Segment Coverage
AA on Institution and Segment CoverageThe financial segments served are named and each carries its own maintained material, whether the coverage is broad or deliberately narrow.
Vendor Published

Institutional depth at the top of United States banking that nothing else in this segment matches, with the financial lines built as products rather than positioned as a vertical. The headline claim, 19 of the top 20 United States banks, is specific enough to be checked and is supported by named customers spanning distinct institution types: two global banks, a card network, a major private label and co brand issuer, a co branded card programme and a national bank.

Coverage extends across the financial estate rather than sitting in onboarding alone, with separate published lines for banking, fintech and lending, crypto, insurance and merchants, and use case material reaching stablecoins, tokenised deposits and payment recipient verification.

Distribution corroborates the claim, since the product is listed on a core banking exchange and partnered into digital banking and lending origination platforms, which are channels a vendor only reaches with genuine institutional adoption. Geographic reach is stated at 227 countries with dedicated United Kingdom and Brazil presences and a European research hub. The record grades only these lines: healthcare, online gaming and marketplaces are sold from the same registry and fall outside it.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No price, tier, unit of billing or contract term appears on any vendor surface
Not published. Nothing on any vendor surface states how the product is charged, so a buyer cannot tell whether the basis is verification events, monthly active users, seats, product modules or a platform fee, nor whether the several solutions are licensed together or separately. One disclosure of real commercial substance is published and is unusual for this segment: know your customer and anti money laundering screening, covering global sanctions, watchlists and politically exposed persons, is stated as included at no additional cost within the onboarding and verification products rather than charged as a separate line, which is a commitment about scope even in the absence of a rate. A cloud marketplace listing provides an alternative procurement route. The published entry path is a sales conversation, with a free developer account available separately for technical evaluation. No tiered data protection terms are published. Commitments are made uniformly rather than sold by tier: a privacy notice, full terms of service, a working data subject rights portal on a third party privacy platform, and an operative do not sell or share my information route. The architecture carries the substantive commitment, since identities are held as tokens and the subscriber identity module acts as a proxy, so a customer can recognise a person without underlying identifiers moving. No data processing agreement, subprocessor list, retention schedule, hosting region or model training commitment was located without contact. No implementation, onboarding, integration or professional services fee is published. The vendor markets integration effort rather than pricing it, stating five minutes to deploy core interface functionality, offering client and server side software development kits, and publishing one named case study in which a card programme completed total implementation in 48 hours. A developer account can be opened free and without a sales conversation, with full interface documentation and a public code repository organisation available, so a technical team can build and test before any commercial commitment. Backward compatibility has been handled without charge or migration work in at least one documented instance, when the unified fraud policy output was extended to the older interfaces with customers explicitly not required to change their integration. Distribution partnerships place the product inside a core banking exchange, a digital banking platform and a lending origination platform, where deployment cost may sit with those partners rather than with this vendor and is not described here. Vendor Published

Two passes across the vendor's own site, its solution and industry pages, its developer portal and documentation, its press archive and the software aggregator listings produced no price and no billing unit. One aggregator states plainly that the vendor does not publish pricing and that the platform is licensed to financial institutions on volume, which is a third party characterisation rather than a vendor statement and is recorded as such.

What lifts this above a bare contact sales posture is that two of the three things a buyer normally wants are public even though the number is not: the scope of what is included, through the stated bundling of screening at no additional charge, and the integration effort, through complete public documentation and a free developer account that let a technical team scope the work before any commercial contact.

The cloud marketplace listing adds a procurement route that can carry privately negotiated terms. What a buyer still cannot form is a budget expectation, because nothing indicates whether charging follows verification events, monthly active users, seats or modules.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746