Vouched
Vouched began as a document based identity verification provider, reading photo identity documents, comparing them to a live selfie, detecting tampering and checking details against databases, aimed at industries where missing documentation excludes people from access. It has since turned toward verifying artificial intelligence agents rather than only people, building a Know Your Agent platform with an agent reputation directory and continuous behavioural monitoring for anomalous or malicious activity.
A shipped integration binds a biometric check of the authorising human to the moment an agent is created, after which the agent receives only the financial authority its user intended through payment tokens bounded in advance by merchant, amount and use case, with every authorisation event logged into a tamper evident trail.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
The removal test leaves nothing at either end of the business. The original product reads photo identity documents, compares them against a live selfie, examines addresses, checks databases and looks for signs of tampering, all of which is model work, and the founders came from computer vision and autonomous vehicle backgrounds rather than from workflow software.
The newer agent platform is equally model dependent, continuously monitoring agent behaviour to detect anomalous or potentially malicious activity, which the company describes as using artificial intelligence to safeguard against artificial intelligence.
The most concrete answer in this index to the question of how an autonomous agent's authority is bounded, and it operates at the point of delegation rather than after the fact. A biometric check with live liveness detection confirms the identity and intent of the authorising human at the moment an agent is created or activated, and the agent then receives exactly the financial authority its user intended and nothing more, through payment tokens bounded in advance by merchant, amount and use case.
Every authorisation event is logged with biometric, behavioural and intent signals into a tamper evident trail, and agent behaviour is monitored continuously afterwards for anomalies. The company states the principle directly, that this converts agent level authorisation into human anchored authorisation. Where Recordsure prohibits a decision and motif locates the liability, this bounds the grant itself.
No accuracy figure, false match rate, error analysis or independent evaluation result was located for the document and face verification products, and no participation in an accredited presentation attack scheme or government face evaluation appears. Nothing is published for the behavioural monitoring either, where the operative measure would be how often anomalous agent activity is correctly identified against how often normal automation is flagged. For a product whose whole purpose is deciding what may be trusted, the absence of any published measure of its own reliability is the central gap.
The chief executive states annual recurring revenue above 10 million dollars alongside very strong growth and demand, which is a revenue disclosure most private vendors of this size decline to make and which is a harder number to assert than a customer count. A 17 million dollar Series A in late 2025 brought total funding to 22 million.
One shipped integration is named and dated, with a biometric authentication partner also indexed here, described as available to enterprise customers and development partners at launch rather than announced as a roadmap. Against that, no customer is named anywhere, no verification volume is published, and the revenue figure is a founder statement rather than an audited one.
The shared corpus here is the product rather than a side effect, since an agent reputation directory only works by aggregating observed behaviour across every customer that uses it, so what one enterprise learns about a misbehaving agent necessarily informs what every other enterprise sees. That is the correct design for a reputation system and it is disclosed as the offering.
What is absent is governance around it: nothing states what behavioural data is contributed, whether contribution is a condition of use, how an agent operator can contest its own reputation entry, or how customer specific verification material is separated from the shared behavioural record.
No data protection agreement, retention schedule, subprocessor list or deletion commitment was located. The payload spans identity documents and selfies in the original product and, through the biometric integration, face, palm and voice captures at the moment an agent is authorised, with each authorisation event logged alongside biometric, behavioural and intent signals.
That authorisation record is an unusually rich artifact, describing not only who a person is but what they intended to permit and when, and nothing published states how long any of it is kept or who can access it.
No attestation, certification, trust centre or enumerated framework was located. That matters more than usual for this product, because the company is asking enterprises to trust it as the authority on which agents and which humans may be trusted, and a platform occupying that position without published assurance is asking for confidence it does not evidence. Peers in adjacent identity work publish accredited biometric testing; nothing equivalent appears here.
No supervisor, statute or instrument is named. Enterprise compliance is referenced as the purpose of the audit trail without identifying which obligations it serves, and the central concept the company promotes is one it is defining itself rather than one a regulator has established, so there is no admission process to have passed. That is not unreasonable for a category this new, and it leaves an enterprise buyer unable to establish what regulatory question a Know Your Agent record actually answers.
Two exposures sit alongside a genuine inclusion motivation. The founding account is explicit that a lack of documentation excludes millions from banking and healthcare, and building verification that works for people with imperfect paperwork is a real access objective. Against it, document reading and, through the integration, face matching carry the demographic error differentials documented throughout this lane, and no evaluation result or per population accuracy was located.
The second exposure is newer and less examined anywhere: an agent reputation directory means a model judging which agents may be trusted, and reputation systems tend to concentrate advantage with established operators while making it hard for a new or wrongly scored agent to recover standing. Nothing describes how a reputation is formed or contested.
No guarantee or indemnity was located, and the design does something better than a commercial promise for the party at risk. Because an agent's authority is bounded in advance by merchant, amount and use case, the maximum loss from a hijacked or misbehaving agent is capped at the moment of delegation rather than discovered afterwards, and because every authorisation carries a tamper evident record of the biometric and intent signals behind it, a disputed transaction can be traced to whether a live consenting human actually granted the authority. Containment plus traceability is real recourse. What is missing is anything for the other side: an agent operator wrongly scored in the reputation directory has no described route to correct it.
The most sensitive component in the newer product is named rather than obscured, with the biometric authentication supplying face, palm and voice verification and liveness detection identified as a partner's technology rather than presented as the company's own, which tells an enterprise exactly whose system captures its users' biometrics. Document and face comparison models in the original product appear to be built in house given the founders' computer vision background.
What is not disclosed is the rest: no model provider is named for the behavioural monitoring, no data source for the database checks the verification product performs, and no subprocessor list or hosting arrangement was located.
One integration is named, dated and shipped rather than announced, embedding a biometrics platform directly into the agent creation and authorisation workflow and available to enterprise customers at launch, and the partner is itself indexed here. A public agent reputation directory operates as its own connection point for anyone assessing an agent.
The company positions the platform as a single identity layer adapting across physical documents, digital credentials and agent interactions, which is the right architectural ambition. What is not evidenced is any connection into the systems a financial institution runs, with no core banking, onboarding, case management or payments platform named.
No hosting provider, region selection, residency commitment or private deployment option was located. The exposure is meaningful given that the platform holds identity documents, biometric captures taken through its integration partner and a persistent record of what each person authorised their agent to do, and nothing published states where any of it is processed or held.
No pricing, packaging or basis of charge was located for either the identity verification product or the agent platform. The unit question is genuinely open for the newer line, since an agent authorisation is a different economic event from a one time identity check and could plausibly be charged per agent, per authorisation, per monitored hour or per transaction, and nothing indicates which.
Financial services appears as a target industry rather than as a maintained segment. The founding motivation names banking and healthcare as the sectors where missing documentation excludes people, and the agent work is intrinsically financial in that it governs payment authority, purchases and transfers, but no bank, lender or insurer is named as a customer, no financial services specific product or proposition exists, and the strategic direction is toward agent infrastructure across commerce generally rather than deeper into regulated institutions. This is coverage by adjacency.
Alternatives to Vouched
The closest documented capability profiles to Vouched in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Institution and Segment Coverage and AI Governance and Bias Disclosure, among others where Vouched does not
Documents Institution and Segment Coverage where Vouched does not
A lighter documented profile than Vouched
Documents Institution and Segment Coverage and AI Safety and Data Stewardship where Vouched does not
Documents Institution and Segment Coverage and Regulatory Status and Licensure where Vouched does not
Documents Institution and Segment Coverage and Regulatory Status and Licensure, among others where Vouched does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.