How to Compare Identity Verification Providers When All the Marketing Sounds the Same

How to Compare Identity Verification Providers When All the Marketing Sounds the Same

A fintech evaluating four identity verification vendors wrote publicly that “marketing from all four sounds identical so the website comparisons are useless.” They are right, and the reason is visible in the search results themselves: nine of the ten pages ranking for this question are comparisons written by vendors in the category, and each of them ranks itself at or near the top.

TextToolz sells no identity verification, no KYC platform and no fraud product, competes with nothing named here, and takes no referral fee.

There is one differentiator in this category that a buyer can verify without trusting any vendor’s description of itself. It is not a feature, and it is not an accuracy percentage. It is a laboratory certification, and the section below explains what it measures and why it is the only checkable claim on the page.

What these products actually do, and where KYC starts

Identity verification software confirms that a person presenting themselves online is who they claim to be, typically by checking a government document, capturing a selfie, and testing that the selfie belongs to a live human rather than a photograph or a recording.

KYC is not the same thing, and buyers conflate them constantly. Know Your Customer is a regulated programme, and identity verification is one step inside it. The rest of the programme includes screening the verified person against sanctions lists, politically exposed person registers and adverse media, then re-screening them periodically because the lists change even when the customer does not.

This matters commercially rather than academically. A company can buy a verification product, deploy it correctly, and discover at audit that it has no ongoing screening and therefore no KYC programme. The distinction determines which vendors on this page are even eligible for your requirement.

The one thing you can actually verify

Ondato publishes the only per-vendor certification table found anywhere on this search, and it is the single most useful artefact in the category. Read on 17 August 2026, it lists certifications vendor by vendor rather than as a marketing badge wall.

The item on it that matters most is iBeta PAD Level 1 and Level 2, and it is worth explaining properly because the acronym hides how concrete it is.

Presentation Attack Detection testing is performed by an independent laboratory. The lab attempts to defeat the vendor’s biometric liveness check using known attacks: a printed photograph, a video replay on a screen, a 3D mask, and increasingly a deepfake. The testing is conducted against NIST standards, and the level records the sophistication of attack the system withstood. Level 1 covers basic presentation attacks. Level 2 covers considerably more sophisticated ones.

Consider what kind of claim that is compared with everything else on this search. “AI-powered biometrics” is a description a vendor writes about itself. “Advanced liveness detection” is the same. An accuracy percentage with no test set named is a number a vendor chose. A PAD level is the outcome of somebody outside the company trying to break the product and recording how far they got.

A buyer who cannot tell four vendors apart from their marketing can tell them apart from their PAD level in about a minute, and can ask the ones that do not publish it why not.

The other certifications on that table govern different things and are worth knowing by function rather than by name. ISO/IEC 27001 covers information security management. ISO/IEC 27701 extends it to privacy management. SOC 2 Type 2 is an audited report on security controls operating over a period rather than at a moment. ISO/IEC 30107 is the standard behind liveness and presentation attack detection itself. eIDAS and ETSI TS 119 461 govern identity proofing in the EU, and the UK Digital Identity and Attributes Trust Framework does the equivalent job in the UK. KJM is Germany’s age verification requirement, which most buyers discover exists only when it applies to them.

Four figures naming iBeta presentation attack detection levels one and two as a third party laboratory test, what it measures, eight other standards, and that one page of ten publishes the table
The only per-vendor certification table on the search, and the one entry on it a laboratory can confirm.

Active or passive liveness, and why it is your decision

The second real differentiator on Ondato’s table is the type of liveness detection, and it is presented there as a fact about each vendor rather than as a choice for the buyer. It is a choice.

Active liveness asks the user to do something on camera: turn their head, follow a prompt, blink, move closer. Passive liveness analyses a single selfie in the background, with no instruction and no user action required. Several vendors offer both, and the table records which does which.

The trade runs in both directions and neither answer is correct in general. Active resists spoofing harder, because a static photograph cannot follow an instruction, and it costs completion rate, because a proportion of users abandon a process that asks them to perform. Passive converts better, because the user barely notices it happening, and it places the entire burden on the detection model, which is precisely what the PAD level measures.

So the decision follows from what a failure costs you in each direction. A marketplace onboarding casual sellers loses real revenue to abandonment and can absorb some fraud. A bank opening accounts cannot absorb the fraud and can absorb the abandonment. Those two should not select the same product, and almost nothing on this search frames it that way.

Nobody publishes a price

Ondato’s table records the pricing model for each vendor, and the models genuinely differ: usage-based per completed verification, pay-per-check on a quote basis, subscription or tiered, and enterprise custom.

What no vendor on this entire search publishes is a number. Not one per-verification figure appears anywhere in the ten results.

That is worth naming as a pattern rather than a complaint, because this is now the fourth category in which the same structure has appeared. Compliance automation: one vendor in nine published a price. Enterprise procurement: the pricing column read “custom” for every enterprise suite. Financial close software: no price at all, and the figures in circulation were placeholders. Identity verification behaves identically.

Negotiated enterprise pricing produces this reliably, and the practical consequence is the same each time. You cannot benchmark a quote in this category against anything published, so the only available leverage is interrogating the structure. Ask what the unit is, whether a failed verification is billable, what happens to the rate at renewal, and what a second market or a second use case costs.

Four figures showing zero vendors publishing a price, nine of ten results vendor written, one independent verdict, and one kind of verifiable claim
What the category publishes, and what it does not.

The eight providers

Each entry below states liveness type, human review, pricing model and the certifications published for it, plus one real limitation. Certification details are credited to Ondato’s table throughout and were verified at no certifying body by us.

The eight providers at a glance. Certification and liveness data from Ondato’s published comparison, read 17 August 2026.
Provider Liveness Human review Pricing model
Ondato Active Yes Per completed verification
Jumio Active and passive Yes Per verification, custom quote
Entrust (Onfido) Passive, optional active Optional Per check, quote-based
Trulioo Passive No Enterprise custom
Veriff AI with manual review Yes Not published
Sumsub Not published in the table Not published Not published
IDnow Active, video-based Yes, expert-led Subscription or tiered
Persona Not published in the table Yes Not published

Ondato

A full-stack KYC and AML platform combining biometric verification, document validation, sanctions screening and business onboarding in one system.

It deserves crediting first and for a reason unrelated to its product: it publishes the certification table that most of this page depends on, and that table is the most useful artefact anywhere in this category. A vendor that publishes a comparable, checkable column about its competitors as well as itself has done something none of the others have.

Its own published certifications are the most extensive on that table: ISO/IEC 27001, SOC 2 Type 2, GDPR compliance, eIDAS at the Extended and High levels of assurance, ETSI TS 119 461, iBeta PAD Level 1 and 2, and KJM certification from Germany’s commission for the protection of minors in media, which is the specific requirement for age verification there.

Liveness is active. Human review is available for edge cases and ambiguous documents. Pricing is usage-based, per completed verification, which is a meaningfully different thing from per attempt. It also supports reusable KYC profiles, letting a verified user skip repeat checks.

Best for EU-regulated onboarding where an eIDAS level of assurance is a hard constraint rather than a preference.

The limitations are two and both are stated plainly. It ranks itself first in its own comparison, which is the same behaviour this page criticises elsewhere. And its published accuracy figure is excluded here, exactly as every other vendor’s is, because no test set or method accompanies it.

Jumio

One of the earliest entrants in the category, and positioned by 1Kosmos around continuous KYC rather than a single check at account opening: ongoing monitoring, sanctions rescreening and risk assessment across the whole customer lifecycle.

Certifications per Ondato’s table are broad: ISO/IEC 27001, ISO/IEC 27701 for privacy information management, SOC 2 Type 2, PCI DSS, iBeta PAD Level 2, and alignment with GDPR and CCPA.

Two of those deserve pulling out. iBeta PAD Level 2 means the liveness detection was tested by an independent lab against the more sophisticated attack class, including 3D masks and deepfakes, which is the strongest externally verifiable claim available in this market. And PCI DSS is unusual on this list, mattering specifically where cardholder data falls within the scope of the same system.

Liveness combines active and passive. Human review is available. Pricing is per verification on custom quotes.

Best for enterprises whose obligation is continuous rather than one-time, where a customer verified in January must still be screened in July.

The limitation is the one the Reddit buyer named: Jumio is one of the four whose marketing that buyer found indistinguishable from its competitors. The certification table is how you tell them apart, not the website.

Entrust (Onfido)

Developer-facing SDK tooling is the positioning that recurs across multiple comparisons, credited to Trustpair among others, and it points at a specific buyer: a team that intends to build the verification flow into its own product rather than redirect users into a hosted one.

Certifications per Ondato’s table: ISO/IEC 27001 across the whole organisation, ISO/IEC 27701, SOC 2 Type 2, ETSI TS 119 461, plus ISO 9001 and ISO 14001 for quality and environmental management.

The certification worth understanding here is full certification as an Identity Service Provider under the UK Digital Identity and Attributes Trust Framework. That is a UK government-backed scheme, which changes its character entirely: for a growing set of UK use cases, DIATF certification is eligibility rather than a preference, and a vendor without it cannot be selected regardless of how good it is.

Liveness is passive with optional active prompts, which is a sensible default for conversion with an escalation path for higher-risk cases. Human review is optional. Pricing is per check, quote-based.

Best for regulated UK and financial use cases with the engineering capacity to use the SDK properly.

The limitation is that same engineering dependency: developer-friendly tooling is only an advantage to a team that has developers to point at it.

Trulioo

Global data coverage is the pitch, and Trustpair positions it specifically for companies entering a new market for the first time, which is a precise and credible use case.

Certifications per Ondato: ISO/IEC 27001:2022 and SOC 2 Type 2.

The configuration to understand is the combination rather than any single attribute. Liveness is passive, background biometric analysis with no user action required. Human review is no, described as primarily automated. Pricing is enterprise custom.

Passive and automated together optimise hard for completion rate and scale, which is exactly right for high-volume onboarding across many countries where you cannot staff a review team fluent in every document type in circulation.

The same combination means there is no human fallback when the system is unsure. That is not a defect and it is a real consequence: the ambiguous document, the worn passport, the unusual regional ID gets an automated answer rather than a person’s judgement, and the customer behind it is accepted or rejected accordingly.

Best for breadth of country coverage at volume, particularly for a company expanding into markets whose document formats nobody on its team has seen before. The limitation bites precisely where documents are unusual, which in a genuinely global product is not a rare edge case but a steady percentage of every day’s traffic.

Veriff

Positioned by Trustpair on the blend of AI with manual review, keeping a human in the loop while retaining automation’s efficiency, and named there for e-commerce and marketplace accounts.

nCino lists Monzo, Deel, Bolt, Webull, Starship and Wise among its clients. That list is credited to nCino and has not been verified by us with any of the companies named.

The human-in-the-loop trade is worth stating precisely because it is the entire product decision. Manual review raises the cost per check and slows some verifications down. What it buys is the rescue of cases automation would refuse, and in a consumer marketplace those refusals are not avoided risks but lost customers, many of them entirely genuine people with a slightly unusual document or a poorly lit room.

So the calculation is about what a false rejection costs you. A bank rejecting a genuine applicant loses one account. A marketplace rejecting a genuine seller loses the inventory that seller would have listed, permanently, to a competitor.

Best for marketplaces and consumer platforms where a wrongly rejected user is a direct revenue loss.

The limitation is the Reddit buyer’s again: Veriff is one of the four they could not distinguish from marketing alone.

Sumsub

Named by 1Kosmos for full-cycle compliance, and by Vouched alongside LexisNexis Risk Solutions as offering specialised tooling for KYC and AML requirements.

Full-cycle is the phrase worth unpacking, because it describes an architecture rather than a feature. Verification at onboarding, ongoing screening afterwards, and case management for what those screens throw up, delivered as one system rather than three integrated ones.

That matters to a compliance team for a reason that is easy to miss when comparing features. The question an auditor asks is rarely whether you performed a check. It is whether you can demonstrate the whole lifecycle of a customer relationship in one place, with the decisions and the evidence attached. Three good systems stitched together answer that question badly.

Best for regulated businesses that want onboarding and ongoing AML obligations in a single platform with a single audit trail.

Two limitations, both about evidence rather than product. Sumsub is the fourth of the four the Reddit buyer found indistinguishable. And no certification detail for it appears in the one comparable table on this search, which means the check this page recommends most strongly cannot be run on it from published material. Ask them directly for the PAD level.

IDnow

The most regulatory-specific entry on this list, and EU-centric by design rather than by accident.

Certifications per Ondato’s table are the most targeted of any vendor here: ISO/IEC 27001, SOC 2 Type 2 renewed as of early 2025, eIDAS Qualified status permitting Qualified Electronic Signatures and high-assurance identity proofing, ETSI TS 119 461 certified specifically for its VideoIdent and AutoIdent products, and ISO/IEC 30107 for liveness and presentation attack detection.

It also maintains local data centres, notably in Germany, for data residency compliance. For a buyer under a residency requirement that is a binary qualifier rather than a nice attribute.

Liveness is active and video-based, with expert-led verification available. Pricing is subscription or tiered, which is one of the few departures from per-check billing in this market and produces very different economics at volume.

Best for EU use cases where eIDAS Qualified status, German data residency, or a qualified electronic signature is a hard requirement.

The limitation is the mirror image of the strength. The same EU specificity that makes it the obvious answer inside those requirements makes it a poor fit outside them, and video-based active verification is the highest-friction flow described anywhere on this page, which will show up directly in completion rates for consumer onboarding.

Persona

Customisable workflows is the consistent positioning, credited to 1Kosmos, which also records Persona among companies named as Leaders in a 2026 Gartner Magic Quadrant for Identity Verification.

That last claim needs an explicit caveat rather than a quiet repetition. The report sits behind a paid research model, we have not read it, and it is reported here as a statement made on another vendor’s page rather than as a verified finding. It appears because excluding it silently would be its own kind of distortion.

AU10TIX credits Persona with an unusually broad surface: AML and KYC compliance, sharable KYC, Know Your Business for verifying companies rather than people, business fraud prevention, age assurance, workforce identity verification, background checks, manual review and reverification.

Know Your Business is the differentiator most worth noticing there. Verifying a company is a materially different problem from verifying a person, involving registries, ownership structures and beneficial owners, and comparatively few products on this list address it.

Best for teams whose verification flow needs to differ by user type, risk tier or market, rather than teams accepting a fixed flow.

The limitations: configurability is a project rather than a setting, and no certification detail for Persona appears in the one comparable table here.

iDenfy

The value entry on this list, and described consistently enough by two independent-ish sources to be credible.

SEON describes it as a broad identity verification and KYC platform for onboarding customers remotely while meeting global compliance requirements, founded in Lithuania in 2016. Ondato, in its honourable mentions, calls it cost-effective, offering document verification, facial biometrics, liveness detection and basic AML screening through APIs and no-code tools, designed for easy deployment by small and mid-sized businesses.

The word “basic” in that description is doing real work and should not be skimmed. Basic AML screening is adequate for lower-risk onboarding and is not the same thing as a full sanctions, politically exposed person and adverse media programme with ongoing rescreening. A regulated institution buying on price here would be buying the wrong product.

The no-code tooling is a genuine advantage for the buyer it targets: a small business that needs verification working this month and has no engineering capacity to allocate to it.

Best for small and mid-sized businesses needing standard KYC without enterprise complexity or an enterprise sales cycle.

The limitation is a ceiling rather than a fault. The simplicity that makes it deployable in days is the same simplicity you outgrow if your regulatory obligations expand, and migrating a verification provider mid-programme is expensive.

What none of this tells you

Accuracy, which is the question that decides the purchase and the one this page deliberately refuses to answer. The exclusion is principled rather than cautious, and the reasoning is worth following.

Accuracy percentages do appear on this search, including a 99.8% figure. None of them arrives with a test set named, a method published, or a third party involved in producing it. A percentage of that kind is a marketing artefact, and repeating it inside an editorial comparison would launder it into something it is not.

Contrast that deliberately with iBeta PAD, which is the whole argument of this page. Both are numbers about how well a system detects fraud. One was produced by the vendor and one by an independent laboratory attempting to break the product against a published standard. Only the second is evidence.

We evaluated no vendor, ran no verification and did not read the Gartner report.

What to ask for instead is specific and cheap: a pilot on your own document mix, in your own markets, with the rejections reviewed by you rather than reported to you. A vendor’s accuracy on their test set tells you about their test set. Your rejection rate on your customers tells you about your business.

A note on where this category is going, since it affects the check above: deepfake and synthetic identity attacks are the reason PAD Level 2 exists as a distinct tier, and the reason a certification from three years ago is a weaker signal than a current one. Ask for the date of the certification, not only its existence.

Buyers wanting an example of a provider in the adjacent fraud and identity space can look at FortifID, and the same instruction applies: ask for the certification and its date rather than taking any description, including this one, at face value.

How this comparison was built

Ten results were reviewed and eight extracted in full on 17 August 2026, with no extraction failures. Keyword research was run against Google’s autocomplete the same day, which publishes no search volume, and none is quoted here.

The source-interest map is the finding rather than a footnote. Every comparison on this search is written by a vendor in the category, and each ranks itself at or near the top of its own list. The non-vendor exceptions are an analyst marketplace behind a paid research model, an affiliate, and one forum thread.

The single most useful artefact on the search, the per-vendor certification table, is published by Ondato, which also ranks itself first in the same article. This page credits and relies on that table anyway, and the reason is worth stating: a checkable table published by an interested party is still checkable. Certifications can be confirmed with the certifying bodies. A ranking cannot be confirmed with anybody.

We verified none of those certifications at source, so every one is credited to Ondato’s table and dated rather than asserted. Client lists are credited to nCino. Accuracy figures and Magic Quadrant claims are excluded, with the reasons given above.

The Reddit thread that supplies this page’s framing could not be extracted and is quoted from its search snippet. That is a real gap: the one page on this search written by an actual buyer is the one we could not read in full.

Frequently asked questions

These are the questions buyers search in this category, answered from the published sources named throughout.

What is identity verification software?

Software that confirms a person online is who they claim to be, usually by checking a government document, capturing a selfie, and testing that the selfie is a live human rather than a photo or recording. It is one step inside a KYC programme, not the whole thing.

How is KYC different from identity verification?

Verification proves the person. KYC is the regulated programme around it, adding sanctions, politically exposed person and adverse media screening, plus periodic re-screening because those lists change even when your customer does not.

What is iBeta PAD certification?

An independent laboratory test of whether a biometric liveness check can be defeated by a photograph, video replay, 3D mask or deepfake, conducted against NIST standards. Level 2 covers the more sophisticated attacks. It is the only externally verifiable claim in this category.

What is the difference between active and passive liveness?

Active asks the user to perform guided actions on camera. Passive analyses a selfie in the background with no user action. Active resists spoofing harder and loses users to abandonment; passive converts better and puts more weight on the detection model.

How much does identity verification cost?

No vendor on this search publishes a per-verification figure. Only the model is public: per completed verification, per check on quote, subscription or tiered, or enterprise custom. Ask what the billable unit is and whether failed attempts count.

Which provider is the most accurate?

This page cannot tell you and no page on this search honestly can. Every accuracy figure published here lacks a test set, a method and a third party. Run a pilot on your own document mix and review the rejections yourself.