verifier.org

best 9 identity verification and kyc providers

ranked on what one document-plus-selfie check costs, and how long the vendor keeps your customer's face afterwards.

last reviewed 1 sept 2026 · 9 tools tested ·list curated by Onur Ozcanxin

the short version
best overallDiditteams who want the lowest cost per check and the shortest data retention in the category88/100runner-upVeriffteams who need the deepest presentation-attack credentials at a self-serve price84/100best free optionSocurebuyers who want enterprise-grade fraud signals without an enterprise sales cycle81/100

the unit of this category is one completed check: a government id document read and matched against a selfie, with a liveness test to prove the selfie is a live person rather than a photo of one. that is what you are buying, and it is the only figure that lets these vendors be compared at all.

published, it runs from $0.33 to $1.50. Didit is cheapest at $0.33 for the full bundle and gives away 500 checks a month permanently; Socure and Veriff both land on $0.80; Shufti $0.95, Sumsub $1.35, Stripe Identity $1.50. that is a fourfold spread on a commodity operation, and the expensive end is not four times more accurate — what it tends to buy is coverage, certifications and a support contract.

the second number matters more and almost nobody prints it next to the first: how long the vendor keeps the biometric data. this is a face, permanently attached to a real person, and the spread is enormous. Didit deletes face images, liveness video and embeddings with the session by default. Trulioo destroys the facial scan on completion, capped at a year. Stripe removes biometric identifiers within a year but keeps the id documents for three. Incode keeps biometrics up to three years from the last interaction. Socure keeps them up to three years and offers the buyer no control at all. Veriff and Shufti publish no default whatsoever — retention is whatever your contract says — and Sumsub does not disclose it on any page we could reach.

then the thing none of them will tell you. not one vendor in this category publishes a false rejection rate. every one of them claims high accuracy; not one says how often it refuses a legitimate customer, which is the number that decides how many real signups you lose and which is well documented to fall hardest on darker skin tones and on identity documents from outside western europe and north america. if you are choosing on accuracy, you are choosing on marketing copy, and the only honest answer is to run your own sample before you commit.

three vendors that belong in this ranking are absent, and the reason is worth stating. Persona, Entrust IDV — which is Onfido, acquired and renamed, with onfido.com now redirecting there — and iDenfy each return a 403 to every automated request, on pricing pages and privacy policies alike. we could not read a single figure for any of them from their own sites. rather than publish three entries that say nothing, they are left out. it is not an accusation, they may well show a human a perfectly good price, but a site built on verifiable published figures cannot rank what it cannot read.

advertisement
  1. 1

    Didit

    a third of the going rate, and it throws the face away when it's done

    88/100

    verdictthe cheapest published price here by a wide margin, with the best default retention posture of any vendor ranked — from the youngest company on the list.

    best for
    teams who want the lowest cost per check and the shortest data retention in the category
    price
    $0.33 / full kyc check
    pricing note
    document verification, passive liveness, face match and device analysis bundled; components are $0.15 for the document and $0.10 for the selfie if bought separately. failed verifications are not charged, and there is no monthly minimum, seat fee or contract
    free tier
    yes
    doc + selfie
    $0.33
    biometric retention
    deleted with the session
    free tier
    500 / month, permanent
    self-serve
    yes
    minimum
    none

    at $0.33 for a full check Didit is less than half the next cheapest published price, and the free tier is not a trial: 500 full kyc verifications every month, resetting monthly, permanently. that is more free capacity than most startups will use in their first year, and unlike the fourteen-day trials elsewhere here it does not expire into a sales call.

    the retention posture is the reason it ranks first rather than merely cheapest. by default face images, liveness video and embeddings are deleted with the session — the vendor keeps nothing. buyers who need duplicate detection can opt into storing a single image-free face template with a configurable window from one month to ten years, and there is a per-session delete endpoint. against Socure keeping biometrics up to three years with no buyer control, that is a categorical difference in exposure, and it is the difference that matters if you are ever the subject of a biometric privacy claim.

    the operational details hold up too. it does not bill for verifications that fail, coverage is claimed at 220-plus countries and 14,000-plus documents, and it holds SOC 2 Type 2 as of july 2026 alongside ISO 27001, 27017 and 27018. camera-stream tampering and video-injection detection are claimed explicitly, which is more than most of this field commits to in writing.

    two honest caveats, and one disclosure. its iBeta presentation-attack certification is level 1, where Veriff holds level 2 — a lower bar on exactly the spoofing question this product exists to answer. and it is young, with a $7.5m raise on its homepage and no long public track record, which is a real consideration for something sitting in your signup flow.

    the disclosure: Didit publishes a 'cheapest kyc provider' ranking of its own competitors, which is one of the affiliate-flavoured pages this ranking exists as an alternative to. it does happen to be the cheapest here on our own reading of the vendors' pricing pages. readers should know who wrote the other list.

    pros
    • +$0.33 a check — less than half the next cheapest published price
    • +500 free full verifications a month, permanently, not a trial
    • +biometrics deleted with the session by default; retention configurable 1 month to 10 years
    • +failed verifications are not billed, and there is no minimum or contract
    • +SOC 2 Type 2, ISO 27001/27017/27018, explicit injection-attack detection
    cons
    • iBeta level 1 presentation-attack certification, against Veriff's level 2
    • young company with a short public track record
    • publishes its own competitor ranking — a conflict worth knowing about
  2. 2

    Veriff

    the strongest anti-spoofing credentials here, on undisclosed retention

    84/100

    verdictthe best-certified defence against spoofing in the category at a competitive $0.80 — from a vendor that will not tell you how long it keeps the face until you negotiate a contract.

    best for
    teams who need the deepest presentation-attack credentials at a self-serve price
    price
    $0.80 / verification
    pricing note
    Essential tier, document check and iBeta-conformant liveness priced as one figure rather than split; $49 monthly minimum, with Plus, Premium and enterprise tiers above it for volumes over 5,000 a month
    free tier
    yes
    doc + selfie
    $0.80
    biometric retention
    not published — by contract
    free tier
    50 checks, 15-day trial
    self-serve
    yes
    minimum
    $49 / month

    Veriff carries the most serious security credentials of anything ranked here: ISO/IEC 30107-3 level 1 and level 2 presentation-attack detection, SOC 2 Type II, ISO/IEC 27001:2022, UK Cyber Essentials, FIDO certification and UKDIATF. level 2 is the meaningful one — it tests against sophisticated artefacts rather than a phone held up to a camera, and Didit, Sumsub and Shufti all stop at level 1.

    the commercial terms are reasonable and legible: $0.80 a verification on the Essential tier with a $49 monthly minimum, a fifteen-day trial with fifty live verifications and no card required, self-serve signup with no mandatory sales conversation, and 230-plus countries of document coverage. liveness is included on every plan rather than sold as an upgrade.

    the gap is retention, and it is a real one. the privacy notice says end-user data is stored for the period set out in the agreement, with different retention periods agreed with each customer — which means there is no published default and no answer before you are in a negotiation. the only fixed points are legal floors it does not control: three years for illinois residents under BIPA, a year for texas. compare Didit deleting with the session or Trulioo capping at a year, and this is the vendor asking you to take retention on trust.

    as everywhere in this category, no false rejection rate is published. Veriff claims the highest automated accuracy based on more than a thousand signals per session, which is a description of a method rather than a measurement of an outcome.

    pros
    • +ISO 30107-3 level 1 and 2 presentation-attack certification — the only level 2 here
    • +$0.80 a verification with liveness included on every plan
    • +SOC 2 Type II, ISO 27001:2022, FIDO certified, UKDIATF
    • +15-day trial with 50 live verifications, no card, self-serve signup
    cons
    • no default biometric retention published — set per contract
    • $49 monthly minimum, where Didit and Stripe have none
    • no false rejection rate published, only a claim about signal count
  3. 3

    Socure

    an enterprise vendor that quietly grew a self-serve tier

    81/100

    verdictthe enterprise fraud stack at a published $0.80 with $1,000 of monthly credit and no sales call — undercut by keeping biometrics for up to three years with no buyer control.

    best for
    buyers who want enterprise-grade fraud signals without an enterprise sales cycle
    price
    $0.80 / evaluation
    pricing note
    document verification with selfie on the self-serve Socure Launch tier; $0.90 adds watchlist screening, $1.00 adds kyc and fraud, $1.30 adds prefill. enterprise volumes are custom-quoted
    free tier
    yes
    doc + selfie
    $0.80
    biometric retention
    up to 3 years, vendor-set
    free tier
    $1,000 monthly credit
    self-serve
    yes
    minimum
    none stated

    Socure is usually described as a sales-led enterprise vendor, and that description is now out of date. the Socure Launch tier is genuinely self-serve, publishes $0.80 an evaluation for a government id scan plus selfie, and comes with $1,000 in monthly credits — which at list price is more than a thousand free checks a month. for a company whose reputation is built on large financial-services contracts, that is a significant and underreported change.

    the tier ladder above it is unusually legible for this category. $0.90 adds watchlist screening, $1.00 adds kyc and fraud scoring with document step-up, $1.30 adds prefill. you can see what each capability costs rather than discovering it in a quote, and document coverage is claimed at 195-plus countries.

    retention is where it loses ground. Socure states it keeps facial signatures, embeddings and related biometric data for no more than three years from your last interaction — a fixed vendor-set maximum, presented with no indication that a buyer can shorten it. three years is the longest biometric window of any vendor here that publishes one at all, and unlike Incode's identical cap it is not paired with a purpose-satisfied trigger that would end it earlier.

    the public pages are also thin beyond pricing. we could not confirm certifications, injection-attack defence, or whether business verification is offered, and there is no published false rejection rate — the same gap as everyone else.

    pros
    • +$0.80 self-serve with $1,000 of monthly credit and no sales call
    • +clear tier ladder showing what watchlist, kyc and prefill each add
    • +195+ countries of document coverage
    • +enterprise-grade fraud signals available at startup scale
    cons
    • biometrics kept up to 3 years with no stated buyer control
    • certifications and injection-attack defence not published
    • no false rejection rate, like the rest of the category
    advertisement
  4. 4

    Stripe Identity

    the frictionless option if you are already Stripe, at the highest published price

    79/100

    verdictthe easiest integration in the category and the most expensive published check, from a vendor that publishes almost nothing about how the verification actually works.

    best for
    teams already running payments on Stripe who want verification on the same bill
    price
    $1.50 / verification
    pricing note
    document capture plus selfie biometric match; a us social security number lookup is $0.50 extra. no monthly minimum, custom pricing above 2,000 verifications a month
    free tier
    yes
    doc + selfie
    $1.50
    biometric retention
    1 year; documents 3 years
    free tier
    first 50 free
    self-serve
    yes
    minimum
    none

    if you already take payments through Stripe this is close to free to adopt: same dashboard, same keys, same invoice, no new vendor review. the first fifty verifications are free — a real allotment rather than a trial — there is no monthly minimum, and signup is immediate. for a team that wants identity checks working this afternoon, nothing else here is as fast.

    the price is $1.50, the highest published figure in this ranking and more than four times Didit. you are paying for integration convenience and Stripe's operational reliability rather than for a better check, and whether that trade is worth roughly a dollar a verification depends entirely on your volume.

    retention is middling and worth reading carefully, because it is split. biometric identifiers used to match the selfie to the document are removed within a year, which is reasonable. the photographs and id documents themselves are retained in the dashboard for three years by default, which is longer than most people assume when they read the biometric line and stop there. there is no self-serve control over either — earlier deletion means emailing Stripe's privacy team.

    the bigger weakness is silence. Stripe's public pages say nothing we could confirm about liveness methodology, injection-attack defence, document or country coverage, or security certifications for this product specifically. for most Stripe products that would be unremarkable; for one making a judgement about whether a human being is real, the absence of any published detail is a genuine gap.

    pros
    • +no new vendor, key or invoice if you already use Stripe
    • +first 50 verifications free, with no monthly minimum
    • +biometric identifiers removed within a year
    • +immediate self-serve signup
    cons
    • $1.50 is the highest published price here — over 4x Didit
    • id documents retained three years by default, not one
    • no published detail on liveness, injection attacks, coverage or certifications
    • retention changes require emailing privacy, not a setting
  5. 5

    Shufti

    a flat price and a free tier, with retention handed entirely to you

    76/100

    verdictflat, predictable pricing with a genuinely permanent free tier — from a vendor that applies no default retention of its own, which is either the best or the worst answer depending on your contract.

    best for
    small teams who want a permanent free tier and one flat number above it
    price
    $0.95 / check
    pricing note
    Essentials tier, flat per check up to 20,000 verifications a month, covering facial biometrics with liveness and 3d analysis plus document verification — not broken out by check type. the Free Forever tier carries 10 checks a month with the same feature list
    free tier
    yes
    doc + selfie
    $0.95
    biometric retention
    client-instructed, no default
    free tier
    10 / month, permanent
    self-serve
    yes
    minimum
    none

    Shufti's pricing is the simplest shape in the category: one flat $0.95 per check on the Essentials tier, up to twenty thousand a month, covering document verification and facial biometrics with liveness and 3d analysis. no tier ladder to model, no per-module arithmetic. above that, enterprise is quoted.

    the Free Forever tier gives ten verifications a month permanently with the same feature list and no card required. ten is not much, but it is enough to build and test an integration end to end without a sales conversation or a trial clock, which is more than Veriff, Sumsub or Jumio offer.

    the retention position is unusual and cuts both ways. the services privacy notice states plainly that where Shufti acts as a processor, retention is strictly governed by client instructions and that Shufti applies no default retention period in its own right. read one way that is maximal buyer control. read another it means an inattentive buyer sets no policy at all and nobody is minding the biometric data. separately, Shufti keeps pseudonymised model-training data for twelve to twenty-four months as a controller in its own right — worth knowing if customer faces contributing to a vendor's training set is a line you do not want to cross.

    the flat price hides one thing worth asking about: because $0.95 is not broken out by check type, it is unclear whether a document-only check costs the same as a full document-plus-biometric one. if a meaningful share of your volume needs only the cheaper half, vendors that itemise — Didit at $0.15 for a document check — will cost less. we also could not confirm certifications from a primary page.

    pros
    • +flat $0.95 a check with no tier modelling
    • +permanent free tier of 10 checks a month, no card
    • +liveness with 3d analysis included at every tier
    • +retention explicitly under buyer control, stated in writing
    cons
    • no vendor default retention at all — you must set the policy
    • keeps pseudonymised training data for 12-24 months as controller
    • flat price is not broken out, so document-only checks cost full price
    • certifications could not be confirmed from a primary source
  6. 6

    Sumsub

    a broad compliance suite that will not say what it keeps

    74/100

    verdicta genuinely broad compliance product at a mid-table price, ranked down for the one disclosure this category is judged on and does not make.

    best for
    regulated businesses that need kyc and kyb from one compliance platform
    price
    $1.35 / verification
    pricing note
    Basic tier, bundling id verification with liveness and face match as one figure; $149 monthly minimum, rising through a Compliance tier to custom enterprise pricing
    free tier
    yes
    doc + selfie
    $1.35
    biometric retention
    not disclosed
    free tier
    50 checks, 14-day trial
    self-serve
    yes
    minimum
    $149 / month

    Sumsub sells the full compliance surface rather than just a check — kyc and kyb side by side, with the Compliance tier adding the screening and monitoring a regulated business needs. for a fintech or exchange that would otherwise buy identity verification and business verification from two vendors, consolidating has real value beyond the per-check price.

    the commercial terms are clear enough: $1.35 a verification on Basic with liveness and face match bundled rather than sold as extras, self-serve signup, and a fourteen-day trial with fifty free checks. iBeta testing to ISO 30107-3 level 1 is claimed for presentation-attack detection.

    two things push it down. the $149 monthly minimum is the highest here — triple Veriff's $49 — so at low volume the effective cost per check is far above the list price. and the disclosure gap: we went to the pricing page, the privacy notice hub and the security page, and none of them states how long biometric data is kept or whether the buyer can configure it. the privacy hub links out to a service-delivery notice we could not reach. in a category where Didit deletes with the session and publishes it plainly, not answering the question is itself an answer.

    we also could not confirm SOC 2 or ISO 27001 from the pages we reached, and as with every vendor here there is no published false rejection rate. the product is likely stronger than this entry can evidence — that is rather the point of ranking on what is published.

    pros
    • +kyc and kyb from one compliance platform
    • +liveness and face match bundled into the base price
    • +iBeta tested to ISO 30107-3 level 1
    • +14-day trial with 50 free checks, self-serve signup
    cons
    • biometric retention not disclosed on any page we could reach
    • $149 monthly minimum is the highest in the ranking
    • SOC 2 and ISO 27001 could not be confirmed from primary sources
    • $1.35 is mid-table, four times Didit's rate
  7. 7

    Trulioo

    the widest coverage claim in the category, and not one number

    63/100

    verdictthe broadest claimed document and data coverage anywhere in this ranking, and the shortest retention cap of the sales-led vendors — attached to a pricing page that is a demo booking form.

    best for
    large multinational rollouts where coverage breadth outweighs procurement friction
    price
    quote only
    pricing note
    trulioo.com/pricing exists but displays no per-verification, document or biometric price of any kind — every call to action on the page is book a demo. no minimum, tier or ballpark is published anywhere we could find
    free tier
    no
    doc + selfie
    quote only
    biometric retention
    1 year maximum
    free tier
    no
    self-serve
    no — demo only
    minimum
    not published

    on coverage Trulioo claims more than anyone else here: 195 countries, over 14,000 document types, 450-plus global and local data sources and 43 languages, plus business verification spanning 500 registration number formats. if you are launching in dozens of markets at once and the constraint is whether a vendor can read a particular national id at all, this is the strongest claim in the category.

    it also has the best retention policy of the vendors that do not publish prices, and one of the better ones overall. the facial scan and biometric information policy states the scan is destroyed immediately on completion of a verification check, or up to a year after the last interaction, consistent with the business customer's instructions. a one-year ceiling is half Incode's and Socure's three, and it is published in a dedicated policy rather than buried.

    certifications are stated plainly too — SOC 2 Type II and ISO 27001:2022 in the site footer.

    and then there is no price. the pricing page has no figure on it, there is no self-serve signup, and every route leads to booking a demo. for an enterprise buyer with a procurement process that is normal. for anyone smaller, or anyone trying to model unit economics before committing engineering time, it means you cannot answer the most basic question about this product without getting on a call — which is why it sits below six vendors that will simply tell you.

    pros
    • +195 countries, 14,000+ document types, 450+ data sources claimed
    • +facial scan destroyed on completion, capped at one year
    • +biometric retention published as a dedicated policy
    • +SOC 2 Type II and ISO 27001:2022
    cons
    • no price published anywhere — the pricing page is a demo form
    • no self-serve signup and no free tier
    • no minimum or ballpark disclosed, so unit economics need a sales call
    • no false rejection rate, despite claiming leading match rates
  8. 8

    Incode

    the firmest retention promise here, on a pricing page that does not exist

    60/100

    verdictpublishes a clearer biometric retention commitment than most vendors that publish prices, and no price whatsoever.

    best for
    enterprises already running a procurement process who value a written retention cap
    price
    quote only
    pricing note
    incode.com/pricing returns a 404 — there is no pricing page at all, and the homepage offers only a demo request. no price, minimum, tier or free allowance is published anywhere we could find
    free tier
    no
    doc + selfie
    quote only
    biometric retention
    3 years maximum
    free tier
    no
    self-serve
    no — demo only
    minimum
    not published

    the one thing Incode does better than nearly everyone here is commit to a retention limit in writing, in a standalone biometric data policy rather than a clause buried in a general privacy notice. it keeps biometric data only until the initial purpose for collecting it has been satisfied, or three years after your last interaction, whichever comes first. the purpose-satisfied trigger is the part that matters — it is what Socure's identical three-year cap lacks, and it means the clock can stop early rather than always running the full term.

    everything else about evaluating this product from the outside is a dead end. there is no pricing page: incode.com/pricing returns a 404, not a form or a placeholder. the homepage carries no figure, no tier, no minimum and no free allowance, and offers only a demo request. we found no self-serve signup path at all.

    we also could not confirm liveness methodology, injection-attack defence, document or country coverage, or any security certification from the pages we could reach, and there is no published false rejection rate.

    so the honest summary is narrow: a vendor with a good, clearly written answer to the data question this category is ranked on, and no answer to any other question a buyer would ask first. it ranks here because a retention policy you can read beats a price you cannot — but only just, and only against the other vendors that also refuse to publish.

    pros
    • +biometric retention capped at purpose-satisfied or 3 years, whichever is first
    • +retention published as a dedicated standalone policy
    • +the purpose-satisfied trigger can end retention early, unlike a flat cap
    cons
    • no pricing page at all — /pricing returns a 404
    • no self-serve signup, no free tier, no published minimum
    • liveness, injection-attack defence, coverage and certifications all unpublished
    • nothing about the product can be evaluated without contacting sales
  9. 9

    Jumio

    a long-established vendor that now publishes nothing at all

    52/100

    verdictone of the oldest names in identity verification, ranked last because there is less publicly checkable information about it than about any other vendor here.

    best for
    enterprises with an existing Jumio relationship or a procurement process that expects one
    price
    quote only
    pricing note
    both jumio.com/pricing and jumio.com/pricing/ return 404. the homepage carries no price, tier or minimum, and its only calls to action are get started and request information
    free tier
    no
    doc + selfie
    quote only
    biometric retention
    not disclosed
    free tier
    no
    self-serve
    no — sales only
    minimum
    not published

    Jumio has been doing this longer than most of the companies above it and is a genuinely established enterprise vendor. none of that is in dispute, and none of it is visible from outside.

    there is no pricing page — /pricing and /pricing/ both 404, which means not a gated form but no page at all. the homepage states no price, no tier, no minimum and no free allowance, and offers only get started and request information. we found no self-serve path.

    the retention answer is missing too. the privacy centre is a landing hub linking to an online services privacy notice and a website privacy notice, and the hub itself states no retention period; we could not reach the linked notices. so on the two axes this category is ranked on — what a check costs and how long the face is kept — Jumio publishes neither, where Trulioo and Incode at least publish the second.

    we could not confirm liveness, injection-attack defence, document coverage, certifications or a false rejection rate either. that is why it ranks last: not a judgement that the product is poor, but that among nine vendors it is the one about which a reader can independently learn least, and this site ranks what is published.

    pros
    • +long-established enterprise vendor with a substantial deployed base
    • +maintains a privacy centre and a vulnerability disclosure programme
    cons
    • no pricing page — both /pricing urls return 404
    • no biometric retention period stated on any reachable page
    • no self-serve signup, free tier or published minimum
    • liveness, coverage and certifications could not be confirmed

how this ranking was made

the anchor is one completed verification of a government id document plus a selfie with liveness, at each vendor's cheapest published tier, read from the vendor's own pricing page on 1 september 2026. where a vendor prices the document check and the biometric check separately, both components are given as printed rather than added together.

retention figures come from each vendor's privacy notice, biometric information policy or trust centre — never from a marketing page, and never from a sales claim. where a vendor states no default and defers to the customer contract, the entry says exactly that, because that is a materially different answer from a short retention period.

no comparison post, listicle or 'x vs y' article was used for any figure. that content is close to entirely affiliate-funded in this category, and one of the vendors ranked below publishes its own ranking of its competitors — a conflict that is named on its entry rather than hidden.

false rejection rates are absent throughout because no vendor publishes one. we have not estimated them, and we would rather leave the column empty than fill it with vendor accuracy claims that cannot be checked.

three shortlisted vendors were dropped for blocking automated access to their own public pages; they are named in the intro. none of these vendors are operated by us, and none of the links are affiliate links.

our general methodology and disclosures →

building something that belongs here?

submitting is free and never buys placement — it just puts you in front of us for the next refresh.

submit a service →
was this useful?