Questions and answers
Identity verification, answered
The questions we get on the first call: what the platform checks, what it costs, and how it looks to a regulator.
The short answers
No catch. 500 checks per month, free for 1 year, no card. After that it’s $0.33 per check, with no hidden fees and no auto-charges.
No. Start on the free plan and scale pay-as-you-go — no minimum, no contract.
A standard Hosted UI integration takes about 4 hours: POST /v3/session/ → get a session_url → redirect the client. SDKs for iOS, Android, Flutter and React Native are in the docs. The sandbox opens right after sign-up with no payment details required.
You get a clear pass/fail with reasons, and edge cases can be routed to manual review right in the dashboard.
Data is encrypted in transit and at rest and processed under ISO 27001 and GDPR, with flexible hosting including on-premise for Enterprise.
Yes — migration is free, and our team helps map your existing flow to Biometric.Vision.
Yes — we provide audit logs and report exports for regulators and meet international compliance standards.
We run ISO 27001 controls, encryption, access auditing and continuous monitoring to minimize that risk.
Yes — Hosted UI supports white-label theming, and the SDKs let you embed verification natively in your app.
What the platform checks
KYC is the obligation to know your customer: collect documents, confirm the person, assess the risk. eKYC is the same process done remotely. The customer photographs a document and their face, and the system decides: the document is read and checked for authenticity, the face is matched against the portrait inside it, and liveness confirms there is a person in front of the camera rather than a mask or a recording.
Seven modules and an orchestrator on top: Liveness Core, document recognition and authenticity, 1:1 face match, 1:N face search, age estimation, biometric authentication for returning users, and AML screening against sanctions lists and PEP databases. Modules run on their own or inside a single request.
433+ document types from 180+ countries: passports, ID cards, driving licences, residence permits. The system reads the MRZ, validates the checksums, and inspects fonts and portrait geometry for traces of editing. Average parsing time is 1.2 seconds.
The passive Fast mode finishes in under a second at a stated accuracy of 99.1%. The external reference point is the NIST ranking: 37th out of 570+ entries. We do not promise total protection. Ask us — and any other vendor — not for a single accuracy figure but for APCER and BPCER: they show the balance between missed attacks and rejected genuine customers.
Yes, and these are two different jobs. Presentation to the camera — a mask, a print, a screen playing video — is covered by presentation attack detection. Injection that bypasses the camera — a virtual camera, an emulator, a compromised phone — is caught by a separate layer: app integrity control and emulation signals. A vendor with a PAD certificate but no injection detection covers only the first half.
Integration and rollout
The sandbox and a working API key open right after sign-up, no card needed. Hosted UI is the shortest path: POST /v3/session/, take the session_url, redirect the customer, collect the result by webhook. A typical integration takes about four hours of developer time.
Hosted UI is a ready-made verification screen on our side: fastest to ship and no camera work at all. The SDKs for iOS, Android, Flutter and React Native are for when verification has to stay inside your app and look like part of it. Both support white-label styling.
You get a pass/fail verdict with reasons rather than silence: which signal did not match, which check failed. Disputed cases go to manual review right in the dashboard, where an operator sees the session frames, the document data and the rules that fired.
Yes, and migration is free: we take your current flow apart step by step and rebuild it on our modules, rejection thresholds and manual-review routing included. One thing is worth doing in advance — pull the export of historical verifications from your current vendor. After the contract ends it is usually out of reach.
Pricing and limits
500 checks a month for a year, no card and no commitment. On Start, a free check is one module of your choice: liveness, document recognition or face match. The full stack with AML opens on Growth.
$0.33 per full check on Growth: no minimum volume, no contract, pay-as-you-go. Modules can be enabled separately. For banks, lenders and high volumes the terms are quoted individually.
One completed verification session, whatever the outcome: a pass and a fail cost the same. A repeat attempt by the same customer after a rejection is a new session.
No. The free plan does not turn into a paid one by itself: when the allowance runs out, checks stop rather than start billing.
Data and security
In the cloud in the region you pick, or inside your own perimeter: on-premise is available on Enterprise. Data is encrypted in transit and at rest. For banks and lenders required to keep session records for years, on-premise usually turns out to be the only workable option.
ISO 27001 for processing and storage, GDPR requirements for personal data, and an international cybersecurity certification. The list of practices and certificates is on the Security page.
Retention is set by the customer. The biometric template is needed for repeat authentication, the original frames for proving to a regulator that the check happened. If your regulator requires the session video to be kept — five years in Kazakhstan — that is configurable. If it must not be kept, frames are deleted on a schedule.
There is no absolute protection, and promising it would be dishonest. The risk is reduced by ISO 27001 controls, encryption, access auditing and continuous monitoring, and an on-premise deployment keeps the data inside your own perimeter.
Compliance and regulators
No, it carries it out. The regulator says what must be verified and how it must be evidenced; biometrics is the way to do that remotely and leave a trail. Requirements differ by country: in Kazakhstan, since 12 July 2026, banks and microfinance organizations must detect an app launched in an emulated environment and a substituted built-in camera.
The customer is checked against OFAC, EU, UN and HMT sanctions lists, politically exposed person databases, terrorist lists and local stop-lists — in the same request as the identity check. You get one verdict instead of two.
Audit logs and report exports: who decided what, when and under which rule, and which frames and data the decision rested on. On Enterprise the log depth, retention and export formats are tuned to a specific regulator.
Yes. National Bank of Kazakhstan resolutions and NBKR remote identification requirements are taken apart clause by clause on our blog: what exactly a bank or lender has to check, and what covers it technically.
Didn't find your question?
Write to us — you get specifics, not a brochure. Or ask an engineer to run your own onboarding scenario in a demo.