Veridas
Veridas is a Spanish identity verification platform combining document checks, facial and voice biometrics, liveness detection and an anti-fraud layer against deepfakes and injection attacks. It is sold to regulated organisations by contract, in the cloud or on premise.
What is Veridas?
Veridas is an end-to-end identity verification platform built by a Spanish company founded in 2017 as a joint venture with BBVA. Its promise is technological independence: the document engine, the facial engine and the voice engine are all developed in house, which the vendor presents as the reason it can adapt to new fraud techniques without waiting on a supplier.
A verification runs in a few seconds. The platform classifies the identity document without the user having to declare its type, reads it with a proprietary OCR engine that handles Latin, Arabic, Chinese and Cyrillic alphabets, and checks its authenticity — holograms, fonts, signs of tampering — before reading the NFC chip of an electronic passport or ID card and cross-checking it against the printed data. It then compares a selfie with the document photo and runs liveness detection, active or passive, to confirm a real person is in front of the camera. On top of that sits an anti-fraud layer aimed at three attack families: presentation attacks such as printed photos and 3D masks, injection attacks that feed forged media straight into the stream, and large-scale automated fraud.
Around this core the vendor sells face and voice authentication for returning customers, duplicate identity detection, AML screening against sanctions and PEP lists, checks against government databases and qualified electronic signature. Operations teams get a real-time dashboard of the verification funnel and, on premise, a review panel where an agent can inspect every piece of evidence.
Integration comes in three shapes: XpressID, a plug-and-play web and native flow the vendor says can be live in two weeks; direct REST API calls for teams that already own their capture tooling; and Android, iOS and HTML SDKs that capture inside the client's own application. Deployment is on Amazon Web Services in Europe and North America, on Google Cloud in Europe, or entirely on premise. Onboarding journeys can also run inside WhatsApp, Instagram, Facebook and Gmail webviews.
There is no self-service route: no pricing page, no signup, no free tier. Everything goes through a sales conversation or a marketplace private offer.
What it does
- Verify an identity document and extract its data through proprietary OCR
- Match a live selfie against the document photo with a NIST-evaluated facial engine
- Confirm the person is physically present through active or passive liveness detection
- Block deepfakes, 3D masks, replay attacks and camera-bypassing injection attacks
- Authenticate returning customers by face or by voice, without a password
- Screen an applicant against sanctions lists, politically exposed persons and government databases
- Detect duplicate or synthetic identities already present in a customer database
When to use Veridas / When not to
A quick filter to help you decide if Veridas is the right fit.
When to use Veridas
- Compliance, AML and KYC teams in regulated institutions that must onboard customers remotely
- Banks, neobanks, credit unions and buy-now-pay-later lenders fighting identity fraud at signup
- Telecom operators, utilities, insurers, healthcare providers and iGaming platforms with regulated onboarding
- Public bodies and their suppliers, and qualified trust service providers needing a certified identity proofing partner
- Engineering teams that want to embed verification through REST APIs, mobile SDKs or a plug-and-play web flow
When not to use Veridas
- Individuals or very small businesses looking for a one-off identity check: there is no self-service signup
- Anyone who needs a published price list before talking to a salesperson, since none exists on the site
- Teams hoping for a free plan or a free trial, neither of which is offered anywhere
- Organisations unwilling to act as data controller, a role Veridas explicitly refuses to take on
- Buyers wanting to test the full platform unaided: the public mobile app is a controlled demo whose credentials Veridas issues
How to use Veridas
A typical end-to-end flow, from setup to results.
- Request a demo through the website form and talk to one of the vendor's digital identity consultants
- Agree the scope, the deployment model and a private offer, either directly or through AWS or Google Cloud Marketplace
- Sign the Data Processing Agreement, which Veridas requires before any personal data is processed
- Choose an integration route: XpressID plug-and-play, direct REST API calls, or the mobile and web SDKs
- Read the public documentation on the vendor's docs site and request access to the full product documentation hub
- Wire the orchestration API so it drives document verification, biometric matching and liveness in one flow
- Tune the experience through the configurable parameters, from capture guidance to branding
- Test in the sandbox provided as part of the post-integration service
- Add the optional modules you need: AML screening, government database checks, electronic signature or assisted back office
- Monitor conversion, processing times and SLA compliance in the business intelligence dashboard
Pros & Cons
Pros
- Proprietary engines from end to end, independently evaluated by NIST and iBeta
- Four certifications verified on named certificates: SOC 2 Type II, ETSI TS 119 461, iBeta ISO/IEC 30107-3 and ISO/IEC 42001
- Data hosted in the European Economic Area by default, with an on-premise option for full control
- Explicit commitment never to retain production data, with automatic deletion beyond thirty minutes
- Explicit commitment never to train the biometric engines on end-user production data
- Three integration routes, from a two-week plug-and-play flow to raw API calls, plus mobile and web SDKs
- Purchasable through AWS and Google Cloud Marketplace, which lets buyers spend existing cloud commitments
Cons
- No pricing page at all: the absence is confirmed across the site's full page sitemap
- The only public rate sits on AWS Marketplace, and that listing itself points buyers to a private offer
- No free plan and no free trial are advertised anywhere
- The only published contract terms cover the demonstration app, not the platform itself
- The ISO 27001 and ISO 9001 certificates put forward are group certificates, not issued to the editor by name
- Document coverage figures contradict each other between the product page and the KYC page
- A merger with Fourthline was signed in July 2026 and had not closed, leaving the roadmap uncertain
Pricing & Plans
There is no free plan and no free trial. Veridas publishes no pricing whatsoever on its own website: the site carries no pricing page, and none appears in its full page sitemap either. The only public figure comes from the vendor's own AWS Marketplace listing, Veridas ID Verification Platform (Pay-as-you-Go), which quotes 1.37 USD per identity verification, both within a contracted annual package and for each additional verification beyond it. That rate is attached to a twelve-month term and the listing explicitly invites buyers to request a private offer, so it should be read as a list price rather than as a real entry ticket. The platform is also available through Google Cloud Marketplace, which allows buyers to draw on existing cloud commitments.
- Direct enterprise contract negotiated with the vendor
- with no published price and no published tiers
- 1.37 USD per identity verification
- twelve-month term
- private offer expected
- Google Cloud Marketplace listing of the same platform
- IDV Flow with electronic signature
- AML Screening
- Government Checks and Support
Data, GDPR & hosting
A consolidated view of how Veridas handles your data.
GDPR overview
Veridas is established in Spain, so the GDPR and the Spanish LOPDGDD apply to it directly, including for operations outside the European Union. The company publishes a designated Data Protection Officer, names the Spanish AEPD as its supervisory authority, lists the full set of data subject rights, and undertakes to sign a Data Processing Agreement with every client before any processing starts. It also claims alignment with the California Consumer Privacy Act, BIPA, Mexican and Colombian data protection law, and classifies its biometric systems as low or no risk under the EU AI Act. One caveat matters: the main privacy policy covers the corporate website only. Platform processing is governed by a separate Identity Proofing Services notice, linked but not surfaced in the navigation, and it is that document which carries the operative commitments.
Who owns the data?
For its identity proofing services Veridas always acts as a data processor, never as the controller. The client company decides what happens to end-user data, and Veridas states it never processes that data for its own purposes, acting only on the client's documented instructions. Where the platform runs outside the Veridas cloud, Veridas has no access to the data at all and is not even a processor. Veridas is a controller only for its own website data — contact forms, newsletter, cookies and job applications — under the entity Veridas Digital Authentication Solutions, S.L. A designated Data Protection Officer can be reached at the published GDPR address, and end users are directed to the client for most rights requests.
Reuse rights
End-user data is processed only to verify an identity: the platform reads the identity document, generates an irreversible biometric vector from the face or the voice, compares it with the document photo or a stored reference, and checks liveness. The evidence produced — processed images, similarity scores, integrity checks — is handed to the client, who is free to reuse it under its own privacy policy. Veridas keeps nothing and states it never trains its biometric engines on production data, using dedicated development databases instead. The demonstration mobile application follows a different regime: data captured there is kept for five years for research and development, is never commercialised, and is never made available to customers or end users.
Data retention & training
Hosting summary
By default the platform runs on Amazon Web Services infrastructure located in Germany and Ireland, which keeps processing inside the European Economic Area and means no international transfer in the sense of the GDPR. Veridas also operates AWS regions in Virginia and Oregon to serve customers based in the Americas, but states that this is only done where the Data Processing Agreement with the client provides for it. The same platform is available on Google Cloud Platform in Europe. For organisations that will not place identity data in a vendor's cloud, an on-premise deployment lets the whole platform run inside the client's own infrastructure, in which case Veridas has no access to the data and does not act as a processor at all. The participation of the cloud provider as a sub-processor is agreed in advance with the controller, and any change of provider requires the controller's authorisation. Sub-processors are disclosed by category rather than by name.
Things to keep in mind
Risks and trade-offs to weigh before adopting Veridas.
- Buying blind on price: with no public rate card, the entry ticket depends entirely on a negotiated private offer
- Reading the demonstration app terms as the platform contract, when they govern a controlled demo supplied as is
- Taking the ISO 27001 and ISO 9001 badges as certificates issued to the editor, when they are group certificates
- Relying on the website privacy policy for platform facts, when it only covers the corporate site and a separate notice governs the service
- Signing a multi-year commitment while the announced merger with Fourthline has not closed
- Treating biometric verification as infallible and dropping human review, when the vendor itself ships a manual review panel
- Forgetting that the client, not the vendor, carries the controller obligations towards the people being verified
Setup & Integrations
Technical difficulty
Effort depends on the route chosen. XpressID is the lightest: a plug-and-play flow the vendor says can be live in about two weeks, with configuration done through parameters. Direct API calls assume the client already handles capture and simply sends evidence to the orchestration endpoint. The SDKs require an in-house mobile or web team, since they are embedded in the client's own application. On-premise deployment is the heaviest option and assumes internal infrastructure skills. In every case there is no self-service signup: access follows a contract or a marketplace offer, and the full product documentation hub sits behind a form.
Deployment
Apps stores
Integrations
Supported languages
Behind Veridas
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does the Veridas platform actually do?
How much does it cost?
Is there a free plan or a free trial?
How is it integrated?
Where is the data hosted?
Is my data used to train the models?
How long is data kept?
Who is responsible for the personal data?
Which certifications can be verified?
Is there a mobile application?
Should you pick Veridas?
Veridas is a serious, mature player rather than a newcomer. Its engines are evaluated by third parties who publish their results, four of its certifications were checked on documents naming the company, and Gartner listed it as a Visionary in its 2026 identity verification quadrant for the second year running. Its data governance is unusually explicit for this market: it refuses the role of data controller, commits to keeping nothing after a verification, and commits to never training its models on production data. Hosting sits in the European Economic Area by default, with a genuine on-premise option for organisations that will not put identity data in someone else's cloud.
The counterweight is commercial opacity. There is no pricing page, no free tier, no self-service route, and the only public rate lives on a cloud marketplace that immediately redirects buyers to a private offer. The only contract terms published cover a demonstration application rather than the platform, which makes any contractual fact drawn from them revocable for the product itself. Two of the certifications the site puts forward most prominently, ISO 27001 and ISO 9001, are group certificates rather than certificates issued to the editor by name, and the site contradicts itself on how many documents and countries it covers.
One structural uncertainty remains. A merger with Fourthline was signed in July 2026 and, at the time of this review, had not closed: regulatory approvals were still pending and no entry had appeared in the Spanish commercial register. Both companies promised continuity of service, but a buyer signing a multi-year contract should ask where the product line lands afterwards. For a regulated institution with a procurement team and an integration budget, Veridas is a credible candidate; for anyone hoping to sign up online and start verifying tomorrow, it is not.
- Choosing a selection results in a full page refresh.
- Opens in a new window.