Veridas logo
Security Fraud · Privacy Security

Veridas

Veridas is a Spanish identity verification platform combining document checks, facial and voice biometrics, liveness detection and an anti-fraud layer against deepfakes and injection attacks. It is sold to regulated organisations by contract, in the cloud or on premise.

Active GDPR compliant Enterprise API available Verified by Guidaio
Overview

What is Veridas?

Veridas is an end-to-end identity verification platform built by a Spanish company founded in 2017 as a joint venture with BBVA. Its promise is technological independence: the document engine, the facial engine and the voice engine are all developed in house, which the vendor presents as the reason it can adapt to new fraud techniques without waiting on a supplier.

A verification runs in a few seconds. The platform classifies the identity document without the user having to declare its type, reads it with a proprietary OCR engine that handles Latin, Arabic, Chinese and Cyrillic alphabets, and checks its authenticity — holograms, fonts, signs of tampering — before reading the NFC chip of an electronic passport or ID card and cross-checking it against the printed data. It then compares a selfie with the document photo and runs liveness detection, active or passive, to confirm a real person is in front of the camera. On top of that sits an anti-fraud layer aimed at three attack families: presentation attacks such as printed photos and 3D masks, injection attacks that feed forged media straight into the stream, and large-scale automated fraud.

Around this core the vendor sells face and voice authentication for returning customers, duplicate identity detection, AML screening against sanctions and PEP lists, checks against government databases and qualified electronic signature. Operations teams get a real-time dashboard of the verification funnel and, on premise, a review panel where an agent can inspect every piece of evidence.

Integration comes in three shapes: XpressID, a plug-and-play web and native flow the vendor says can be live in two weeks; direct REST API calls for teams that already own their capture tooling; and Android, iOS and HTML SDKs that capture inside the client's own application. Deployment is on Amazon Web Services in Europe and North America, on Google Cloud in Europe, or entirely on premise. Onboarding journeys can also run inside WhatsApp, Instagram, Facebook and Gmail webviews.

There is no self-service route: no pricing page, no signup, no free tier. Everything goes through a sales conversation or a marketplace private offer.

What it does

  • Verify an identity document and extract its data through proprietary OCR
  • Match a live selfie against the document photo with a NIST-evaluated facial engine
  • Confirm the person is physically present through active or passive liveness detection
  • Block deepfakes, 3D masks, replay attacks and camera-bypassing injection attacks
  • Authenticate returning customers by face or by voice, without a password
  • Screen an applicant against sanctions lists, politically exposed persons and government databases
  • Detect duplicate or synthetic identities already present in a customer database
Audience

When to use Veridas / When not to

A quick filter to help you decide if Veridas is the right fit.

When to use Veridas

  • Compliance, AML and KYC teams in regulated institutions that must onboard customers remotely
  • Banks, neobanks, credit unions and buy-now-pay-later lenders fighting identity fraud at signup
  • Telecom operators, utilities, insurers, healthcare providers and iGaming platforms with regulated onboarding
  • Public bodies and their suppliers, and qualified trust service providers needing a certified identity proofing partner
  • Engineering teams that want to embed verification through REST APIs, mobile SDKs or a plug-and-play web flow

When not to use Veridas

  • Individuals or very small businesses looking for a one-off identity check: there is no self-service signup
  • Anyone who needs a published price list before talking to a salesperson, since none exists on the site
  • Teams hoping for a free plan or a free trial, neither of which is offered anywhere
  • Organisations unwilling to act as data controller, a role Veridas explicitly refuses to take on
  • Buyers wanting to test the full platform unaided: the public mobile app is a controlled demo whose credentials Veridas issues
Get started

How to use Veridas

A typical end-to-end flow, from setup to results.

  1. Request a demo through the website form and talk to one of the vendor's digital identity consultants
  2. Agree the scope, the deployment model and a private offer, either directly or through AWS or Google Cloud Marketplace
  3. Sign the Data Processing Agreement, which Veridas requires before any personal data is processed
  4. Choose an integration route: XpressID plug-and-play, direct REST API calls, or the mobile and web SDKs
  5. Read the public documentation on the vendor's docs site and request access to the full product documentation hub
  6. Wire the orchestration API so it drives document verification, biometric matching and liveness in one flow
  7. Tune the experience through the configurable parameters, from capture guidance to branding
  8. Test in the sandbox provided as part of the post-integration service
  9. Add the optional modules you need: AML screening, government database checks, electronic signature or assisted back office
  10. Monitor conversion, processing times and SLA compliance in the business intelligence dashboard
Quick read

Pros & Cons

Pros

  • Proprietary engines from end to end, independently evaluated by NIST and iBeta
  • Four certifications verified on named certificates: SOC 2 Type II, ETSI TS 119 461, iBeta ISO/IEC 30107-3 and ISO/IEC 42001
  • Data hosted in the European Economic Area by default, with an on-premise option for full control
  • Explicit commitment never to retain production data, with automatic deletion beyond thirty minutes
  • Explicit commitment never to train the biometric engines on end-user production data
  • Three integration routes, from a two-week plug-and-play flow to raw API calls, plus mobile and web SDKs
  • Purchasable through AWS and Google Cloud Marketplace, which lets buyers spend existing cloud commitments

Cons

  • No pricing page at all: the absence is confirmed across the site's full page sitemap
  • The only public rate sits on AWS Marketplace, and that listing itself points buyers to a private offer
  • No free plan and no free trial are advertised anywhere
  • The only published contract terms cover the demonstration app, not the platform itself
  • The ISO 27001 and ISO 9001 certificates put forward are group certificates, not issued to the editor by name
  • Document coverage figures contradict each other between the product page and the KYC page
  • A merger with Fourthline was signed in July 2026 and had not closed, leaving the roadmap uncertain
Pricing

Pricing & Plans

There is no free plan and no free trial. Veridas publishes no pricing whatsoever on its own website: the site carries no pricing page, and none appears in its full page sitemap either. The only public figure comes from the vendor's own AWS Marketplace listing, Veridas ID Verification Platform (Pay-as-you-Go), which quotes 1.37 USD per identity verification, both within a contracted annual package and for each additional verification beyond it. That rate is attached to a twelve-month term and the listing explicitly invites buyers to request a private offer, so it should be read as a list price rather than as a real entry ticket. The platform is also available through Google Cloud Marketplace, which allows buyers to draw on existing cloud commitments.

Plan 1
  • Direct enterprise contract negotiated with the vendor
  • with no published price and no published tiers
Plan 3
  • Google Cloud Marketplace listing of the same platform
Optional add-ons quoted separately
  • IDV Flow with electronic signature
  • AML Screening
  • Government Checks and Support
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Veridas handles your data.

GDPR overview

Veridas is established in Spain, so the GDPR and the Spanish LOPDGDD apply to it directly, including for operations outside the European Union. The company publishes a designated Data Protection Officer, names the Spanish AEPD as its supervisory authority, lists the full set of data subject rights, and undertakes to sign a Data Processing Agreement with every client before any processing starts. It also claims alignment with the California Consumer Privacy Act, BIPA, Mexican and Colombian data protection law, and classifies its biometric systems as low or no risk under the EU AI Act. One caveat matters: the main privacy policy covers the corporate website only. Platform processing is governed by a separate Identity Proofing Services notice, linked but not surfaced in the navigation, and it is that document which carries the operative commitments.

Who owns the data?

For its identity proofing services Veridas always acts as a data processor, never as the controller. The client company decides what happens to end-user data, and Veridas states it never processes that data for its own purposes, acting only on the client's documented instructions. Where the platform runs outside the Veridas cloud, Veridas has no access to the data at all and is not even a processor. Veridas is a controller only for its own website data — contact forms, newsletter, cookies and job applications — under the entity Veridas Digital Authentication Solutions, S.L. A designated Data Protection Officer can be reached at the published GDPR address, and end users are directed to the client for most rights requests.

Reuse rights

End-user data is processed only to verify an identity: the platform reads the identity document, generates an irreversible biometric vector from the face or the voice, compares it with the document photo or a stored reference, and checks liveness. The evidence produced — processed images, similarity scores, integrity checks — is handed to the client, who is free to reuse it under its own privacy policy. Veridas keeps nothing and states it never trains its biometric engines on production data, using dedicated development databases instead. The demonstration mobile application follows a different regime: data captured there is kept for five years for research and development, is never commercialised, and is never made available to customers or end users.

Data retention & training

Retention summary
In production Veridas keeps nothing. Personal data is processed only for as long as the verification takes, typically a few seconds and at most a couple of minutes. The resulting evidence is handed to the client, who becomes responsible for storing it, and the data is then deleted from the Veridas cloud automatically. An auto-delete system erases anything that has remained in the system for more than thirty minutes, or a shorter period agreed with the client. Where the platform runs outside the Veridas cloud, no data reaches Veridas at all. Website data follows ordinary rules: kept as long as needed to answer a request, or until consent to receive communications is withdrawn. The demonstration application is the exception, with data kept for five years before destruction.
Trains on customer data
No
DPA available
Yes
GDPR contact

Hosting summary

By default the platform runs on Amazon Web Services infrastructure located in Germany and Ireland, which keeps processing inside the European Economic Area and means no international transfer in the sense of the GDPR. Veridas also operates AWS regions in Virginia and Oregon to serve customers based in the Americas, but states that this is only done where the Data Processing Agreement with the client provides for it. The same platform is available on Google Cloud Platform in Europe. For organisations that will not place identity data in a vendor's cloud, an on-premise deployment lets the whole platform run inside the client's own infrastructure, in which case Veridas has no access to the data and does not act as a processor at all. The participation of the cloud provider as a sub-processor is agreed in advance with the controller, and any change of provider requires the controller's authorisation. Sub-processors are disclosed by category rather than by name.

Hosting countries
🇩🇩 Germany🇮🇪 Ireland🇺🇸 United States
Hosting regions
EEANorth America
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Veridas.

  • Buying blind on price: with no public rate card, the entry ticket depends entirely on a negotiated private offer
  • Reading the demonstration app terms as the platform contract, when they govern a controlled demo supplied as is
  • Taking the ISO 27001 and ISO 9001 badges as certificates issued to the editor, when they are group certificates
  • Relying on the website privacy policy for platform facts, when it only covers the corporate site and a separate notice governs the service
  • Signing a multi-year commitment while the announced merger with Fourthline has not closed
  • Treating biometric verification as infallible and dropping human review, when the vendor itself ships a manual review panel
  • Forgetting that the client, not the vendor, carries the controller obligations towards the people being verified
Setup

Setup & Integrations

Technical difficulty

Effort depends on the route chosen. XpressID is the lightest: a plug-and-play flow the vendor says can be live in about two weeks, with configuration done through parameters. Direct API calls assume the client already handles capture and simply sends evidence to the orchestration endpoint. The SDKs require an in-house mobile or web team, since they are embedded in the client's own application. On-premise deployment is the heaviest option and assumes internal infrastructure skills. In every case there is no self-service signup: access follows a contract or a marketplace offer, and the full product documentation hub sits behind a form.

Deployment

APIWeb appIOS appAndroid app

Apps stores

Integrations

WhatsApp Facebook Instagram Gmail

Supported languages

EnglishSpanishPortugueseItalian
Company

Behind Veridas

Company name
Veridas Digital Authentication Solutions, S.L.
Founded
05/07/2017
Country of origin
🇪🇸 Spain
Headquarters
Polígono Industrial Talluntxe II, M-10, 31192 Tajonar (Navarra), Spain
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact

Fundraising

Founded in 2017 as a joint venture with BBVA, with an initial share capital of 3,000 EUR recorded at incorporation
BBVA was still described as a shareholder in July 2026 and is stated to remain one in the entity that would result from the Fourthline merger
The Fourthline merger announced in July 2026 was to be partly funded by Finch Capital and by new investors including Rabo Investments, but that funding concerns the combined entity rather than a Veridas round

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does the Veridas platform actually do?
It verifies that a person is who they claim to be. It reads and authenticates an identity document, extracts its data by OCR, compares a live selfie with the document photo using facial biometrics, and confirms the person is physically present through liveness detection. An anti-fraud layer sits on top to block presentation attacks, injection attacks and large-scale automated fraud. The whole sequence takes a few seconds.
How much does it cost?
Veridas publishes no price on its own website, and there is no pricing page anywhere in its sitemap. The only public figure is on the vendor's AWS Marketplace listing, which quotes 1.37 USD per identity verification on a twelve-month term. That same listing tells buyers to ask for a private offer, so the real entry ticket is not public.
Is there a free plan or a free trial?
Neither is advertised. Sandbox access is described as part of the support you get after integration, not as a way to try the product beforehand. The only publicly downloadable piece is a demonstration mobile application, and its terms state that Veridas issues the credentials itself.
How is it integrated?
Three ways. XpressID is a plug-and-play flow for web and native environments that the vendor says can be live in two weeks. Direct REST API calls suit teams that already own their capture tooling. Android, iOS and HTML SDKs capture evidence inside the client's own application. Public documentation is available on the vendor's documentation site.
Where is the data hosted?
By default on Amazon Web Services infrastructure in Germany and Ireland, so within the European Economic Area. Servers in Virginia and Oregon are used for customers operating in the Americas, but only where the Data Processing Agreement provides for it. The platform is also available on Google Cloud in Europe, and can be deployed entirely on the client's own infrastructure.
Is my data used to train the models?
No. Veridas states that it never trains its biometric engines on the data that passes through them in production, and that training happens only during development on separate dedicated databases. Because the commitment is unconditional, there is no opt-out mechanism to speak of.
How long is data kept?
For production services, only for the time needed to run the verification, usually seconds. Results are handed to the client and deleted from the Veridas cloud, with an automatic system that erases anything left in place beyond thirty minutes, or a shorter period agreed with the client. The demonstration application is different: data captured there is kept for five years.
Who is responsible for the personal data?
The client is. Veridas states that for its identity proofing services it always acts as a data processor and never processes end-user data for its own purposes. Where the platform runs outside the Veridas cloud, Veridas has no access to the data at all. Veridas is a controller only for its own website data.
Which certifications can be verified?
Four were checked on certificates naming the company: SOC 2 Type II, ETSI TS 119 461 with EN 319 401, iBeta qualification at levels 1 and 2 of ISO/IEC 30107-3, and ISO/IEC 42001. The ISO 27001 and ISO 9001 certificates the site advertises are issued at group level rather than to the editor by name.
Is there a mobile application?
Yes, a demonstration application published on both the App Store and Google Play under the company's own developer name. It is explicitly a controlled demo: the terms state that Veridas provides the credentials, that the service may be interrupted or withdrawn, and that it is supplied as is.
Conclusion

Should you pick Veridas?

Veridas is a serious, mature player rather than a newcomer. Its engines are evaluated by third parties who publish their results, four of its certifications were checked on documents naming the company, and Gartner listed it as a Visionary in its 2026 identity verification quadrant for the second year running. Its data governance is unusually explicit for this market: it refuses the role of data controller, commits to keeping nothing after a verification, and commits to never training its models on production data. Hosting sits in the European Economic Area by default, with a genuine on-premise option for organisations that will not put identity data in someone else's cloud.

The counterweight is commercial opacity. There is no pricing page, no free tier, no self-service route, and the only public rate lives on a cloud marketplace that immediately redirects buyers to a private offer. The only contract terms published cover a demonstration application rather than the platform, which makes any contractual fact drawn from them revocable for the product itself. Two of the certifications the site puts forward most prominently, ISO 27001 and ISO 9001, are group certificates rather than certificates issued to the editor by name, and the site contradicts itself on how many documents and countries it covers.

One structural uncertainty remains. A merger with Fourthline was signed in July 2026 and, at the time of this review, had not closed: regulatory approvals were still pending and no entry had appeared in the Spanish commercial register. Both companies promised continuity of service, but a buyer signing a multi-year contract should ask where the product line lands afterwards. For a regulated institution with a procurement team and an integration budget, Veridas is a credible candidate; for anyone hoping to sign up online and start verifying tomorrow, it is not.