Facephi Compliance logo
Security Fraud · Privacy Security

Facephi Compliance

Facephi Compliance is the Spanish biometrics vendor's regulatory stack for financial institutions, uniting KYC onboarding, AML and sanctions screening and transaction monitoring behind explainable AI and audit-ready evidence trails. Pricing is quoted on request.

Active GDPR compliant Contact Sales API available 14+ Verified by Guidaio
Overview

What is Facephi Compliance?

Facephi Compliance, marketed as Lead in Compliance, is the regulatory arm of Facephi, a Spanish digital identity vendor headquartered in Alicante and listed on BME Growth and Euronext Growth Paris. Rather than a standalone tool, it is the compliance module of the Facephi Identity Platform, sold to banks, neobanks, fintechs, crypto platforms and payment service providers that must satisfy KYC, AML and fraud-prevention mandates in several jurisdictions at once.

The offering is organised around three product domains. KYC and digital onboarding covers remote identity verification: automated document checks with OCR across more than 195 countries, real-time validation against national population registers, liveness detection against presentation and injection attacks, facial matching with deepfake protection, risk-based customer profiling to graduate CDD and EDD, and electronic signature aligned with eIDAS, ECTA and regional laws. AML and sanctions screening adds real-time screening against OFAC, UN, EU and domestic TFS designations, dynamic PEP identification, adverse media monitoring driven by natural language processing, and beneficial ownership verification at the 25% threshold FATF guidance recommends. Transaction monitoring and fraud prevention looks for structuring, layering, rapid movement and mule account networks, layering behavioural biometrics, device intelligence, synthetic identity detection and predictive risk scoring on top.

Underneath sits a three-part architecture: multi-modal biometrics (face with passive liveness certified to ISO/IEC 30107-3, fingerprint, voice, behavioural signals and verifiable credentials), an AI engine combining supervised learning, unsupervised anomaly detection, NLP and graph analytics, and a reporting layer that produces STR and SAR documentation, connects to national databases such as RENAPO, DHA, INE and CURP, and exposes an API-first design for core banking integration. On-premise deployment is offered where data sovereignty demands it.

Facephi positions the product on European regulatory heritage — built under PSD2, eIDAS and the GDPR, and engineered ahead of PSD3 — and backs it with third-party certification: ISO 27001, SOC 2 Type 2, iBeta Levels 1 and 2, Spain's ENS High category, the UK DIATF and Canada's DIACC framework, alongside published NIST FRTE and FATE results. Territory pages cover Europe, LATAM, MENA, NORAM, Canada, South Africa and the UAE. No pricing is published anywhere: access begins with a demo request.

What it does

  • Verify identity remotely with OCR across 195+ countries, passive liveness detection and 1:1 or 1:N facial matching
  • Screen customers in real time against OFAC, UN, EU and domestic TFS sanctions designations
  • Identify politically exposed persons dynamically, including foreign and international-organisation PEPs
  • Monitor transactions for structuring, layering, rapid movement and mule account activity
  • Verify beneficial ownership against the 25% threshold set out in FATF guidance
  • Generate STR and SAR filings automatically, with timestamped audit trails
  • Scan global news sources for adverse media using natural language processing
Audience

When to use Facephi Compliance / When not to

A quick filter to help you decide if Facephi Compliance is the right fit.

When to use Facephi Compliance

  • Banks and neobanks running KYC and AML programmes across several jurisdictions at once
  • Fintechs and payment service providers that must reconcile onboarding speed with regulatory defensibility
  • Crypto exchanges and digital-asset platforms exposed to the FATF Travel Rule, MiCA and FinCEN requirements
  • Compliance teams losing capacity to false positives in sanctions screening and transaction monitoring
  • Institutions preparing an AML/CFT audit and needing timestamped, explainable evidence trails

When not to use Facephi Compliance

  • Individuals and freelancers: this is an enterprise contract with no self-service sign-up
  • Buyers who need a published price before speaking to a salesperson, since no rate card exists
  • Teams looking for a free plan or a trial period to evaluate the product on their own
  • Organisations without engineering capacity, as adoption means a REST API and SDK integration project
  • Anyone wanting a single compliance module off the shelf, detached from the wider Facephi Identity Platform
Get started

How to use Facephi Compliance

A typical end-to-end flow, from setup to results.

  1. Start on the Lead in Compliance pages and pick the entry point that matches your case: by product, by industry or by territory
  2. Download the AML/CFT Audit Checklist — 13 control areas and more than 100 evidence items, aligned with FATF — to benchmark your current programme
  3. Request a demo through the site form, giving your name, business email, company, role, industry, country and requirement
  4. Work through scoping with the Facephi team, since there is no self-service sign-up and no published rate card
  5. Agree the deployment model: SaaS, PaaS, IaaS or on-premise, across web, Android, iOS, Windows or Linux
  6. Integrate through the REST APIs — the Identity API for the SelphID and Selphi services, the Landing API for generated landing URLs secured by an API key
  7. Consult the technical documentation on docs.facephi.com and docs.identity-platform.io while building
  8. Design verification and authentication journeys in Design Studio, the platform's no-code flow builder
  9. Connect the national databases your market requires, such as RENAPO, DHA, INE or CURP
  10. Register on the Customer Support Center at desk.facephi.com to raise tickets, with critical incidents answered in under an hour
Quick read

Pros & Cons

Pros

  • Unusually deep third-party certification: ISO/IEC 27001:2022, 27017, 27018, 27701, 22301, 9001, 20000-1, SOC 2 Type 2 and Spain's ENS High category
  • Biometric accuracy measured publicly by NIST: FRTE 1:1 at a 0.5% error margin, FRTE 1:N at 1% over a 1.6 million identity gallery, and first place in FATE PAD
  • National trust frameworks recognise the vendor, including UK DIATF as an identity service provider, Canada's DIACC PCTF and Spain's SEPBLAC video identification circulars
  • Identity, account and transaction signals are handled in one stack instead of being stitched together from point solutions
  • Audit-ready by design, with explainable AI, evidence trails and automated regulatory reporting
  • Website user data is hosted on servers inside the European Union, with standard contractual clauses for any transfer beyond the EEA
  • The vendor is publicly listed and audited, so its financial standing can be checked independently

Cons

  • No pricing whatsoever: neither a pricing page nor a single figure appears in the Spanish or English sitemaps
  • No free plan and no trial, so the product cannot be evaluated without going through a sales conversation
  • No support email is published; help runs exclusively through the desk.facephi.com portal and the chat
  • No Data Processing Agreement is published or offered on request, and no subprocessor list exists
  • The vendor never states whether customer data is used to train its models, while advertising self-learning AI
  • Headline metrics — 98% detection accuracy, 94% fewer false positives, $50M+ potential savings — come without any published methodology
  • The English Legal Notice renders the company as FACEPHI BIOMETRICS Ltd., a form unknown to Spanish law, while the Spanish version and the privacy policy say FACEPHI BIOMETRIA S.A.
Pricing

Pricing & Plans

No pricing is published. Facephi operates no public rate card, no pricing page and no free plan, and neither a starting price, a currency nor a billing unit could be established from the site. Access to Facephi Compliance runs entirely through a demo request or a sales conversation. The investor pages describe the commercial model rather than a tariff: recurring revenue from annual and monthly licences, cloud and support, and non-recurring revenue from specific and perpetual licences, certifications and consultancy, sold both directly and through partners.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Facephi Compliance handles your data.

GDPR overview

Implementation is explicit and unusually detailed. Facephi states that it is subject to the GDPR (Regulation (EU) 2016/679) and to Spanish Organic Act 3/2018 (LOPDGDD), and designates a Data Protection Officer at dpo@facephi.com. Access, rectification, erasure, objection, portability and restriction are all named, exercised by email with proof of identity, with a right of complaint to the Spanish Agency for Data Protection. The Trust Center adds ISO/IEC 27701 for privacy information management and ISO/IEC 27018 for personal data in public clouds, membership of the AEPD Digital Pact since 2021, and claimed alignment with the CCPA and with Argentine, Brazilian, Chilean, Colombian, Mexican, Ecuadorian and Peruvian data protection law. No Article 27 representative is designated, which is consistent: the company is established in Spain, inside the Union.

Who owns the data?

FACEPHI BIOMETRIA S.A. — tax code A-54659313, LEI 959800H5NSTQNR25786, registered at Avenida Perfecto Palacio de la Fuente 6, 03003 Alicante — is named as the data controller for the website and the FACEPHI Portals. It also owns the intellectual and industrial property rights over the published content, and browsing transfers none of them. Users warrant that the data they submit is accurate and that they hold the rights to any content they upload. One boundary matters: this policy governs the corporate site and its portals, not the biometric data Facephi processes on behalf of its client institutions.

Reuse rights

No. Facephi reserves all intellectual and industrial property rights over the site and the Portals, and the Legal Notice expressly forbids reproduction, distribution, public communication, transformation or any retrieval by scraping without prior written authorisation. Visitors hold only a private right of use. Personal data is processed for named purposes — press and newsletter, the careers portal, the investor portal, the partner and client portal, and audiovisual recording of Teams sessions — on the basis of consent, contractual and pre-contractual measures, legitimate interest or legal obligation. Disclosure to third parties happens only where the law requires it: courts, the tax authority, financial auditors and supervisory bodies. Suppliers acting as processors may access data under signed processing contracts, but no named list of them is published. Nothing on the site states whether customer data feeds model training, while the marketing pages advertise self-learning AI and risk scoring built on transactional data.

Data retention & training

Retention summary
Facephi keeps a user's personal data for as long as they remain a user of the FACEPHI Portals — that is, until they close their account, withdraw consent, or exercise their right to erasure or objection. After that point the data is not deleted outright: it is blocked and held in restricted status for five years, so the company can answer any liability arising from the processing before the competent authorities. Erasure and objection requests go to the Data Protection Officer at dpo@facephi.com, with proof of identity. Note the boundary: these rules describe the corporate website and its portals. No retention period is published for the biometric data Facephi processes on behalf of its client institutions, which is the more sensitive question for a prospective buyer.
Trains on customer data
Unclear
GDPR contact

Hosting summary

The privacy policy is explicit on one point: personal data from the FACEPHI Portals is hosted on servers within the European Union. Facephi states that, as a general rule, it neither transfers nor processes data outside the European Economic Area; where a transfer does occur, it relies on European Commission adequacy decisions and on standard contractual clauses agreed with the recipients. No specific country and no cloud provider is named, so the jurisdiction is described at regional level only. Cloud practice is backed by ISO/IEC 27017 for cloud service security controls and ISO/IEC 27018 for personal data in public clouds. Separately — and this is a customer-side matter rather than a statement about Facephi's own hosting — on-premise deployment is offered for Saudi Arabia, the United Arab Emirates, Qatar, Bahrain, Kuwait, Oman and South Africa, where data sovereignty rules apply. An AWS Qualified Software badge appears on the homepage and IBM Cloud is named as a partner, but neither is presented as the hosting location for user data.

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Facephi Compliance.

  • Biometric data is special category data: check what your contract says about retention and deletion, because the published privacy policy covers only the website and its portals
  • The absence of a published DPA and subprocessor list shifts the burden onto your procurement team, so insist on both before signing
  • Silence on model training is a real gap: if your end users' biometric or transactional data may improve the vendor's models, settle it contractually rather than assuming
  • Automated risk scoring and PEP or adverse media flags can produce false accusations, so keep a human review path and a route for individuals to contest a decision
  • Certifications listed on the Trust Center belong to Facephi and its biometric technology as a whole, not necessarily to the compliance module alone — ask which scope each certificate covers
  • Opaque pricing weakens budget planning and renewal leverage, since total cost only becomes visible after a full sales cycle
  • Facial recognition deployed at scale carries bias and accessibility risks; aggregate NIST accuracy figures do not describe the experience of every demographic group among your customers
Setup

Setup & Integrations

Technical difficulty

High, and unavoidably so. There is no self-service route: adoption starts with a demo request and a contract. Integration is an engineering project built on REST APIs and SDKs, with an API-first design intended for core banking systems, and deployment can be SaaS, PaaS, IaaS or on-premise across web, Android, iOS, Windows and Linux. Design Studio offers no-code flow building once the platform is in place, but connecting national databases such as RENAPO, DHA, INE or CURP adds external dependencies and regulatory lead times. Support carries stated targets: under one hour for critical incidents, under two for high priority.

Deployment

Web appMobile appAPIIOS appAndroid app

Integrations

IBM Cloud Temenos
Company

Behind Facephi Compliance

Company name
FACEPHI BIOMETRIA S.A.
Founded
INFORMATION_NOT_FOUND
Country of origin
🇪🇸 Spain
Headquarters
Avenida Perfecto Palacio de la Fuente 6, 03003, Alicante - Spain
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact

Fundraising

March 2024 — Hancom Group, one of South Korea's leading software conglomerates, invested EUR 5 million through a capital increase priced at EUR 2.95 per share and became Facephi's second largest shareholder. The binding Memorandum of Agreement was signed in Barcelona on 21 March 2024 and announced on 25 March 2024.
The same agreement granted Hancom an exclusive right and licence to use, sell and distribute Facephi products across the APAC region, with royalties indexed to the operating profit from those sales.
Facephi is dual-listed on BME Growth in Madrid (ES0105029005 — FACE) and on Euronext Growth Paris (ES0105029005 — ALPHI), with 26,624,087 shares outstanding as at 31 December 2025.
A financing transaction with Nice & Green is listed under inside information in the investor section, with no amount published on the site.

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does Facephi Compliance actually cover?
Three product domains: KYC and digital onboarding, AML and sanctions screening, and transaction monitoring with fraud prevention. They are delivered as the compliance module of the Facephi Identity Platform, with dedicated pages by product, by industry and by territory.
How much does it cost?
No price is published. There is no pricing page in either the Spanish or the English sitemap, and no figure appears anywhere on the site. Access starts with a demo request or a sales conversation, and the commercial model mixes recurring licences with perpetual licences, certifications and consultancy.
Is there a free trial or a free plan?
Neither is announced. The site offers a demo on request, which is not the same thing as a self-serve trial, and it never states that a free plan is unavailable either. Evaluation therefore requires contacting the sales team.
Which certifications does the vendor hold?
ISO/IEC 27001:2022, 27017, 27018, 27701, 22301, 9001 and 20000-1, SOC 2 Type 2, Spain's ENS High category, iBeta Levels 1 and 2 under ISO/IEC 30107-3, the UK DIATF, Canada's DIACC PCTF, SEPBLAC video identification circulars, and KISA K-NBTC in South Korea.
Is there an API?
Yes. Facephi exposes REST APIs — the Identity API for its SelphID and Selphi services and the Landing API for generating landing URLs with a valid API key. Documentation lives on docs.facephi.com and docs.identity-platform.io.
Where is the data hosted?
The privacy policy states that personal data from the FACEPHI Portals is hosted on servers within the European Union, with standard contractual clauses covering any transfer outside the EEA. No specific country or cloud provider is named. On-premise deployment is offered for markets with data sovereignty rules.
How do I exercise my GDPR rights?
By emailing the Data Protection Officer at dpo@facephi.com with proof of identity, specifying the right you wish to exercise. Access, rectification, erasure, objection, portability and restriction are all available, and complaints can be filed with the Spanish Agency for Data Protection.
How is support provided?
Through the Customer Support Center at desk.facephi.com and a chat channel; no support email address is published. Stated response targets are under one hour for critical incidents and under two hours for high-priority ones, with 24/7 cover for critical cases.
Conclusion

Should you pick Facephi Compliance?

Facephi Compliance is a credible enterprise offering rather than a light compliance add-on. Its strongest argument is evidence: the biometric engine has been measured publicly by NIST and certified by iBeta to Level 2, the organisation carries an unusually long list of ISO certificates plus SOC 2 Type 2 and Spain's ENS High category, and national frameworks in the United Kingdom, Canada, Spain and South Korea have accredited it. For a compliance buyer, documentation of that quality is worth more than any feature list, and it is the part of the proposition that stands up to independent checking.

The functional scope is genuinely broad. Identity verification, sanctions and PEP screening, adverse media monitoring, beneficial ownership checks, transaction monitoring and mule account detection sit in one stack, with automated STR and SAR generation and explainable audit trails on top — which is precisely the fragmentation problem the vendor argues against.

Two reservations deserve attention. The first is commercial: nothing about cost is public, so budgeting is impossible before a sales cycle, and there is no trial to evaluate the product independently. The second is contractual. No Data Processing Agreement is published, no subprocessor list exists, and the vendor never states whether customer data may be used to train its models while simultaneously advertising self-learning AI. The published privacy policy governs the corporate website and its portals, not the biometric processing carried out for client institutions, so the questions that matter most to a regulated buyer are left to the contract.

Verdict: a well-evidenced choice for regulated institutions with the engineering capacity to integrate it, provided the data governance terms are pinned down in writing before signature.