fidentity logo
Security Fraud · Gov Legal

fidentity

fidentity is a Swiss platform that combines AI-driven online identity verification, qualified electronic signatures and digital onboarding in one browser-based journey, built for banks, insurers, public administrations and fintechs that need certified remote processes.

Active GDPR compliant Contact Sales API available 18+ Verified by Guidaio
Overview

What is fidentity?

fidentity is a Swiss software company based in Köniz/Liebefeld, near Bern, founded in 2016 by Thorsten Hau (CEO) and Edi Spring (CTO) around a single promise: enabling trust in a digital world. Its platform turns two regulated formalities - proving who someone is, and having them sign - into a browser journey measured in seconds rather than days.

The platform is sold as three combinable modules. IDENT performs fully automated identity verification in three steps: the user scans an identity document, optionally authenticates it through its NFC chip, then passes a liveness check built to detect photo, video, mask and deepfake attacks. SIGN issues a qualified electronic signature (QES) which, under Article 14 of the Swiss Code of Obligations and under ZertES and eIDAS, carries the same weight as a handwritten signature; simple and advanced signatures, and handwritten capture on screen, are also supported. ONBOARD adds a form engine, PDF template filling and due-diligence checks against PEP lists, sanctions lists, organised crime links and domicile databases. A separate consumer-facing journey, simpleSIGN, packages identification and signature into a single flow advertised at 120 seconds.

Every decision is taken by an AI engine within seconds, weighing several hundred factors, and each one is documented in PDF, video and JSON form in the customer dashboard - the vendor describes these decisions as traceable, comparable, and repeatable. The first version of the AI dates from 2018; KPMG has audited FINMA compliance since 2019, and the eIDAS and ZertES certifications were obtained in 2023.

Everything runs in the browser: no app download, no SMS code, no password, with authentication delegated to the device's own biometric login. Identity documents from more than 70 countries are covered. Development and operations remain entirely in Switzerland, with no near-shoring or offshoring, and hosting sits in the Swisscom Wankdorf Tier IV data centre. fidentity is not itself a trust service provider: it acts as a certified registration authority alongside Swisscom Trust Services and SIGN8. Published customers include Bank Avera, Swiss Post, the Swiss Confederation, Valiant and the cantonal banks of St. Gallen, Thurgau and Zug. Full white labelling and multichannel delivery - web, app, mobile, chat, email - complete the offer.

What it does

  • Verify a customer's identity remotely by scanning their identity document and running a liveness check
  • Authenticate the document through its NFC chip, using an Android instant app or an iPhone App Clip
  • Have a document signed with a qualified electronic signature valid in Switzerland and the EU
  • Collect structured data through a form engine, including address, source of funds and portfolio details
  • Generate and pre-fill PDF documents from identification and form data
  • Run PEP, sanctions list, organised crime and domicile checks
  • Manage and review every process from an SSO-protected back office
Audience

When to use fidentity / When not to

A quick filter to help you decide if fidentity is the right fit.

When to use fidentity

  • Regulated financial providers - banks, fintechs - that must identify clients remotely under Swiss anti-money-laundering rules and FINMA circular 2016/7
  • Insurers and public administrations, both named among fidentity's customers, digitising contract signature and citizen-facing procedures
  • Companies whose contracts require a legally prescribed form, such as consumer credit or fixed-term clauses, and therefore a qualified electronic signature
  • HR and onboarding teams that identify new employees or new clients remotely and are working on completion rates - the vendor claims up to 50% better conversion than video identification
  • Organisations bound by a strict Swiss data residency requirement, since development, operations and hosting all stay in Switzerland

When not to use fidentity

  • Individuals looking for a personal signature app: fidentity sells to organisations, and end-user support is handled by the bank, insurer or employer that started the process
  • Buyers who expect self-service: there is no public price, no online sign-up and no autonomous trial, and every project starts with a quote
  • Use cases involving minors: identification is normally reserved for people aged 18 and over, and can only be lowered to 14 on request depending on the use case
  • Users equipped with a tablet only: tablets are treated like desktop computers, so the identification step has to be completed on a smartphone
  • Organisations that need evidential value outside Switzerland and the European legal area, or that are looking for a trust service provider itself - fidentity is certified under ZertES and eIDAS and acts as a registration authority, not as a TSP
Get started

How to use fidentity

A typical end-to-end flow, from setup to results.

  1. Start from the contact form or book a slot with the sales lead through Calendly: there is no online sign-up and no public price list
  2. Choose the subject of your request among the four proposed - IDENT, SIGN, the two combined, or support on an identification or signature already under way
  3. Discuss scope, modules and transaction volumes so that fidentity can prepare a tailored quote
  4. Ask for a test environment or a demonstration, both available on request from the sales team
  5. Plan the integration through fidentity's modern APIs, with custom adapters where legacy applications are involved; the vendor says specific integration requests are answered within a few days
  6. Configure the process: white labelling (colours, fonts, logos), decision criteria per use case, and module chaining by risk profile or channel
  7. Check the technical prerequisites for your users: iOS 16.4+ (Safari 16.4+, Chrome 100+) or Android 8+ (Chrome/Edge 100+, Samsung Internet 20+), knowing that tablets count as desktop computers and force a switch to a smartphone
  8. Go live with a fidentity product manager accompanying the project from onboarding through to go-live
  9. On the end-user side, IDENT runs in three steps - document scan, optional NFC authentication, liveness check - with no installation, no account and no password
  10. On the end-user side, SIGN runs in three steps - authentication, consent, download of the signed document - while your teams monitor and review each case from the SSO back office
Quick read

Pros & Cons

Pros

  • Rare and verifiable certifications: ETSI TS 119 461, DIN EN 419241-1, ETSI EN 319 401, ISO/IEC 30107-3, ISAE 3000 and ISO/IEC 27001, the latter checkable on iafcertsearch.org
  • FINMA compliance audited by KPMG - circulars 2016/7, 2018/3 and 2008/21 - plus CDB 20 and the OFCOM TAV
  • Hosting and development entirely Swiss, in the Swisscom Wankdorf Tier IV data centre, with no offshoring
  • Nothing to install on the end-user side: no app, no SMS code, no password
  • Speed and success rates claimed by the vendor: 60 seconds for an identification, 2 minutes for a QES, under 90 seconds for an onboarding, and more than 85% success on the first attempt
  • AI decisions documented and repeatable, with criteria that can be configured for each use case
  • Unusual openness on data governance: an explicitly appointed Article 27 GDPR representative, a named and detailed list of subprocessors including the product ones, and a dedicated database and container for each customer

Cons

  • No public pricing whatsoever: no pricing page exists, and every deal goes through a quote based on transaction volume and chosen modules
  • No self-service: neither online sign-up nor autonomous trial
  • No public API documentation, even though API integration is a headline argument of the offer
  • End-user support is not provided by fidentity, which refers users back to the bank, insurer or employer behind the process
  • Legal scope limited to Switzerland and the European legal area (ZertES, eIDAS)
  • Tablets are not supported for identification, which forces the user to switch to a smartphone
  • Several governance blanks: no data processing agreement published or announced as available, no information on the languages of the product interface, and no statement on whether customer data is used to train the models
Pricing

Pricing & Plans

fidentity publishes no price. There is no pricing page on the site and the sitemap lists none. The FAQ states that "Costs depend on your individual requirements, your transaction volume, and the modules you choose (IDENT, SIGN, ONBOARD)", with a tailored quote prepared by fidentity and adapted to each customer's processes. No permanent free plan and no free trial is announced: the FAQ mentions test environments and demonstrations available on request, without ever stating that they come at no cost. Service levels - availability, response times, conversion - are likewise agreed individually with each customer. Because no amount is published, no starting price, currency or billing unit is stated on this page.

No named plan and no price grid is published
  • the model is a tailored quote
  • prepared after contact with the sales team
Plan 3
SIGN
  • qualified electronic signature module (QES)
  • priced within the quote
Plan 4
ONBOARD
  • form engine
  • PDF generation and due-diligence checks
  • priced within the quote
Plan 5
  • The three modules are combinable
  • and the quote depends on the combination chosen and on transaction volume
Plan 6
simpleSIGN
  • a separate consumer-facing signature journey hosted on its own subdomain
  • with no published price
Special offers — No promotional offer, discount or programme for students, jobseekers, non-profits or start-ups is published · Test environments and demonstrations are available on request from the sales team, with no indication that they are provided free of charge
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how fidentity handles your data.

GDPR overview

fidentity states on its homepage that its bank-grade security framework "naturally also complies with the data protection regulations according to GDPR (EU) and FADP (Switzerland)". The privacy policy applies both regimes and cites the European Commission adequacy decision for Switzerland of 26 July 2000, confirmed on 15 January 2024. The legal bases invoked are Article 6(1) points a to f and Article 9(2) GDPR. An EU representative under Article 27 GDPR is explicitly appointed: VGS Datenschutzpartner GmbH, Am Kaiserkai 69, 20457 Hamburg, info@datenschutzpartner.eu. Listed rights cover access, rectification, erasure, restriction, portability and objection, plus the right to state a point of view and obtain human review of an automated decision. The Swiss supervisory authority is the FDPIC, with a pointer to the EDPB for the EEA. Note that the policy is written in German and the German version prevails.

Who owns the data?

fidentity AG is the controller for the processing it carries out on its own account. The website privacy policy names Thorsten Hau, at Waldeggstrasse 30, CH-3097 Liebefeld, as the responsible person and data protection adviser, reachable at office@fidentity.ch, while the Data Protection Policy PDF dated 22 May 2026 states that fidentity is a controller of data processing and routes requests to info@fidentity.ch. The picture changes when a business partner makes the service available: that partner then acts as controller and instructs fidentity on processing and transfers. Swiss data protection law applies, together with the GDPR where relevant, and fidentity operates a dedicated database for each customer to ensure strict data separation.

Reuse rights

The data processed is everything shown on the identity document used - sex, names, date of birth - together with images and video of the document and of the person. It serves identity verification, the issuance of the qualified signature and, where the user acts under a contract with a financial provider, anti-money-laundering compliance. Named recipients include supervisory authorities, certification authorities and conformity assessment bodies, Swisscom Trust Services as trust service provider, Begasoft AG for hosting and Finform AG for manual review; the corporate website relies on further processors such as Google, Microsoft Azure, Exoscale, Calendly, Matomo Cloud, bexio and Pipedrive. Profiling and automated decisions are possible, and the user may ask for a human to review an automated decision. Nothing in the published documents grants the end user a right to reuse this material freely on their own initiative: the evidence of each decision is documented in PDF, video and JSON form in the dashboard of the customer that ordered the process. The site never states whether customer data feeds the training of the AI engine, which it describes only as trained on thousands of images and constantly improved.

Data retention & training

Retention summary
Retention is driven by legal archiving duties. The Practice Statement states that fidentity archives legally required identification data for at least 11 years for a Swiss (ZertES) compliant qualified signature, and at least 35 years for an EU (eIDAS) compliant one. The Data Protection Policy keeps data as long as necessary for the purpose, or as long as legally required or permitted, and refers to the Practice Statement for the detail. The FAQ indicates that deletion happens either according to legal requirements or on request, with the GDPR right to erasure in the EU and Swiss data protection law otherwise: data is erased or anonymised once it is no longer needed. An erasure request can be refused where a statutory retention duty applies. Data carriers are kept locked and professionally destroyed at end of life, and central logging is protected against access, deletion and manipulation.
Trains on customer data
Unclear
Subprocessors disclosed
Yes
GDPR contact

Hosting summary

For the product itself, the FAQ states that "All data is stored exclusively in Switzerland in the Swisscom Wankdorf data center (Tier IV)", and the IDENT page adds that data and processes never leave that Swiss data centre and are never passed on to third parties. A Tier IV facility implies redundant systems, physical access controls and high availability. Product hosting is operated by Begasoft AG, Laupenstrasse 17, 3008 Bern, named as a recipient in the Data Protection Policy, and each customer gets a dedicated container and a dedicated database, which keeps customer data strictly separated. The corporate perimeter is different: the website itself runs on Exoscale (Akenes SA) infrastructure in Geneva, the domain resolving to 85.217.163.58 in AS61098, and the website privacy policy describes processing in Switzerland and the EEA - a wider scope than the product, because it covers CRM, HR and marketing tools. The exclusive Swiss residency claim should therefore be read as applying to identification and signature data, not to every corporate tool the company uses.

Hosting countries
🇨🇭 Switzerland
Availability

Where fidentity works

Country-level availability.

Not available in

No country or region is excluded in fidentity's published material. The scope it states certified for use in Switzerland and the European legal area (ZertES, eIDAS) is a certification scope, not a sales or access restriction: identity documents from more than 70 countries are covered, and European expansion was announced from 2022 onwards.
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting fidentity.

  • Contradictory company address: the imprint page gives Alpenstrasse 62, 3126 Kaufdorf, while the site footer, the privacy policy and the commercial register all give Waldeggstrasse 30, CH-3097 Liebefeld. Kaufdorf was the address at incorporation in 2016; the transfer of the seat to Köniz/Liebefeld was published on 25 October 2022, so the imprint is roughly four years out of date
  • Two different contact addresses for the same data protection requests: office@fidentity.ch in the website privacy policy, info@fidentity.ch in the Data Protection Policy PDF
  • No public price of any kind: any cost figure circulating elsewhere cannot be verified against the vendor's own material
  • No public API documentation, although API integration is presented as a key part of the offer - the integration effort cannot be assessed before contacting sales
  • The training of the models on customer data is never addressed: the engine is described as trained on thousands of images and constantly improved, with no word on where those images come from, and no data processing agreement is published or announced as available on request
  • The companies displayed as partners (Begasoft, Cryptomathic, Finform, Approppo, Swisscom, Designsensor, XToniq) are fidentity's own suppliers, not integrations a customer can switch on; likewise the "preferred Languages: en, de, fr" line on the Security page concerns security reports, not the product interface
  • The performance figures - more than 85% success on the first attempt, up to 50% better conversion, 60 seconds, 90 seconds, 2 minutes - are first-party marketing claims, not audited measurements; and the 18-year minimum age can be lowered to 14 on request depending on the use case
Setup

Setup & Integrations

Technical difficulty

Two very different levels. For the end user, the effort is nil: a web journey with no download, no account and no password, on iOS 16.4+ or Android 8+. For the integrator, this is a project rather than a setup. After a quote, integration goes through modern APIs, with custom adapters available for legacy applications, plus white labelling and process configuration by risk profile and channel. A fidentity product manager accompanies customers from onboarding to go-live, and specific integration requests are answered within a few days. The absence of public API documentation makes the effort hard to size beforehand.

Deployment

Web appAPI
Company

Behind fidentity

Company name
fidentity AG
Founded
21/11/2016
Country of origin
🇨🇭 Switzerland
Headquarters
Alpenstrasse 62, 3126 Kaufdorf, Switzerland
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇩🇩 Germany
Legal contact

Fundraising

16 September 2021: financing round announced, with the amount not disclosed
Lead investor Spicehaus Swiss Venture Fund, advised by Spicehaus Partners AG (Switzerland), alongside several experienced angel investors, with a public comment from Heidi Kunz, Investment Manager at Spicehaus Partners AG
The round accompanied the conversion of fidentity GmbH into fidentity AG, recorded in the commercial register journal of 25 June 2021
Share capital raised from CHF 100,000 to CHF 131,816 on 28 September 2021, then to CHF 158,177 on 20 October 2022, then to CHF 192,448 on 14 December 2023, through successive series A, B and C preferred shares
Stated objective: European expansion from 2022 onwards, starting with the countries bordering Switzerland

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Is fidentity a trust service provider?
No. fidentity is a certified registration authority. It works with trust service providers - Swisscom Trust Services and SIGN8 - which issue the qualified certificates behind the signatures.
Where is the data stored?
Exclusively in Switzerland, in the Swisscom Wankdorf data centre (Tier IV). The IDENT page adds that data and processes never leave that Swiss data centre and are never passed on to third parties.
Does the end user have to install an app?
No. Everything runs in the browser, with no download, no SMS code and no password. iOS 16.4 or Android 8 and above are required, and tablets are treated as desktop computers, so the identification has to be completed on a smartphone.
Which identity documents are accepted?
Identity cards and passports from more than 70 countries. Residence permits, driving licences and student cards are accepted as supporting documents, and the platform is announced as ready for the Swiss e-ID.
What is the minimum age?
18 as a rule for an identification with a qualified electronic signature. It can be lowered to 14 on request, depending on the use case.
How much does fidentity cost?
No price is published. Costs depend on your requirements, your transaction volume and the modules you choose, and fidentity prepares a tailored quote. Test environments and demonstrations are available on request, without any statement that they are free of charge.
Which certifications and audits does fidentity hold?
FINMA circular 2016/7, CDB 20, the OFCOM TAV, ETSI TS 119 461, ZertES, eIDAS, ISO/IEC 27001, ISO/IEC 30107-3, DIN EN 419241-1, ETSI EN 319 401 and ISAE 3000, with recurring KPMG audits.
How long is the data kept?
Legal archiving applies: at least 11 years for a Swiss (ZertES) compliant qualified signature and at least 35 years for an EU (eIDAS) compliant one. Outside those duties, deletion follows the legal requirements or a request from the data subject.
Which types of signature are supported?
Simple (SES), advanced (AES) and qualified (QES) electronic signatures, plus a handwritten signature captured on screen. Signing again without a new identification is possible through the device login or Face ID combined with long-lived certificates.
Who supports the person being identified?
The company where the process started - the bank, the insurer or the employer - and not fidentity, which explicitly refers end users back to it.
Conclusion

Should you pick fidentity?

fidentity is a narrow, heavily certified Swiss specialist rather than a general-purpose AI tool. Its strength is the combination it puts under one roof: automated remote identity verification and qualified electronic signature, with the due-diligence checks that regulated onboarding demands, developed and hosted entirely in Switzerland. For a bank, an insurer or a public body that has to satisfy FINMA circulars, ZertES or eIDAS, that single-vendor coverage - backed by ISO/IEC 27001, ETSI and ISO/IEC 30107-3 certifications and by recurring KPMG audits - is a substantive argument, and a company founded in 2016, financed in 2021 and working with cantonal banks and federal clients supports it.

The reservations are just as clear. There is no public pricing of any kind: costs depend on transaction volume and chosen modules, and only appear in a tailored quote. There is no self-service sign-up and no published API documentation, even though API integration is a headline argument, so a technical team cannot size the work before talking to sales. Supporting the person being identified is not fidentity's job either: that is handed back to the bank, insurer or employer who started the process. And the performance figures the site leads with - more than 85% success on the first attempt, up to 50% better conversion than video identification, 60 seconds for an identification - are vendor claims, not independently audited measurements.

The real audience is therefore regulated organisations with a Swiss or European legal footprint and enough volume to justify an integration project - not individuals, and not teams looking to test a signature tool over a weekend. If that describes you, fidentity deserves a place on the shortlist, provided you accept starting with a conversation, a quote and a test environment rather than a sign-up form.