Nect
German identity wallet combining AI-driven remote identity verification, qualified electronic signatures, KYC and KYB due diligence and digital document delivery. Certified to eIDAS and ISO/IEC 27001, it claims over 18 million wallet users across Europe.
What is Nect?
Nect is a digital identity wallet built by Nect GmbH in Hamburg, Germany. Its premise is that an identity should be proven once and reused afterwards: a user digitises an identity document into the Nect Wallet app, and every later check draws on that verified record instead of starting again. The company claims more than 18 million wallet users in Europe and over 130 customers.
The platform is sold as five building blocks. Nect Ident handles identity verification, with AI recognising the document presented and routing the user into the right flow: Auto Video Ident using a document scan and a selfie video, the eID procedure reading the German ID card over NFC, ePass reading a passport chip and machine-readable zone, or ReIdent reusing an identity already in the wallet. Coverage extends to more than 150 identification documents, with passports from over 180 countries. Nect Sign covers electronic signatures at the simple, advanced and qualified levels; the vendor deliberately declines to offer the simple variant on its own, arguing it lacks legal weight. Nect Box replaces paper mail with digital delivery of contracts, policies and notices, invited by email, SMS, QR code or a single letter. KYC/KYB adds due diligence on individuals and companies: an AI-generated risk profile, an audit-proof AML report, automated PEP, sanctions and terrorism screening, ongoing monitoring, automatic register queries and beneficial-owner determination. The EUDI Wallet strand positions Nect as an intermediary — a connector or verifier — ahead of the European deadline of 2027.
Security is the selling point. Liveness detection is patented, using vibration artefacts in image and sound as a digital watermark so that pre-recorded videos fail, and the 'Put Your Face Here' feature adds randomised movement prompts. Three European patents cover these mechanisms. The company holds ISO/IEC 27001:2024 and eIDAS certificates issued to Nect GmbH by the accredited body datenschutz cert GmbH, meets the 'high' assurance level of BSI-TR 03147, and its ePass procedure is listed by gematik as the first remote video identification method accepted for the German telematics infrastructure.
What it does
- Verify a person's identity remotely in about three minutes and two steps, choosing automatically between video, NFC eID, passport chip or a previously verified wallet identity
- Run anti-money-laundering due diligence on individuals and companies, with automated PEP, sanctions and terrorism-list screening
- Sign contracts with a qualified electronic signature that meets the written-form requirement
- Determine beneficial owners automatically and reconstruct a company's ownership structure
- Query the transparency register, the commercial register and the shareholder list automatically
- Deliver contracts, policies and notices digitally instead of by post, with tamper-proof storage
- Check a user's age by comparing the expected age against the apparent age from the document photo and selfie
When to use Nect / When not to
A quick filter to help you decide if Nect is the right fit.
When to use Nect
- Compliance, AML and financial-crime teams in banks and payment firms that must run KYC on individuals and KYB on companies, including PEP, sanctions and terrorism-list screening.
- Insurers, health insurance funds and telecoms operators onboarding customers remotely and needing a legally recognised identity check rather than a self-declared one.
- Public-sector and eGovernment bodies that require the 'high' assurance level of BSI-TR 03147 for citizen-facing digital services.
- Organisations whose contracts must satisfy the written-form requirement, and that therefore need a qualified electronic signature equivalent to a handwritten one.
- Operators subject to age restrictions, such as state lotteries, gambling platforms, online drinks retailers and adult-content services.
When not to use Nect
- Buyers who need a published price list: the whole site carries no pricing page at all, so no entry ticket or order of magnitude can be assessed before contacting sales.
- Teams wanting to self-serve, since there is no online sign-up on the business side and every route leads to a demo request form.
- Developers who need to evaluate the integration before talking to sales, as the documentation host answers with an authentication challenge and no public API reference exists.
- Organisations operating far outside the German-speaking market, given that the offering is anchored in German frameworks such as gematik, BSI, VDG and GwG.
- Individuals under 16, who are excluded by the terms of use, and anyone unwilling to submit biometric data, which the identification procedure cannot work without.
How to use Nect
A typical end-to-end flow, from setup to results.
- Identify which building block fits the need: Nect Ident for verification, Nect Sign for signatures, Nect Box for digital mail, KYC/KYB for due diligence, or the EUDI Wallet track
- Submit the sales enquiry form, selecting a department such as compliance, IT, KYC and fraud, or digitalisation, and a subject matching the product of interest
- Discuss scope and commercial terms with the vendor, since there is no published price list and no online sign-up on the business side
- Agree the integration route, either directly or through an integration partner such as a distributor or IT service provider
- Obtain access to the integration documentation, which is not public and sits behind an authentication challenge
- Embed the entry point into the customer journey, for example an onboarding QR code on the website, an email or SMS invitation, or a branded portal inside the Nect Wallet
- Have the end user install the Nect Wallet app on iOS 17 or later, or on Android
- Guide the user through a scan of the identity document and a selfie video, completed in roughly three minutes and two steps
- For due diligence, create the client record, let the automated invitation and register queries run, then read the risk assessment
- Download the audit-proof report and rely on continuous monitoring and automatic re-checks for follow-up obligations
Pros & Cons
Pros
- Certificates are issued to the company itself by a named accredited body, datenschutz cert GmbH, with certificate numbers — not borrowed from a hosting provider
- The ePass procedure is listed by gematik as the first and so far only remote video identification method with proven security suitability for the German telematics infrastructure
- Meets the 'high' assurance level of BSI-TR 03147, audited by an accredited conformity assessment body
- Core technology is developed in-house and protected by three European patents
- A very large installed base means many users are already verified, which shortens recurring checks through ReIdent
- Processing is advertised on German servers, and the app policy states that no personal data is processed in third countries
- The consumer app is free of charge, rated 4.8 from 69,270 reviews on the German App Store, and covers documents from a very wide range of countries
Cons
- No public pricing whatsoever: a sitemap of 685 pages contains no pricing page, so the cost cannot be assessed without contacting sales
- Nothing is said about a free trial on the business side
- Integration documentation is closed, the documentation host returning an authentication challenge, and there is no public API reference
- Audience figures contradict each other across the site: 18 million users on the homepage, 16 million on the Nect Box page and 13 million on the security page
- The homepage advertises 4.8 from 46,689 reviews while the German App Store reported 69,270 reviews on 4 September 2026, so the published count is out of date
- The offering is heavily anchored in German frameworks, and the app itself is available in only three languages while the marketing site exists in eighteen
- Neither a consolidated list of subprocessors for product data nor any statement about AI model training on customer data is published
Pricing & Plans
No price is published. The site carries no pricing page anywhere across its 685 indexed pages, and the business offering is sold under contract, with a demo request form as the only entry point. No amount, currency or billing unit is therefore stated, and no free trial is announced for business customers. A free offering does exist, but on the consumer side only: the Nect Wallet app is listed at 0.00 EUR, and section XI of the terms of use states that users are not required to pay any fees for using the procedures themselves, while reserving the right to introduce such fees later if partners are not integrated. The only quantified economic claim concerns Nect Box, described as up to 70 percent cheaper than paper mail.
Data, GDPR & hosting
A consolidated view of how Nect handles your data.
GDPR overview
Implementation is concrete rather than declarative. Nect GmbH is established in Germany, so the GDPR applies directly and no Article 27 representative is required or named. A data protection officer is appointed and reachable at the company's postal address, with privacy@nect.com as the general contact and a dedicated data-subject-rights portal on the support site. The policies cite access, rectification, erasure, restriction and portability, and note that sections 34 and 35 BDSG apply alongside. The app privacy policy states that no processing of personal data takes place in third countries, and Nect Sign is advertised as GDPR-compliant processing on German servers. The marketing website is a separate matter: it uses Google, LinkedIn and Meta tools whose transfers outside the EU rely on standard contractual clauses under Article 46.
Who owns the data?
Roles shift depending on the product. For Nect Ident and for anything stored in the Nect Wallet, Nect GmbH acts as the controller under Article 4(7) GDPR. For Nect Sign it describes itself, exceptionally, as a processor under Article 28, handling data solely on the documented instructions of the customer that commissioned the signature. Once a document is signed and filed in the wallet, Nect becomes controller again, while every recipient of the signed document becomes responsible for its own copy. Biometric processing rests on the user's explicit consent under Articles 9(2)(a) and 6(1)(a), revocable at any time without justification.
Reuse rights
Data is collected to confirm an identity to a partner organisation and is not offered back to the end user as a reusable asset in any general sense. What the user does get is reuse within the product: an identification already completed in the Nect Wallet can be presented again for another service or contract through ReIdent, without repeating the check. Disclosure to partners is deliberately narrow. The selfie video is not passed to statutory health insurance funds, and where an integration partner such as a distributor or IT provider sits in the chain, only a success message about the verification status is transmitted. Where anti-money-laundering or telecommunications law requires it, a copy of the identity document and of the selfie recording are sent in addition. Consent may be withdrawn at any time with future effect.
Data retention & training
Hosting summary
Two perimeters must be kept apart. The product is advertised as processing on German servers: Nect Sign is described as GDPR-compliant processing on servers in Germany, and the app privacy policy states plainly that no processing of personal data takes place in third countries. Service providers supporting the platform, covering hosting and managed services, are engaged as processors under Article 28 GDPR, but they are not named individually. The scope of the ISO/IEC 27001 certificate covers the technical infrastructure in offices and data centres. The marketing website is separate and less strictly bounded. It is hosted by Hostinger International Ltd, a Cyprus-registered company, on an address resolving to Frankfurt in Germany. Hostinger also operates data centres outside the EU and EEA, in which case transfers rest on standard contractual clauses under Article 46. The sales contact form runs on Salesforce, whose European server location is given as Frankfurt am Main. Jurisdiction throughout is German, with the terms governed by the law of the Federal Republic of Germany.
Things to keep in mind
Risks and trade-offs to weigh before adopting Nect.
- Biometric data is central and irreplaceable here: the identification procedure cannot run without it, so a user who is uneasy about facial and voice measurement has no partial path, only consent or abstention.
- Consent can be withdrawn only with future effect, and statutory retention under money-laundering, commercial and tax law can hold records for six to ten years, so withdrawal does not erase what already exists.
- The site states three different user counts on three pages, 18, 16 and 13 million, and an App Store review count that no longer matches the store, so headline figures should not be quoted without checking.
- Security claims on the site mix two different things: certificates genuinely issued to Nect and 'ISO-certified data centres' that describe the hosting provider. Only the former says anything about the vendor.
- The vendor's role shifts between controller and processor depending on the product, which makes accountability harder to follow for a customer assuming a single relationship throughout.
- Nothing on the site addresses whether customer or user data is used to train AI models, and no opt-out is documented, so this cannot be assumed either way.
- A reusable identity concentrates risk: one wallet unlocking many services is convenient, but it also makes the wallet and the device holding it a single high-value target.
Setup & Integrations
Technical difficulty
Uneven, and it depends which side you sit on. For the end user there is effectively no difficulty: install the app, scan a document, record a selfie, with iOS 17 or later required on Apple devices. For the buying organisation it is an integration project, not a sign-up. There is no self-service onboarding, the commercial conversation comes first, and the integration documentation is not public. Entry points are lightweight once agreed, such as an onboarding QR code, an email or SMS invitation, or a branded portal inside the wallet, and the vendor supports delivery through integration partners.
Deployment
Apps stores
Supported languages
Behind Nect
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What identification procedures does Nect offer?
How long does an identity check take?
Which certifications does Nect actually hold?
What does it cost?
Is there a minimum age?
Where is the data hosted?
Is there an API?
Are there mobile apps?
How does Nect prevent fraud?
Is Nect ready for the EUDI Wallet?
Should you pick Nect?
Nect is best understood as regulated identity infrastructure rather than a general-purpose AI tool. It targets organisations that cannot simply take a customer's word for who they are: banks, insurers, health insurance funds, telecoms operators, state lotteries and public bodies, all of which face a legal test their onboarding must pass.
On that ground the evidence is unusually solid. The ISO/IEC 27001 and eIDAS certificates are issued to Nect GmbH itself by a named accredited body and carry certificate references, which is rarer than the volume of security claims across the market would suggest. The gematik listing of the ePass procedure for the German telematics infrastructure, the 'high' assurance level under BSI-TR 03147, and three European patents on liveness detection all point the same way. The reuse model, where a verified identity is presented again through ReIdent, is a genuine advantage for recurring checks, and the anti-money-laundering module goes beyond identity into screening, beneficial ownership and continuous monitoring.
The reservations are about transparency rather than substance. There is no published price at any point, no stated free trial for business buyers, and no public integration documentation, so a prospective customer cannot size the commitment before entering a sales conversation. The site also contradicts itself on how many users it has, quoting eighteen, sixteen and thirteen million on different pages, and its published review count lags the App Store. Nothing is said about whether customer data trains any model.
For a buyer inside the German-speaking market with a compliance obligation to meet, this is a credible and well-evidenced option. For anyone shopping on price or expecting to evaluate it unaided, the closed commercial posture will be the obstacle.
- Choosing a selection results in a full page refresh.
- Opens in a new window.