Nect logo
Security Fraud · Privacy Security

Nect

German identity wallet combining AI-driven remote identity verification, qualified electronic signatures, KYC and KYB due diligence and digital document delivery. Certified to eIDAS and ISO/IEC 27001, it claims over 18 million wallet users across Europe.

Active GDPR compliant Free plan Contact Sales API available 16+ Verified by Guidaio
Overview

What is Nect?

Nect is a digital identity wallet built by Nect GmbH in Hamburg, Germany. Its premise is that an identity should be proven once and reused afterwards: a user digitises an identity document into the Nect Wallet app, and every later check draws on that verified record instead of starting again. The company claims more than 18 million wallet users in Europe and over 130 customers.

The platform is sold as five building blocks. Nect Ident handles identity verification, with AI recognising the document presented and routing the user into the right flow: Auto Video Ident using a document scan and a selfie video, the eID procedure reading the German ID card over NFC, ePass reading a passport chip and machine-readable zone, or ReIdent reusing an identity already in the wallet. Coverage extends to more than 150 identification documents, with passports from over 180 countries. Nect Sign covers electronic signatures at the simple, advanced and qualified levels; the vendor deliberately declines to offer the simple variant on its own, arguing it lacks legal weight. Nect Box replaces paper mail with digital delivery of contracts, policies and notices, invited by email, SMS, QR code or a single letter. KYC/KYB adds due diligence on individuals and companies: an AI-generated risk profile, an audit-proof AML report, automated PEP, sanctions and terrorism screening, ongoing monitoring, automatic register queries and beneficial-owner determination. The EUDI Wallet strand positions Nect as an intermediary — a connector or verifier — ahead of the European deadline of 2027.

Security is the selling point. Liveness detection is patented, using vibration artefacts in image and sound as a digital watermark so that pre-recorded videos fail, and the 'Put Your Face Here' feature adds randomised movement prompts. Three European patents cover these mechanisms. The company holds ISO/IEC 27001:2024 and eIDAS certificates issued to Nect GmbH by the accredited body datenschutz cert GmbH, meets the 'high' assurance level of BSI-TR 03147, and its ePass procedure is listed by gematik as the first remote video identification method accepted for the German telematics infrastructure.

What it does

  • Verify a person's identity remotely in about three minutes and two steps, choosing automatically between video, NFC eID, passport chip or a previously verified wallet identity
  • Run anti-money-laundering due diligence on individuals and companies, with automated PEP, sanctions and terrorism-list screening
  • Sign contracts with a qualified electronic signature that meets the written-form requirement
  • Determine beneficial owners automatically and reconstruct a company's ownership structure
  • Query the transparency register, the commercial register and the shareholder list automatically
  • Deliver contracts, policies and notices digitally instead of by post, with tamper-proof storage
  • Check a user's age by comparing the expected age against the apparent age from the document photo and selfie
Audience

When to use Nect / When not to

A quick filter to help you decide if Nect is the right fit.

When to use Nect

  • Compliance, AML and financial-crime teams in banks and payment firms that must run KYC on individuals and KYB on companies, including PEP, sanctions and terrorism-list screening.
  • Insurers, health insurance funds and telecoms operators onboarding customers remotely and needing a legally recognised identity check rather than a self-declared one.
  • Public-sector and eGovernment bodies that require the 'high' assurance level of BSI-TR 03147 for citizen-facing digital services.
  • Organisations whose contracts must satisfy the written-form requirement, and that therefore need a qualified electronic signature equivalent to a handwritten one.
  • Operators subject to age restrictions, such as state lotteries, gambling platforms, online drinks retailers and adult-content services.

When not to use Nect

  • Buyers who need a published price list: the whole site carries no pricing page at all, so no entry ticket or order of magnitude can be assessed before contacting sales.
  • Teams wanting to self-serve, since there is no online sign-up on the business side and every route leads to a demo request form.
  • Developers who need to evaluate the integration before talking to sales, as the documentation host answers with an authentication challenge and no public API reference exists.
  • Organisations operating far outside the German-speaking market, given that the offering is anchored in German frameworks such as gematik, BSI, VDG and GwG.
  • Individuals under 16, who are excluded by the terms of use, and anyone unwilling to submit biometric data, which the identification procedure cannot work without.
Get started

How to use Nect

A typical end-to-end flow, from setup to results.

  1. Identify which building block fits the need: Nect Ident for verification, Nect Sign for signatures, Nect Box for digital mail, KYC/KYB for due diligence, or the EUDI Wallet track
  2. Submit the sales enquiry form, selecting a department such as compliance, IT, KYC and fraud, or digitalisation, and a subject matching the product of interest
  3. Discuss scope and commercial terms with the vendor, since there is no published price list and no online sign-up on the business side
  4. Agree the integration route, either directly or through an integration partner such as a distributor or IT service provider
  5. Obtain access to the integration documentation, which is not public and sits behind an authentication challenge
  6. Embed the entry point into the customer journey, for example an onboarding QR code on the website, an email or SMS invitation, or a branded portal inside the Nect Wallet
  7. Have the end user install the Nect Wallet app on iOS 17 or later, or on Android
  8. Guide the user through a scan of the identity document and a selfie video, completed in roughly three minutes and two steps
  9. For due diligence, create the client record, let the automated invitation and register queries run, then read the risk assessment
  10. Download the audit-proof report and rely on continuous monitoring and automatic re-checks for follow-up obligations
Quick read

Pros & Cons

Pros

  • Certificates are issued to the company itself by a named accredited body, datenschutz cert GmbH, with certificate numbers — not borrowed from a hosting provider
  • The ePass procedure is listed by gematik as the first and so far only remote video identification method with proven security suitability for the German telematics infrastructure
  • Meets the 'high' assurance level of BSI-TR 03147, audited by an accredited conformity assessment body
  • Core technology is developed in-house and protected by three European patents
  • A very large installed base means many users are already verified, which shortens recurring checks through ReIdent
  • Processing is advertised on German servers, and the app policy states that no personal data is processed in third countries
  • The consumer app is free of charge, rated 4.8 from 69,270 reviews on the German App Store, and covers documents from a very wide range of countries

Cons

  • No public pricing whatsoever: a sitemap of 685 pages contains no pricing page, so the cost cannot be assessed without contacting sales
  • Nothing is said about a free trial on the business side
  • Integration documentation is closed, the documentation host returning an authentication challenge, and there is no public API reference
  • Audience figures contradict each other across the site: 18 million users on the homepage, 16 million on the Nect Box page and 13 million on the security page
  • The homepage advertises 4.8 from 46,689 reviews while the German App Store reported 69,270 reviews on 4 September 2026, so the published count is out of date
  • The offering is heavily anchored in German frameworks, and the app itself is available in only three languages while the marketing site exists in eighteen
  • Neither a consolidated list of subprocessors for product data nor any statement about AI model training on customer data is published
Pricing

Pricing & Plans

No price is published. The site carries no pricing page anywhere across its 685 indexed pages, and the business offering is sold under contract, with a demo request form as the only entry point. No amount, currency or billing unit is therefore stated, and no free trial is announced for business customers. A free offering does exist, but on the consumer side only: the Nect Wallet app is listed at 0.00 EUR, and section XI of the terms of use states that users are not required to pay any fees for using the procedures themselves, while reserving the right to introduce such fees later if partners are not integrated. The only quantified economic claim concerns Nect Box, described as up to 70 percent cheaper than paper mail.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Nect handles your data.

GDPR overview

Implementation is concrete rather than declarative. Nect GmbH is established in Germany, so the GDPR applies directly and no Article 27 representative is required or named. A data protection officer is appointed and reachable at the company's postal address, with privacy@nect.com as the general contact and a dedicated data-subject-rights portal on the support site. The policies cite access, rectification, erasure, restriction and portability, and note that sections 34 and 35 BDSG apply alongside. The app privacy policy states that no processing of personal data takes place in third countries, and Nect Sign is advertised as GDPR-compliant processing on German servers. The marketing website is a separate matter: it uses Google, LinkedIn and Meta tools whose transfers outside the EU rely on standard contractual clauses under Article 46.

Who owns the data?

Roles shift depending on the product. For Nect Ident and for anything stored in the Nect Wallet, Nect GmbH acts as the controller under Article 4(7) GDPR. For Nect Sign it describes itself, exceptionally, as a processor under Article 28, handling data solely on the documented instructions of the customer that commissioned the signature. Once a document is signed and filed in the wallet, Nect becomes controller again, while every recipient of the signed document becomes responsible for its own copy. Biometric processing rests on the user's explicit consent under Articles 9(2)(a) and 6(1)(a), revocable at any time without justification.

Reuse rights

Data is collected to confirm an identity to a partner organisation and is not offered back to the end user as a reusable asset in any general sense. What the user does get is reuse within the product: an identification already completed in the Nect Wallet can be presented again for another service or contract through ReIdent, without repeating the check. Disclosure to partners is deliberately narrow. The selfie video is not passed to statutory health insurance funds, and where an integration partner such as a distributor or IT provider sits in the chain, only a success message about the verification status is transmitted. Where anti-money-laundering or telecommunications law requires it, a copy of the identity document and of the selfie recording are sent in addition. Consent may be withdrawn at any time with future effect.

Data retention & training

Retention summary
Retention varies sharply by data type. Website server logs are kept for 90 days and then deleted automatically. Contact and prospecting data is held for no longer than two years, or until consent is withdrawn. Job applications are deleted after six months at the latest. Identity data is held far longer, because the law requires it. The app privacy policy points to retention obligations under German social security, commercial, tax, banking and money-laundering legislation, generally six to ten years. Records tied to a qualified electronic signature follow Article 24(2)(h) of the eIDAS Regulation together with the Trust Services Act. Data may also be kept for evidential purposes across statutory limitation periods, normally three years and up to thirty in some cases. The right to erasure under Article 17 GDPR applies, subject to those obligations.
GDPR contact

Hosting summary

Two perimeters must be kept apart. The product is advertised as processing on German servers: Nect Sign is described as GDPR-compliant processing on servers in Germany, and the app privacy policy states plainly that no processing of personal data takes place in third countries. Service providers supporting the platform, covering hosting and managed services, are engaged as processors under Article 28 GDPR, but they are not named individually. The scope of the ISO/IEC 27001 certificate covers the technical infrastructure in offices and data centres. The marketing website is separate and less strictly bounded. It is hosted by Hostinger International Ltd, a Cyprus-registered company, on an address resolving to Frankfurt in Germany. Hostinger also operates data centres outside the EU and EEA, in which case transfers rest on standard contractual clauses under Article 46. The sales contact form runs on Salesforce, whose European server location is given as Frankfurt am Main. Jurisdiction throughout is German, with the terms governed by the law of the Federal Republic of Germany.

Hosting countries
🇩🇩 Germany
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Nect.

  • Biometric data is central and irreplaceable here: the identification procedure cannot run without it, so a user who is uneasy about facial and voice measurement has no partial path, only consent or abstention.
  • Consent can be withdrawn only with future effect, and statutory retention under money-laundering, commercial and tax law can hold records for six to ten years, so withdrawal does not erase what already exists.
  • The site states three different user counts on three pages, 18, 16 and 13 million, and an App Store review count that no longer matches the store, so headline figures should not be quoted without checking.
  • Security claims on the site mix two different things: certificates genuinely issued to Nect and 'ISO-certified data centres' that describe the hosting provider. Only the former says anything about the vendor.
  • The vendor's role shifts between controller and processor depending on the product, which makes accountability harder to follow for a customer assuming a single relationship throughout.
  • Nothing on the site addresses whether customer or user data is used to train AI models, and no opt-out is documented, so this cannot be assumed either way.
  • A reusable identity concentrates risk: one wallet unlocking many services is convenient, but it also makes the wallet and the device holding it a single high-value target.
Setup

Setup & Integrations

Technical difficulty

Uneven, and it depends which side you sit on. For the end user there is effectively no difficulty: install the app, scan a document, record a selfie, with iOS 17 or later required on Apple devices. For the buying organisation it is an integration project, not a sign-up. There is no self-service onboarding, the commercial conversation comes first, and the integration documentation is not public. Entry points are lightweight once agreed, such as an onboarding QR code, an email or SMS invitation, or a branded portal inside the wallet, and the vendor supports delivery through integration partners.

Deployment

Mobile appIOS appAndroid appWeb appAPI

Apps stores

Supported languages

EnglishGermanPolish
Company

Behind Nect

Company name
Nect GmbH
Founded
08/05/2017
Country of origin
🇩🇩 Germany
Headquarters
Großer Burstah 21, 20457 Hamburg, Germany
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
INFORMATION_NOT_FOUND
Legal contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What identification procedures does Nect offer?
Four, and the AI selects between them from the document presented: Auto Video Ident using a document scan and selfie video, the eID procedure reading a German ID card over NFC, ePass reading a passport chip and machine-readable zone, and ReIdent reusing an identity already held in the Nect Wallet.
How long does an identity check take?
The site states around three minutes, completed in two steps, without waiting time or a call-centre agent.
Which certifications does Nect actually hold?
ISO/IEC 27001:2024 and eIDAS certification as an identification service provider, both issued to Nect GmbH at its Hamburg address by datenschutz cert GmbH, an accredited body, with certificate references. The 'ISO-certified data centres' mentioned elsewhere on the site refer to the hosting provider, not to Nect.
What does it cost?
Nothing is published. There is no pricing page anywhere on the site, and business customers are directed to a demo request form. The consumer app, by contrast, is free: the terms of use state that users pay no fees for the procedures themselves.
Is there a minimum age?
Yes. The terms of use state that Nect is aimed at users over 16 years of age, and users must confirm this when registering to use the app.
Where is the data hosted?
Nect Sign is advertised as GDPR-compliant processing on servers in Germany, and the app privacy policy states that no processing of personal data takes place in third countries. The marketing website is hosted separately, by Hostinger, on an address that resolves to Frankfurt.
Is there an API?
No public API documentation is published. Dedicated api and docs subdomains do exist, and the documentation host answers with an authentication challenge, which points to an integration interface reserved for contracted partners rather than an openly documented one.
Are there mobile apps?
Yes. The Nect Wallet app is published by Nect GmbH on the Apple App Store and on Google Play, requires iOS 17 or later on Apple devices, and declares English, German and Polish as its languages.
How does Nect prevent fraud?
Through patented liveness detection, which uses vibration-generated artefacts in image and sound as a digital watermark so that pre-recorded videos are rejected, and through 'Put Your Face Here', which prompts randomised movements of the document on screen.
Is Nect ready for the EUDI Wallet?
The company positions itself as an intermediary in the EUDI ecosystem, acting as a connector or verifier between organisations, wallets and existing identity procedures, ahead of the European implementation deadline of 2027.
Conclusion

Should you pick Nect?

Nect is best understood as regulated identity infrastructure rather than a general-purpose AI tool. It targets organisations that cannot simply take a customer's word for who they are: banks, insurers, health insurance funds, telecoms operators, state lotteries and public bodies, all of which face a legal test their onboarding must pass.

On that ground the evidence is unusually solid. The ISO/IEC 27001 and eIDAS certificates are issued to Nect GmbH itself by a named accredited body and carry certificate references, which is rarer than the volume of security claims across the market would suggest. The gematik listing of the ePass procedure for the German telematics infrastructure, the 'high' assurance level under BSI-TR 03147, and three European patents on liveness detection all point the same way. The reuse model, where a verified identity is presented again through ReIdent, is a genuine advantage for recurring checks, and the anti-money-laundering module goes beyond identity into screening, beneficial ownership and continuous monitoring.

The reservations are about transparency rather than substance. There is no published price at any point, no stated free trial for business buyers, and no public integration documentation, so a prospective customer cannot size the commitment before entering a sales conversation. The site also contradicts itself on how many users it has, quoting eighteen, sixteen and thirteen million on different pages, and its published review count lags the App Store. Nothing is said about whether customer data trains any model.

For a buyer inside the German-speaking market with a compliance obligation to meet, this is a credible and well-evidenced option. For anyone shopping on price or expecting to evaluate it unaided, the closed commercial posture will be the obstacle.