SchoolHeaderSchoolNavSchoolHeaderSchoolNavVeriff and Sumsub wired into signup, so a clean client clears without anybody on your side touching it.
What gets checked
Every one of them runs on signup and lands against the same client record your desk already works from.
Passports, national IDs and driving licences read, validated against the issuing country’s format and checked for tampering — not just filed as an image somebody looks at later.
A selfie taken on the phone the client is already holding, matched against the photo on the document and tested for a live person rather than a picture of one.
A utility bill or bank statement read for the name, the address and the date, and compared with what the client typed — which is where most quiet mismatches show up.
Watchlists, sanctions lists and politically exposed person screening at signup, then again on a schedule, so a client who appears on a list next year does not go unnoticed.
Different jurisdictions ask for different documents and refuse different applicants. The requirement set follows the client’s country rather than being the same form for everyone.
Whatever the checks could not settle on their own, with the reason attached and the file on the screen. Approvals and rejections are logged against the operator who made them.
Under the hood
The checks are the provider’s. What sits around them — the queue, the record and the trail — is the part that decides how the day actually goes.
You hold the Veriff or Sumsub account and the rate you negotiated. We connect to it rather than reselling it, so your pricing and your data agreement stay yours.
Run both if a market asks for it — routed by country or account type, with the results landing in the same queue so nobody works two systems.
The check runs while the client is still on the page rather than in an email a day later, which is the single biggest thing standing between a registration and a funded account.
Documents expire and risk ratings change. Clients are asked again on the cycle you set, and the desk sees who is due before a regulator does.
Documents, check results and every version of both hang off the client rather than a provider dashboard, so an operator opening an account already has the history.
Who approved, who rejected, on what evidence and when — written as it happens and exported from the same screen, which is what a compliance review is really asking for.
How it runs
What actually happens between a client filling in a form and being allowed to trade.
Name, email and phone, and the client record exists from that moment. Somebody who drops out halfway is a lead your desk can follow up rather than a form nobody kept, which is worth more than it sounds on a page most people leave once.
Captured from the phone camera rather than uploaded from a computer, then read for its type and issuing country and checked against the format that country actually uses — not simply stored as a picture for somebody to squint at later.
A selfie compared against the photo on the document and tested for a live person rather than a photograph of one. It takes seconds, and it is where most impersonation attempts stop before anyone on your side has seen them.
Sanctions lists, watchlists and PEP records are queried while the client is still on the page. A hit rejects nobody on its own — it routes the case to a person who reads it, which is the only sensible way to treat a name that half matches.
Clean results clear straight through and the client carries on. Everything else lands in the queue with the reason attached and the file already on screen, and whatever the operator decides is written against them with the evidence they saw.
A verified client goes on to open an account and deposit without being asked to come back another day. The gap between registering and funding is where most desks quietly lose people, and closing it is the whole reason the check runs inside signup.
On the client’s side
Most clients register on a phone, so the whole check happens there — capture, liveness and result — instead of sending them off to find a computer and a scanner.
Questions about verification
What compliance teams ask before they let an automated check decide who gets an account.
You do. The provider account, the rate you negotiate and the data processing agreement are yours — we connect the platform to it rather than reselling verification with a margin on top. That matters for two reasons: your per-check cost is whatever you agreed with them, and the contract that governs your clients’ identity documents is between you and the provider, which is the answer most regulators want when they ask who holds that data.
Most of it, and that is the point of running the check inside signup rather than after it. A client with a readable document, a matching selfie and a clean screening result is verified while they are still on the page. What reaches the queue is the remainder — a blurred document, a name that does not match, an address on a different bill, a screening hit that needs reading. Your team spends its day on the cases that genuinely need judgement instead of on the ones that never did.
They have to, so they do. Which documents are asked for, which are accepted, whether proof of address is required at all and which applicants are refused outright can all be set per jurisdiction and per account type. A client in one market is not shown a form built for another, and a country you do not serve is stopped at registration rather than at the point somebody notices during a review.
They come back round. Documents carry their expiry, screening runs again on the cycle you set, and clients whose risk rating changed are re-asked ahead of the ones whose did not. The desk sees who is due before it becomes a finding, and the client is prompted in the portal rather than chased by email. Every one of those re-checks is stored as its own dated result, so the record shows what was known at each point in time rather than only what is true today.
On your deployment, against the client record. Brokers whose compliance team needs identity data to stay on infrastructure they control run the platform on their own server; desks that would rather not run servers let us host it, and the choice is about where the data sits rather than which version of the product you get. Either way access is set per role, so an operator sees the documents their job needs and no more, and every time one is opened it is written to the trail.