KYC, KYB and AML
Customer verification with results you can explain
verkyc checks documents, the NFC chip, faces, companies and sanctions lists. For every check you see exactly what was done: the source, the version, the time and the evidence. Your policy makes the decision, and the report is signed and verifiable by reference.
Case C-7K3M9Q2T
Individual, KZ passport
- Machine readable zoneCheck digits matchpass
- Chip signatureChain to the CSCA, Master Listpass
- 1:1 face matchingChip portrait, policy thresholdpass
- Sanctions listsNo match established: UN, OFAC, UKpass
- Residential addressA supporting document is neededinconclusive
- Processing and storage in Germany
- API, link, widget, iOS and Android SDK
- Russian and English interface
What verkyc checks
Three areas in one platform and one API: the person, the company and the risk.
Identity (KYC)
Document and machine readable zone, passport NFC chip, 1:1 face matching and liveness.
Learn moreBusiness (KYB)
Company details and documents, ownership structure, beneficial owners, representative and authority.
Learn moreRisk (AML)
UN, OFAC, UK and EU sanctions lists, PEP, adverse information and monitoring.
Learn more
How it works
From creating a case to a signed report: one API contract and one console.
Create a case
Through the API or in the console: the applicant, the purpose, the country and the policy version.
The applicant completes the steps
Via a link, an embedded widget or your app. The server issues the steps and hints.
The platform checks
Every check returns an outcome with a reason; the policy combines them into a decision or manual review.
You get the result
A signed webhook, the case card in the console and a signed report verifiable by reference.
Why verkyc
Transparent results
Six outcomes instead of yes or no. A missing result never turns into an approval.
Your decision policy
Approval rules with versions, simulation on past cases and approval by a second employee.
Signed report
The report is signed with a key held in KMS; anyone can verify it by reference without access to personal data.
Data in Germany
Processing, storage and backups run in the German region; encryption keys never leave the region.
Honest coverage
A country is enabled by a profile of documents, channels and purposes, not by a single flag. Limitations are visible before the check starts.
Learn moreContract-first integration
OpenAPI 3.1, idempotent requests, signed webhooks, a test environment with synthetic outcomes.
Learn more
Scenarios
The set of checks and the applicant steps are configured for the industry.
Fintech and payments
Onboarding of individuals and companies, screening and monitoring with audit-ready evidence.
Learn moreMarketplaces
Seller checks: individuals, sole traders and companies, representatives, owners, monitoring.
Learn moreCrypto services
Customer KYC, screening and monitoring, counterparty company checks.
Learn moreCar sharing and rentals
Renter identity before access, age from the document, repeat checks.
Learn moreHR and remote hiring
Candidate identity via a link before access to company systems.
Learn moreGaming and age checks
Age threshold from the document, no face-based age estimation.
Learn more
For developers
A REST API with an OpenAPI contract, keys for the test and live environments, cursor pagination and errors in problem+json format.
- A verification link in one request
- Webhooks signed with HMAC-SHA256, with retries
- iOS and Android SDK, web widget
- A test environment without real data
curl https://api.verkyc.com/v1/cases/$CASE_ID/hosted-links \
-H "Authorization: Bearer $VERKYC_API_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{"locale": "en", "return_url": "https://example.com/onboarding/done"}'Security by design
Personal data is encrypted with a separate key per applicant and case, keys are held in the regional KMS, files are scanned for malware and parsed in an isolated executor.
How security works- AES-256-GCM encryption
- Isolated file processing
- Audit log
- Deletion with key destruction
Frequently asked questions
Which countries are supported?
The first wave: Russia, Belarus, Kazakhstan, Uzbekistan, Kyrgyzstan, Tajikistan, Armenia, Azerbaijan, Turkmenistan and Moldova. Capabilities for each country are on the coverage page.
Where is the data stored?
Processing and storage run in the platform region in Germany, and backups are kept there too. Encryption keys are held in the regional KMS.
How fast can we start?
A test API key and the test environment are issued after your request. Integration through a verification link takes one API request and webhook handling.
Can a report be verified without console access?
Yes. The report is signed, and its authenticity is verified by the reference in the report without sharing personal data. The public signing keys are published at a standard address.
How much does it cost?
You pay for the checks actually performed under a plan with a minimum payment. Usage in the test environment is not billed. A quote for your volume is available on request.
See it on your own scenarios
Tell us who you need to verify and where. We will prepare a demo, test API access and a price estimate.