Skip to comparison
ZOREAL

ZOREAL Identify

Alternatives to AU10TIX

AU10TIX verifies a document image with forgery tests or the chip with passive and chip authentication on its native mobile SDKs, binds a selfie with passive liveness and face compare, adds AML screening and fraud signals, and returns a result to the business under Kantara IAL2 and UK DIATF certifications. ZOREAL Identify is a "Continue with ZOREAL" sign-in on standard OpenID Connect, backed by a credential the person holds in the ZOREAL ID app after a document chip read, a face match and a liveness capture. This page sets the two side by side on mechanism, who holds the result afterwards, what each costs and how data is handled.

Information last reviewed 10 September 2026. Compared: AU10TIX document verification, passive liveness and face compare, NFC verification and the Reusable Digital ID line item with ZOREAL Identify. AU10TIX’s AML and PEP screening, proof of address, business verification (KYB) and the Serial Fraud Monitor consortium are out of scope.

Where ZOREAL Identify and AU10TIX differ

  • The guarantee

    ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.

  • The same chip checks, then different hands

    AU10TIX reads ICAO 9303 data groups from the chip on its native iOS and Android SDKs, using MRZ-derived BAC keys, and states that "Passive Authentication (PA) and Chip Authentication (CA) verify chip integrity and detect tampering or cloning"; the result goes to the business. ZOREAL re-runs passive authentication on its server from the raw Security Object against a trust store built from the ICAO Public Key Directory, has the chip prove possession of its private key through an active authentication challenge where the document supports it and otherwise through PACE-CAM or Chip Authentication, face-matches a liveness capture against the chip portrait, and issues the credential to the person, who logs in with it at every relying party.

  • What a verification costs

    AU10TIX lists Basic KYC ("Full auto") and Enhanced KYC ("Hybrid") each at a "$500 monthly minimum" (USD as displayed, geography not stated), Enterprise on request, and publishes no per-verification rate, trial or free tier; 12 x $500 = $6,000 a year at the minimum. ZOREAL: Free to enrol; Tier A logins free and unlimited on every plan and never charged; only a Tier B login, where identity disclosure is requested, is charged on Premium. Current prices are on the ZOREAL price list at zoreal.com/pricing.

  • Scheme certifications on file

    AU10TIX’s trust center lists SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27701, "ISO/IEC 30107-3 PAD (Levels 1 & 2)", "Kantara IAL2 (NIST 800-63A)", UK DIATF certified identity service provider status, TX-RAMP Level 2 and U.S. state gaming authorisations. Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026.

Side by side

Comparison of ZOREAL Identify and AU10TIX, based on public materials reviewed on 10 September 2026.

AttributeZOREAL IdentifyAU10TIX
How the identity is boundEnrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope.Document: "Capture or upload your passport, driver's license, or national ID" with "+180 Forgery detection tests"; selfie: "Confirm it's really you with Passive Liveness" and "Face compare"; NFC: "Read trusted identity data directly from encrypted NFC chips", extracting ICAO 9303 data groups DG1, DG2, DG7 and DG14 with MRZ-derived BAC keys, and "Passive Authentication (PA) and Chip Authentication (CA) verify chip integrity and detect tampering or cloning" on native iOS and Android SDKs; AML, PEP and adverse media screening as add-ons (au10tix.com how-to-get-verified, NFC verification and pricing pages, September 2026).
What the relying party receivesTwo halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser.A verification result and a Case Management Dashboard for the business. "Reusable Digital ID" is listed as an Enterprise plan feature with no description on the pages read (pricing page).
GuaranteeZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine."in under 8 seconds" for most verifications and a "97%+ pass rate" on one page, a "99% pass rate" on another, with no period or population stated; liveness listed at "ISO/IEC 30107-3 PAD (Levels 1 & 2)"; "Kantara IAL2 (NIST 800-63A)" and UK DIATF certification listed on the trust center (how-to-get-verified page; solutions page; trust center).
Who issues the credentialZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses.No credential to the person is described: "Au10tix is considered a controller of personal data that it collects", and the result goes to the business. "Reusable Digital ID" appears in the Enterprise plan without detail in the public materials we reviewed (privacy notice; pricing page).
Cost to enrolEnrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person.Basic KYC ("Full auto") and Enhanced KYC ("Hybrid") each at a "$500 monthly minimum" (USD as displayed, geography not stated), Enterprise on request; no per-verification rate, trial, free tier, set-up fee or overage is published, and every plan’s call to action is "Let's Talk!" (au10tix.com/pricing, September 2026). 12 x $500 = $6,000 per year at the minimum.
Cost per sign-inEnrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers.No published per-verification rate as of September 2026; re-verifications are billed under the plan agreed with sales (pricing page).
IntegrationStandard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. One client library per platform: @zoreal/oauth2-react, @zoreal/oauth2-js and @zoreal/oauth2-react-native on npm for the front end, and backends for Node (@zoreal/oauth2-node), Ruby (zoreal-oauth2), Python (zoreal-oauth2), PHP (zoreal/oauth2), Go, Java (com.zoreal:oauth2) and .NET (Zoreal.OAuth2). The React package renders the button and drives the flow itself, with no hosted script and nothing to allowlist in a Content Security Policy. Registration is self-serve in the dashboard (Identify, Assets): redirect addresses, origins and permitted scopes, with domain verification; personal-data scopes require a verified domain and a confidential client."Native iOS and Android SDKs" for NFC, "Web SDK integration" and "Platform (API)", with "Out-of-the-box workflows" and a "Case Management Dashboard" (NFC verification page; solutions page; pricing page).
Data handlingThe ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when.Controller: "Au10tix is considered a controller of personal data that it collects" (privacy notice, last updated 8 August 2026), retained "for as long as necessary to fulfil the purposes we collected it for". Biometric Data Policy: a client’s customer biometric data is retained until the first of listed events, including written notice from the client "indicating that 3 years have lapsed following the last interaction of the client with the client's customer"; clients are responsible for their own biometric retention and destruction policies.
Certifications and evaluationsOrganization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026.Trust center: "SOC 2 (Type II)", "ISO/IEC 27001 Information Security Management", "ISO/IEC 27701 Privacy Information Management", "ISO/IEC 30107-3 PAD (Levels 1 & 2)", "TX-RAMP Level 2 (Texas)", "KJM (Germany) Age Verification", U.S. state gaming authorisations (IN, PA, NV, MI, NJ), UK DIATF certified identity service provider (RTR, RTW, DBS), "Kantara IAL2 (NIST 800-63A)".

Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what AU10TIX offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.

Where ZOREAL Identify and AU10TIX agree

Both read the chip and check it cryptographically. AU10TIX reads the ICAO 9303 data groups over NFC on its native SDKs, unlocks the chip with keys derived from the machine-readable zone, and runs passive authentication and chip authentication to verify integrity and detect cloning. ZOREAL ID enrolment reads the same data groups over NFC, re-runs passive authentication on its server against a trust store built from the ICAO Public Key Directory, and has the chip prove possession of its private key through active authentication where supported and otherwise through PACE-CAM or Chip Authentication. Both then bind a live face to the document: AU10TIX with passive liveness and face compare, ZOREAL with a liveness capture face-matched against the chip portrait.

Both also state a biometric retention rule rather than leaving it to a contract. AU10TIX’s Biometric Data Policy retains a client’s customer biometric data until the first of listed events, including the client’s notice that three years have passed since the last interaction, and places the retention policy with the client. ZOREAL’s ID token carries no personal data, and the document portrait is a separately gated tier that the relying party must request and the person must consent to.

Where they differ is what happens after the check, and who has audited it. AU10TIX’s result goes to the business, under a plan with a $500 monthly minimum and no published per-verification rate, and the service carries Kantara IAL2 and UK DIATF certifications for regulated proofing. ZOREAL issues the credential to the person, who reuses it as a sign-in at every relying party with a different pairwise identifier at each sector, at a published price; no Identify-specific certification or scheme recognition is stated on zoreal.com.

ZOREAL Identify may fit you if

  • You want a sign-in rather than a check: a "Continue with ZOREAL" button on standard OpenID Connect that returns a pairwise pseudonymous identifier for a human verified against a government document chip
  • You want the person, not your database, to hold the credential, and to reuse it at every service without being linkable across them
  • You want published pricing with no minimum: free enrolment, every Tier A login free without limit, and a charge only on a Tier B login where you request identity disclosure
  • You want the assurance of each login stated in acr and amr, with a floor you set per request and a request that cannot meet it denied rather than downgraded

AU10TIX may fit you if

  • You need NIST 800-63A IAL2 (Kantara) or UK DIATF certified proofing for a regulated onboarding flow
  • You need KYC, AML and consortium fraud signals in one contract; ZOREAL Identify is not KYC
  • You need chip reading with passive and chip authentication inside your own native app
  • You must verify people who will not install an app: the Web SDK and API run in your own flow

Other alternatives to AU10TIX

35 more vendors compared under ZOREAL Identify, from their own public materials.

All 36 Identify comparisons

Common questions

How we compared

This comparison is based on publicly available information from AU10TIX’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.

Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.

Sources

ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by AU10TIX. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.

See ZOREAL Identify for yourself.

A product walkthrough, pricing or volume terms, with the ZOREAL team.