ZOREAL Identify
Alternatives to Entrust IDV (Onfido)
Entrust Identity Verification, formerly Onfido, runs document, chip, biometric and device checks in Workflow Studio journeys and returns clear or consider results to the client; its NFC read performs passive authentication against country certificates and, where the document supports it, active authentication, and the service is certified under ETSI TS 119 461 and the UK DIATF. ZOREAL Identify is a "Continue with ZOREAL" sign-in on standard OpenID Connect, backed by a credential the person holds in the ZOREAL ID app after a document chip read, a face match and a liveness capture. This page sets the two side by side on mechanism, who holds the result afterwards, what each costs and how data is handled.
Information last reviewed 10 September 2026. Compared: the Entrust Identity Verification platform (Document report, NFC for Document report, Facial Similarity, Known Faces, Device Intelligence, Workflow Studio) with ZOREAL Identify. Entrust’s watchlist, proof of address and electronic signature products, and its PKI, HSM and card-issuance businesses, are out of scope.
Where ZOREAL Identify and Entrust IDV (Onfido) differ
The guarantee
ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.
The same chip checks, then different hands
Entrust reads the eMRTD chip in its mobile SDKs, unlocked by BAC or PACE, runs passive authentication against signed country certificates and active authentication where the document supports it, and binds the chip photo to the user through its Facial Similarity reports; the clear or consider result goes to the client workflow. ZOREAL re-runs passive authentication on its server from the raw Security Object against a trust store built from the ICAO Public Key Directory, has the chip prove possession of its private key, face-matches a liveness capture against the chip portrait, and issues the credential to the person, who logs in with it at every relying party.
What a verification costs
Entrust publishes no price list for identity verification: entrust.com/pricing/ (where onfido.com/pricing redirects) and the contact-sales page returned HTTP 403 on 10 September 2026, and the practice statement, ETSI terms and developer portal carry no fee schedule. ZOREAL: Free to enrol; Tier A logins free and unlimited on every plan and never charged; only a Tier B login, where identity disclosure is requested, is charged on Premium. Current prices are on the ZOREAL price list at zoreal.com/pricing.
Scheme certifications on file
Entrust states certification against "ETSI TS 119 461 (v1.1.1)" and "ETSI EN 319 401" as an identity proofing service provider under eIDAS, UK DIATF profiles M1A, H1A and H2B, SOC 2 Type II, ISO 27001 certificate IS 660122, and that "Facial Similarity Motion is iBeta PAD Levels 1 and 2 certified on both iOS and Android"; the developer portal’s ETSI page shows a certificate valid until 31 May 2025 and a later date was not found on the pages read. Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026.
Side by side
Comparison of ZOREAL Identify and Entrust Identity Verification (formerly Onfido), based on public materials reviewed on 10 September 2026.
| Attribute | ZOREAL Identify | Entrust IDV (Onfido) |
|---|---|---|
| How the identity is bound | Enrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope. | Document: "automated analysis, powered by Atlas AI, classifies documents in milliseconds". NFC: eMRTD documents "contain a chip" read "using Entrust's mobile Identity Verification SDKs", unlocked by Basic Access Control from the MRZ or PACE, then "Passive Authentication - NFC data integrity authenticated against signed country certificates and revocation lists" and "Active Authentication - If supported by the document, NFC chip is also authenticated using the chip's private key"; "the photo extracted from the authenticated chip data is then bound to the user via our Facial Similarity Reports" (Photo, Video, or Motion, which requests "a simple head turn pattern in both directions or four randomized head movements"); Device Intelligence adds device signals (practice statement v1.5, December 2025; developer portal, September 2026). |
| What the relying party receives | Two halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser. | Per-report results of "clear" or "consider" with breakdowns and extracted data, returned to the client that ran the workflow; clients "can also enforce that NFC verification is performed". A cross-client identifier or login product is not stated in the public materials we could read (pages read: practice statement, developer portal; entrust.com newsroom pages returned HTTP 403). |
| Guarantee | ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. | Entrust states "Facial Similarity Motion is iBeta PAD Levels 1 and 2 certified on both iOS and Android with a perfect score of 0% False Acceptance Rate and 0% False Rejection Rate", and that NFC verification returns "a 95% pass rate on successful scans"; each report returns "clear" or "consider" rather than a guarantee, and under ETSI TS 119 461 and UK DIATF profiles Entrust acts as a certified identity proofing provider (practice statement v1.5; NFC for Document report; ETSI certified IDV page). |
| Who issues the credential | ZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses. | No credential is issued to the person: report results belong to the client workflow, and Entrust describes "our role as a data processor of the data submitted by users". A reusable identity or login product is not stated in the public materials we could read (practice statement v1.5; developer portal). |
| Cost to enrol | Enrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person. | No published price list as of September 2026: entrust.com/pricing/ (where onfido.com/pricing redirects) and entrust.com/contact-sales returned HTTP 403 on 10 September 2026, and the practice statement, ETSI terms and developer portal carry no fee schedule. No free tier, trial, minimum or set-up fee is stated on the pages we could read. |
| Cost per sign-in | Enrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers. | No published price per report or workflow run as of September 2026; the ETSI terms refer commercial terms to "the separate Onfido Services Agreement" (ETSI terms and conditions page). |
| Integration | Standard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. One client library per platform: @zoreal/oauth2-react, @zoreal/oauth2-js and @zoreal/oauth2-react-native on npm for the front end, and backends for Node (@zoreal/oauth2-node), Ruby (zoreal-oauth2), Python (zoreal-oauth2), PHP (zoreal/oauth2), Go, Java (com.zoreal:oauth2) and .NET (Zoreal.OAuth2). The React package renders the button and drives the flow itself, with no hosted script and nothing to allowlist in a Content Security Policy. Registration is self-serve in the dashboard (Identify, Assets): redirect addresses, origins and permitted scopes, with domain verification; personal-data scopes require a verified domain and a confidential client. | Smart Capture SDKs for Web, iOS and Android; "NFC is available via our iOS, Android, React Native and Flutter SDKs"; Smart Capture Link for a hosted link flow; Workflow Studio with "No code required"; a REST API, latest documented v3.6 (NFC for Document report; practice statement section 3.3; developer portal). |
| Data handling | The ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when. | Processor: "our role as a data processor of the data submitted by users". "Clients control how long Entrust retains their data (subject to maximum retention periods set by Entrust)", by ad hoc request or rolling deletion, and Entrust recommends clients do not delete within the first thirty days after a verification; under the ETSI terms, event logs are retained at the customer’s discretion "up to a maximum retention period of 3 years" (practice statement v1.5; ETSI terms and conditions). |
| Certifications and evaluations | Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026. | "Onfido (now part of Entrust) is SOC 2 Type II compliant"; "ISO 27001 under certificate number IS 660122"; ISO 30107-3 PAD Level 1 for Facial Similarity Selfie and Levels 1 and 2 for Motion, iOS and Android, 0% False Acceptance Rate; ETSI TS 119 461 (v1.1.1) and ETSI EN 319 401 as an identity proofing service provider under eIDAS, covering Document Video Report, Facial Similarity Motion, Device Intelligence and Known Faces in Studio workflows; UK DIATF Identity Service Provider profiles M1A, H1A and H2B for Right to Work and Right to Rent. The ETSI page shows a certificate valid until 31 May 2025; a later date was not found on the pages read (developer portal; practice statement v1.5; ETSI certified IDV page). |
Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what Entrust IDV (Onfido) offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.
Where ZOREAL Identify and Entrust IDV agree
Of the verification providers on this site, Entrust is the closest match on chip mechanics. Both read the eMRTD chip over NFC on the phone. Both check the issuing country’s signature over the chip data (Entrust’s passive authentication against signed country certificates and revocation lists; ZOREAL’s passive authentication re-run on its server from the raw Security Object against a trust store built from the ICAO Public Key Directory). Both have the chip prove possession of its private key where the document supports it (Entrust’s active authentication; ZOREAL’s active authentication challenge, and otherwise PACE-CAM or Chip Authentication). And both bind the chip portrait to a live face rather than to the printed photo.
Both also describe their results without a superlative. Entrust returns "clear" or "consider" with breakdowns and lets the client enforce that NFC verification was performed; ZOREAL’s token states in acr and amr the method that was actually used for this login and never smooths a weaker login into a stronger one. Both name the client, not the vendor, as the party that decides what is kept: Entrust states that clients control how long it retains their data, within Entrust maximums, and ZOREAL’s ID token carries no personal data, with identity attributes served only on request and consent.
Where they differ is what happens after the check, and who has audited it. Entrust’s result goes to the client that ran the workflow, under a services agreement with no published price, and the service is certified under ETSI TS 119 461 and the UK DIATF for regulated proofing. ZOREAL issues the credential to the person, who reuses it as a sign-in at every relying party with a different pairwise identifier at each sector, at a published price; no Identify-specific certification or scheme recognition is stated on zoreal.com.
ZOREAL Identify may fit you if
- You want a sign-in rather than a check: a "Continue with ZOREAL" button on standard OpenID Connect that returns a pairwise pseudonymous identifier for a human verified against a government document chip
- You want the person, not your database, to hold the credential, and to reuse it at every service without being linkable across them
- You want published pricing with no sales call: free enrolment, every Tier A login free without limit, and a charge only on a Tier B login where you request identity disclosure
- You want the assurance of each login stated in acr and amr, with a floor you set per request and a request that cannot meet it denied rather than downgraded
Entrust IDV may fit you if
- You need regulated identity proofing under ETSI TS 119 461 or the UK DIATF (Right to Work, Right to Rent) with an audited practice statement
- You need chip verification with passive and active authentication inside your own app, with image capture as the fallback
- You need document coverage stated at over 2,500 documents in 195 countries and a no-code workflow builder
- You need watchlist screening, proof of address or a qualified electronic signature on the same platform; ZOREAL Identify is not KYC
Other alternatives to Entrust IDV (Onfido)
35 more vendors compared under ZOREAL Identify, from their own public materials.
- JumioJumio Identity Verification and selfie.DONE
Jumio Identity Verification checks a government ID photo, matches a selfie with liveness, can read a passport chip on mobile, and runs database and watchlist checks through an SDK, mobile web flow or API; selfie.DONE (October 2025) re-verifies a returning user with a selfie across businesses connected to the Jumio Identity Graph.
- Pricing
- No published price list as of September 2026; Jumio’s contact page offers a sales conversation.
- Assurance
- Document authenticity plus selfie-to-ID face match; liveness tested by iBeta to ISO/IEC 30107-3 Level 2 (letter dated 11 September 2025); NFC chip read available in the mobile SDK and disabled by default.
- Reuse
- Within Jumio’s network: selfie.DONE recognises a returning user by selfie against the Jumio Identity Graph. A login identifier for relying parties is not stated in the public materials we reviewed.
- VeriffVeriff Identity Verification
Veriff verifies a document photo and a selfie with passive liveness, optional background video and device signals, with an NFC chip read available in the mobile SDKs, through iOS, Android, web SDK, API or a hosted page; self-serve plans are priced per verification and reverification re-checks a returning user for the same business.
- Pricing
- Essential $0.80 per verification with a $49 per month minimum; Plus $1.39 and $99; Premium $1.89 and $209; a 15-day trial of up to 50 sessions; Enterprise at volume pricing (veriff.com/pricing, September 2026).
- Assurance
- Document authenticity plus selfie-to-document face match; passive liveness tested by iBeta to ISO/IEC 30107-3 Level 2 (September 2024); FIDO DocAuth certification for Full Auto IDV (April 2026); NFC chip read as an optional SDK framework.
- Reuse
- Per business: reverification re-checks the same user for the same customer. A cross-business identifier or login is not stated in the public materials we reviewed.
- SumsubSumsub platform and Sumsub ID
Sumsub verifies a document image, a selfie with liveness, and optionally the NFC chip, email and phone, through WebSDK, mobile SDKs, a link or the API, with KYC and AML add-ons; Sumsub ID (March 2025) lets a person who verified with one Sumsub client re-share stored document images with another Sumsub client after an email code, a liveness check and explicit consent.
- Pricing
- Basic $1.35 per verification with a $149 monthly minimum; Compliance $1.85 with $299; Enterprise on request; 14-day trial with 50 free checks (sumsub.com/pricing, September 2026).
- Assurance
- Document checks plus liveness and face match; liveness tested by iBeta to ISO/IEC 30107-3 Level 2 on Android and iOS (April 2025); NFC chip data cross-validated against cryptographic and visual checks on mobile.
- Reuse
- Within the Sumsub client base: Sumsub ID stores document images and metadata, recognises the person by email plus a one-time code and liveness, and shares with explicit consent to another Sumsub client, which runs its own checks. A login identifier for relying parties is not stated.
- SocurePredictive DocV on the RiskOS platform
Socure’s RiskOS platform combines Predictive DocV (document and selfie verification with liveness and injection detection) with data-source KYC, watchlist, phone, device and fraud scoring, sold self-serve per evaluation or as an enterprise contract.
- Pricing
- Socure Launch lists DocV at $0.80 per evaluation and bundles up to $1.30, with $1,000 in free monthly credits; Enterprise is usage-based with volume discounts (socure.com/pricing, September 2026).
- Assurance
- Document fraud models plus selfie liveness the vendor describes as NIST PAD Level 2, with injection-attack detection; chip reading is not stated. ISO 27001, SOC 2 Type 2 and FedRAMP Moderate are listed on its trust center.
- Reuse
- Not stated: no reusable identity or login product appears in the public materials we reviewed.
- PersonaPersona Government ID and Selfie verifications
Persona runs government ID, selfie, phone, document and database verifications inside an embedded web module, a hosted flow or native Android, iOS and React Native SDKs, with results returned to the business through its dashboard and API.
- Pricing
- Essential at $250 per month on an annual contract with 500 free services per month and $1.50 per service beyond; Growth and Enterprise on request; 60-day trial of up to 50 services (help.withpersona.com Plans Overview, September 2026).
- Assurance
- Government ID image checks plus a real-time selfie video liveness check; database and phone checks as options. Certifications and chip reading are not stated in the public materials we could read.
- Reuse
- Not stated: no reusable identity or login product appears in the public materials we could read.
- TruliooTrulioo Identity Document Verification and Person Verification
Trulioo verifies people against data sources in 195 countries and verifies identity documents with OCR, MRZ extraction, passive liveness and face match, through web, iOS and Android SDKs, an API and a no-code Workflow Studio, alongside business verification and watchlist screening.
- Pricing
- No published price list as of September 2026; the pricing page offers a demo booking.
- Assurance
- Document authenticity checks plus selfie-to-document face match with passive liveness; data-source matching for person verification. The liveness test lab and level are not named on the pages we read.
- Reuse
- Not stated: no reusable identity or login product appears in the public materials we reviewed.
Common questions
How we compared
This comparison is based on publicly available information from Entrust IDV (Onfido)’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.
Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.
Sources
- Entrust Remote IDV Practice Statement & Security Policy v1.5 (December 2025) Read 2026-09-10
- Entrust Identity Verification Developer Portal (product list, SOC 2, ISO 27001) Read 2026-09-10
- NFC for Document report (SDKs, passive and active authentication, pass rate) Read 2026-09-10
- Facial Similarity reports (Motion mechanism) Read 2026-09-10
- ETSI certified IDV (standards, covered reports, certificate validity) Read 2026-09-10
- Terms and conditions for ETSI certified identity verification (event log retention, services agreement) Read 2026-09-10
- Entrust API reference (latest documented version) Read 2026-09-10
- Entrust pricing page (onfido.com/pricing redirects here; HTTP 403 on the review date) Read 2026-09-10
- Entrust contact sales (HTTP 403 on the review date) Read 2026-09-10
- ZOREAL pricing (our own published claims) Read 2026-09-11
- ZOREAL Identify product page Read 2026-09-11
ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by Entrust IDV (Onfido). Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.
See ZOREAL Identify for yourself.
A product walkthrough, pricing or volume terms, with the ZOREAL team.