ZOREAL Identify
Alternatives to Incode
Incode is an identity verification platform: Identity Verification runs "Document, biometric, and liveness checks in a single flow" with iBeta-certified passive liveness and Deepsight deepfake detection, Authentication makes "The face verified at onboarding" the credential for every later session within a customer’s own iOS, Android, web and call-centre channels, and Workforce verifies employees once and re-authenticates them biometrically for MFA resets, helpdesk requests and high-risk actions. ZOREAL Identify is a "Continue with ZOREAL" sign-in on standard OpenID Connect, backed by a credential ZOREAL issues after reading a government document chip in the ZOREAL ID app. This page sets a verify-once, re-authenticate-later platform whose reuse is within one customer beside a credential the person reuses at every relying party.
Information last reviewed 10 September 2026. Compared: Incode Identity Verification at onboarding, Authentication at login and Workforce as a verified-human check for employees against ZOREAL Identify; KYB, non-ID document validation and the Agentic Identity product are out of scope.
Where ZOREAL Identify and Incode differ
The guarantee
ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.
Reused within one customer, or everywhere
Incode states "The face verified at onboarding becomes the credential for every session after it" and that "One enrollment works across all of them", meaning a customer’s iOS, Android, web and call-centre channels; reuse across different services is not stated. ZOREAL issues the person one credential and the same ZOREAL ID logs in at every relying party, with a pairwise identifier per sector so the logins are not linkable across services.
The enrolled face, or the chip plus a device key
Incode’s anchor after onboarding is the enrolled face: at login, passive liveness is confirmed and a 1:1 match is made against the enrolled identity, with deepfake and device-tampering screens. ZOREAL’s anchor is the document chip, read and verified against the issuing country’s certificates, plus a key generated in the phone’s hardware; the default login is an approval on the enrolled phone, and a relying party can require a fresh liveness capture face-matched to the enrolled document for a given login.
Demo request beside a published list
Incode publishes no price list as of September 2026; a pricing URL returned not found and the Identity Verification, Authentication and Workforce pages offer a demo request. ZOREAL publishes its Identify prices: free to enrol, free tier a logins; only tier b logins charged.
Side by side
Comparison of ZOREAL Identify and Incode (Identity Verification, Authentication and Workforce), from public materials reviewed on 10 and 11 September 2026.
| Attribute | ZOREAL Identify | Incode |
|---|---|---|
| How the claim is made | Enrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope. | At onboarding, "Document, biometric, and liveness checks in a single flow": the document is checked, the live capture is compared with the ID portrait, and iBeta-certified passive liveness plus Deepsight deepfake detection confirm a real human is present. At login, the person presents their face; passive liveness is confirmed, a 1:1 match is made against the enrolled identity, and deepfake and device-tampering screens run before access. NFC chip reading is not stated on the identity verification page we read. |
| Guarantee | ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. | Incode states iBeta Level 3 on iOS and Android and, on its trust center, ISO/IEC 30107-3:2023 and a Kantara IAL2 identity verification trust mark. A statement of assurance about the person beyond those test levels and trust marks is not stated in the public materials we reviewed. |
| Who issues the credential | ZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses. | "The face verified at onboarding becomes the credential for every session after it", within one customer’s deployment: "One enrollment works across all of them" refers to that customer’s iOS, Android, web and call-centre channels. Reuse of the verified identity across different services is not stated in the materials we reviewed (the homepage, the Identity Verification, Authentication and Workforce pages, the platform page, the about page and the trust center). |
| What the relying party receives | Two halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser. | At onboarding, a verification result; at each later login, the outcome of the liveness check and the 1:1 face match against the enrolled identity; for Workforce, verification outcomes wired into Okta, Microsoft Entra ID, ServiceNow and other IAM, ITSM and HR systems. |
| Cost to enrol | Enrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person. | No published price list as of September 2026; a pricing URL returned not found and the Identity Verification, Authentication and Workforce pages offer "Request a demo". |
| Cost per sign-in | Enrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers. | Authentication is priced by demo request; no per-authentication amount is published. An OpenID Connect or FIDO passkey login protocol is not stated in the pages we reviewed. |
| Integration | Standard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. One client library per platform: @zoreal/oauth2-react, @zoreal/oauth2-js and @zoreal/oauth2-react-native on npm for the front end, and backends for Node (@zoreal/oauth2-node), Ruby (zoreal-oauth2), Python (zoreal-oauth2), PHP (zoreal/oauth2), Go, Java (com.zoreal:oauth2) and .NET (Zoreal.OAuth2). The React package renders the button and drives the flow itself, with no hosted script and nothing to allowlist in a Content Security Policy. Registration is self-serve in the dashboard (Identify, Assets): redirect addresses, origins and permitted scopes, with domain verification; personal-data scopes require a verified domain and a confidential client. | A developer hub with platform and API documentation, a Workflow Builder and UI customisation with no-code options; channels are iOS, Android, web and call centre. Workforce integrates with Okta, Microsoft Entra ID, Ping Identity, ServiceNow, Zendesk, Jira Service Management, Workday, Greenhouse, SAP SuccessFactors, Ashby, Slack, Zoom, Microsoft Teams and Google Meet. |
| Data handling and retention | The ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when. | The trust center references a Data Deletion Policy and a privacy policy; the retention period for biometric data was not in the text we read. |
| Certifications stated | Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026. | Trust center: SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 30107-3:2023, ISO/IEC 42001:2023, HIPAA, FedRAMP Moderate, the Age Check Certification Scheme and a Kantara IAL2 trust mark; the homepage states iBeta Level 3 on iOS and Android, as listed in September 2026. |
Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what Incode offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.
Where ZOREAL Identify and Incode agree
Both verify once and carry the assurance forward, and both run passive liveness with a 1:1 face match when a later login needs it. Incode confirms liveness and matches the face against the enrolled identity at each session; ZOREAL’s relying party can require a fresh liveness capture face-matched to the enrolled document, and the token states which authentication happened. Both let the business decide when a fresh biometric is required: Incode for high-risk actions, ZOREAL through the assurance floor the relying party sets per request.
Both state a defence against deepfakes at the biometric step: Incode names Deepsight, and ZOREAL’s liveness capture carries presentation-attack detection. And both bind a person to a device: Incode screens for device tampering at login, and ZOREAL generates the credential’s key in the phone’s hardware and verifies its attestation at registration.
Both publish organisation-level attestations rather than leaving security to the contract: Incode lists SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 42001 and FedRAMP Moderate; ZOREAL lists SOC 2, PCI DSS (SAQ A), GDPR, ISO/IEC 27001:2022 and CSA STAR Level One for Bynn Intelligence, Inc. Where they differ is the scope of reuse and who issues the credential, and the rows above state it.
ZOREAL Identify may fit you if
- You want one enrolment reused at every relying party, beyond a single customer’s channels, with a pairwise identifier per sector
- You want the anchor to be the document chip verified against the issuing country’s certificates and a hardware-bound device key, with the face as one factor
- You want the pricing structure published before the sales call: free to enrol, free tier a logins; only tier b logins charged
- You want a standard OpenID Connect provider your existing library validates, with client libraries for the front end and for Node, Ruby, Python, PHP, Go, Java and .NET
Incode may fit you if
- You want onboarding and face-based returning-user login from one vendor, with one enrolment reused across your own channels
- You need employee, candidate and helpdesk verification wired into Okta, Entra ID, ServiceNow or Zendesk
- You need FedRAMP Moderate, Kantara IAL2 or ISO/IEC 42001 on the supplier’s trust center
- You want a vendor stating iBeta Level 3 on iOS and Android
Other alternatives to Incode
35 more vendors compared under ZOREAL Identify, from their own public materials.
- LexisNexis Risk SolutionsIDVerse, TrueID, InstantID and ThreatMetrix
A portfolio of fraud and identity services from LexisNexis Risk Solutions: database identity verification (InstantID, US), AI document authentication with face match and liveness (IDVerse, TrueID), email risk (Emailage) and device and behaviour risk (ThreatMetrix, BehavioSec).
- Pricing
- No published price list as of September 2026; contact sales. A UK public-sector G-Cloud listing shows ThreatMetrix at £0.01 a transaction.
- Assurance
- Optical document checks, biometric face match and liveness (IDVerse, TrueID); personal data matched to a reference database the vendor states covers almost 100% of US adults (InstantID); device and behavioural risk scores (ThreatMetrix). Chip reading is not stated in the materials reviewed.
- Reuse
- Results are returned to the calling business per check. A reusable identity carried by the person between services is not stated in the materials reviewed.
- ExperianCrossCore and Precise ID
Experian’s CrossCore is a digital identity and fraud platform that orchestrates Precise ID (US bureau-data identity verification with knowledge-based authentication), device risk and partner document and biometric checks into one decision for the business.
- Pricing
- No published price list as of September 2026; contact sales.
- Assurance
- Applicant personal data matched against Experian data with KBA step-up (Precise ID); device risk (FraudNet); document verification with biometric capabilities via Doc Capture and partners. Liveness method and chip reading are not stated in the materials reviewed.
- Reuse
- Decisions are returned to the calling business per check. A reusable identity carried by the person between services is not stated in the materials reviewed.
- GBGGBG Go, IDscan and greenID
GBG Go is GB Group plc’s identity platform: 110+ identity, fraud and risk modules across 195+ countries, including IDscan document authentication with NFC chip extraction and passive liveness, greenID government-data verification in Australia and New Zealand, sanctions and PEP screening and business verification.
- Pricing
- No published price list as of September 2026; GBG Go offers intro and demo forms, and IDscan and greenID route to a sales enquiry form
- Assurance
- IDscan: document authentication with NFC chip extraction and iBeta accredited ISO 30107-3 Level 2 passive liveness; greenID: identity details matched to government data sources with liveness certified to ISO 30107-3
- Reuse
- Results are returned to the business per journey; a reusable identity carried by the person between services is not stated in the materials we reviewed
- ProveProve Identity Platform and Prove Pre-Fill
Prove verifies identity through the phone: possession of the handset, the phone number’s reputation and ownership of the number by the named person, and pre-fills sign-up forms with verified identity data (Prove Pre-Fill).
- Pricing
- No published price list as of September 2026; the vendor’s AWS Marketplace listing states pricing is agreed customer by customer, with an implementation fee plus tiered transactional fees
- Assurance
- Phone possession (Prove Key, Mobile Auth or SMS), phone reputation (Trust Score) and ownership match against authoritative sources; the vendor states no document scans or selfies are needed
- Reuse
- Results are returned to the calling business per request; a reusable identity carried by the person between services is not stated in the materials we reviewed
- PlaidPlaid Identity Verification and Plaid Identity
Plaid Identity Verification checks a new user’s typed details against records, reads an uploaded government ID from 16,000+ types across 200 countries and territories, and matches a live selfie to it; Plaid Identity separately confirms name, phone, email and address from the user’s linked bank account.
- Pricing
- Plan structure published (Pay as You Go, Growth, Custom) with 200 free API calls per product in Limited Production; per-event amounts for Identity Verification are shown only when applying for Production access (September 2026)
- Assurance
- Data source verification, documentary verification and a selfie check that the video is "a genuine, live video of a real human" matching the document, plus SMS and watchlist screening; chip reading and a liveness test certification are not stated in the materials we reviewed
- Reuse
- Results are returned to the business per session; a reusable identity carried by the person between services is not stated in the materials we reviewed
- SignicateID and Wallet Hub and the KYC and KYB platform
Signicat’s eID and Wallet Hub lets a business accept 35 European national eIDs (BankID, MitID, itsme, SPID and others) and, from 2026, EUDI wallets through one API, alongside identity proofing by document, biometrics, liveness and data sources across 40+ countries.
- Pricing
- Setup, subscription and per-transaction fees by identity method with volume discounts; amounts are shown in the Signicat Dashboard after a free developer sign-up (September 2026)
- Assurance
- The assurance of the national eID or wallet the person already holds, brokered by Signicat; proofing by document checks, biometrics and liveness where no eID exists; Signicat states it is an EU Qualified Trust Service Provider with ISO 27001 and SOC 2 Type II
- Reuse
- Yes: the person reuses the national eID or wallet they hold at every business that integrates Signicat; a Signicat-issued credential is not stated in the materials we reviewed
Common questions
How we compared
This comparison is based on publicly available information from Incode’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.
Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.
Sources
- Incode homepage (products, counters, customer tiers, iBeta and SOC 2 statements) Read 2026-09-10
- Incode Identity Verification (single-flow checks, liveness and Deepsight, developer resources) Read 2026-09-11
- Incode Authentication (returning-user face login, reuse across channels) Read 2026-09-11
- Incode Platform page (dashboard functions, counters, documents) Read 2026-09-11
- Incode Workforce (employee lifecycle verification, integrations) Read 2026-09-10
- Incode About (founding, headquarters, valuation, offices) Read 2026-09-11
- Incode Trust Center (certifications and policies listed) Read 2026-09-11
- ZOREAL pricing (our own published prices) Read 2026-09-11
- ZOREAL Identify product page Read 2026-09-11
ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by Incode. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.
See ZOREAL Identify for yourself.
A product walkthrough, pricing or volume terms, with the ZOREAL team.