Skip to comparison
ZOREAL

ZOREAL Identify

Alternatives to Incode

Incode is an identity verification platform: Identity Verification runs "Document, biometric, and liveness checks in a single flow" with iBeta-certified passive liveness and Deepsight deepfake detection, Authentication makes "The face verified at onboarding" the credential for every later session within a customer’s own iOS, Android, web and call-centre channels, and Workforce verifies employees once and re-authenticates them biometrically for MFA resets, helpdesk requests and high-risk actions. ZOREAL Identify is a "Continue with ZOREAL" sign-in on standard OpenID Connect, backed by a credential ZOREAL issues after reading a government document chip in the ZOREAL ID app. This page sets a verify-once, re-authenticate-later platform whose reuse is within one customer beside a credential the person reuses at every relying party.

Information last reviewed 10 September 2026. Compared: Incode Identity Verification at onboarding, Authentication at login and Workforce as a verified-human check for employees against ZOREAL Identify; KYB, non-ID document validation and the Agentic Identity product are out of scope.

Where ZOREAL Identify and Incode differ

  • The guarantee

    ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.

  • Reused within one customer, or everywhere

    Incode states "The face verified at onboarding becomes the credential for every session after it" and that "One enrollment works across all of them", meaning a customer’s iOS, Android, web and call-centre channels; reuse across different services is not stated. ZOREAL issues the person one credential and the same ZOREAL ID logs in at every relying party, with a pairwise identifier per sector so the logins are not linkable across services.

  • The enrolled face, or the chip plus a device key

    Incode’s anchor after onboarding is the enrolled face: at login, passive liveness is confirmed and a 1:1 match is made against the enrolled identity, with deepfake and device-tampering screens. ZOREAL’s anchor is the document chip, read and verified against the issuing country’s certificates, plus a key generated in the phone’s hardware; the default login is an approval on the enrolled phone, and a relying party can require a fresh liveness capture face-matched to the enrolled document for a given login.

  • Demo request beside a published list

    Incode publishes no price list as of September 2026; a pricing URL returned not found and the Identity Verification, Authentication and Workforce pages offer a demo request. ZOREAL publishes its Identify prices: free to enrol, free tier a logins; only tier b logins charged.

Side by side

Comparison of ZOREAL Identify and Incode (Identity Verification, Authentication and Workforce), from public materials reviewed on 10 and 11 September 2026.

AttributeZOREAL IdentifyIncode
How the claim is madeEnrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope.At onboarding, "Document, biometric, and liveness checks in a single flow": the document is checked, the live capture is compared with the ID portrait, and iBeta-certified passive liveness plus Deepsight deepfake detection confirm a real human is present. At login, the person presents their face; passive liveness is confirmed, a 1:1 match is made against the enrolled identity, and deepfake and device-tampering screens run before access. NFC chip reading is not stated on the identity verification page we read.
GuaranteeZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine.Incode states iBeta Level 3 on iOS and Android and, on its trust center, ISO/IEC 30107-3:2023 and a Kantara IAL2 identity verification trust mark. A statement of assurance about the person beyond those test levels and trust marks is not stated in the public materials we reviewed.
Who issues the credentialZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses."The face verified at onboarding becomes the credential for every session after it", within one customer’s deployment: "One enrollment works across all of them" refers to that customer’s iOS, Android, web and call-centre channels. Reuse of the verified identity across different services is not stated in the materials we reviewed (the homepage, the Identity Verification, Authentication and Workforce pages, the platform page, the about page and the trust center).
What the relying party receivesTwo halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser.At onboarding, a verification result; at each later login, the outcome of the liveness check and the 1:1 face match against the enrolled identity; for Workforce, verification outcomes wired into Okta, Microsoft Entra ID, ServiceNow and other IAM, ITSM and HR systems.
Cost to enrolEnrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person.No published price list as of September 2026; a pricing URL returned not found and the Identity Verification, Authentication and Workforce pages offer "Request a demo".
Cost per sign-inEnrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers.Authentication is priced by demo request; no per-authentication amount is published. An OpenID Connect or FIDO passkey login protocol is not stated in the pages we reviewed.
IntegrationStandard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. One client library per platform: @zoreal/oauth2-react, @zoreal/oauth2-js and @zoreal/oauth2-react-native on npm for the front end, and backends for Node (@zoreal/oauth2-node), Ruby (zoreal-oauth2), Python (zoreal-oauth2), PHP (zoreal/oauth2), Go, Java (com.zoreal:oauth2) and .NET (Zoreal.OAuth2). The React package renders the button and drives the flow itself, with no hosted script and nothing to allowlist in a Content Security Policy. Registration is self-serve in the dashboard (Identify, Assets): redirect addresses, origins and permitted scopes, with domain verification; personal-data scopes require a verified domain and a confidential client.A developer hub with platform and API documentation, a Workflow Builder and UI customisation with no-code options; channels are iOS, Android, web and call centre. Workforce integrates with Okta, Microsoft Entra ID, Ping Identity, ServiceNow, Zendesk, Jira Service Management, Workday, Greenhouse, SAP SuccessFactors, Ashby, Slack, Zoom, Microsoft Teams and Google Meet.
Data handling and retentionThe ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when.The trust center references a Data Deletion Policy and a privacy policy; the retention period for biometric data was not in the text we read.
Certifications statedOrganization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026.Trust center: SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 30107-3:2023, ISO/IEC 42001:2023, HIPAA, FedRAMP Moderate, the Age Check Certification Scheme and a Kantara IAL2 trust mark; the homepage states iBeta Level 3 on iOS and Android, as listed in September 2026.

Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what Incode offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.

Where ZOREAL Identify and Incode agree

Both verify once and carry the assurance forward, and both run passive liveness with a 1:1 face match when a later login needs it. Incode confirms liveness and matches the face against the enrolled identity at each session; ZOREAL’s relying party can require a fresh liveness capture face-matched to the enrolled document, and the token states which authentication happened. Both let the business decide when a fresh biometric is required: Incode for high-risk actions, ZOREAL through the assurance floor the relying party sets per request.

Both state a defence against deepfakes at the biometric step: Incode names Deepsight, and ZOREAL’s liveness capture carries presentation-attack detection. And both bind a person to a device: Incode screens for device tampering at login, and ZOREAL generates the credential’s key in the phone’s hardware and verifies its attestation at registration.

Both publish organisation-level attestations rather than leaving security to the contract: Incode lists SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 42001 and FedRAMP Moderate; ZOREAL lists SOC 2, PCI DSS (SAQ A), GDPR, ISO/IEC 27001:2022 and CSA STAR Level One for Bynn Intelligence, Inc. Where they differ is the scope of reuse and who issues the credential, and the rows above state it.

ZOREAL Identify may fit you if

  • You want one enrolment reused at every relying party, beyond a single customer’s channels, with a pairwise identifier per sector
  • You want the anchor to be the document chip verified against the issuing country’s certificates and a hardware-bound device key, with the face as one factor
  • You want the pricing structure published before the sales call: free to enrol, free tier a logins; only tier b logins charged
  • You want a standard OpenID Connect provider your existing library validates, with client libraries for the front end and for Node, Ruby, Python, PHP, Go, Java and .NET

Incode may fit you if

  • You want onboarding and face-based returning-user login from one vendor, with one enrolment reused across your own channels
  • You need employee, candidate and helpdesk verification wired into Okta, Entra ID, ServiceNow or Zendesk
  • You need FedRAMP Moderate, Kantara IAL2 or ISO/IEC 42001 on the supplier’s trust center
  • You want a vendor stating iBeta Level 3 on iOS and Android

Other alternatives to Incode

35 more vendors compared under ZOREAL Identify, from their own public materials.

All 36 Identify comparisons

Common questions

How we compared

This comparison is based on publicly available information from Incode’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.

Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.

Sources

ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by Incode. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.

See ZOREAL Identify for yourself.

A product walkthrough, pricing or volume terms, with the ZOREAL team.