Skip to comparison
ZOREAL

ZOREAL Identify

Alternatives to Mitek

Mitek’s Mobile Verify reads the printed data, barcode or machine-readable zone of a document image and compares a selfie to it with passive liveness from IDLive Face, and its MiVIP platform returns the result to the business through a hosted web interface, SDKs or an API; MiPass re-authenticates a returning user for the same business. ZOREAL Identify is a "Continue with ZOREAL" sign-in on standard OpenID Connect, backed by a credential the person holds in the ZOREAL ID app after a document chip read, a face match and a liveness capture. This page sets the two side by side on mechanism, who holds the result afterwards, what each costs and how data is handled.

Information last reviewed 10 September 2026. Compared: Mitek’s Mobile Verify, the Mitek Verified Identity Platform (MiVIP), IDLive Face and MiPass with ZOREAL Identify. Mitek’s Mobile Deposit and Check Fraud Defender products, which make up the deposits side of the business, are out of scope.

Where ZOREAL Identify and Mitek differ

  • The guarantee

    ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.

  • Who holds the result afterwards

    Mitek returns the verification result to the business through MiVIP’s hosted flow, SDKs or API, and MiPass re-authenticates a returning user for that same business; a cross-business identifier or login is not stated in the public materials we reviewed. ZOREAL issues the credential to the person, who holds it in the ZOREAL ID app and logs in with it at every relying party; the relying party receives a pairwise pseudonymous identifier, stable within its registered sector and different at unrelated sectors, plus the assurance of each login stated in the token.

  • What a verification costs

    Mitek publishes no price list: miteksystems.com/pricing returned 404 on 10 September 2026 and the contact page is the route to a quote; no free tier, trial, minimum or set-up fee is stated on the pages read. ZOREAL: Free to enrol; Tier A logins free and unlimited on every plan and never charged; only a Tier B login, where identity disclosure is requested, is charged on Premium. Current prices are on the ZOREAL price list at zoreal.com/pricing.

  • Liveness evaluations on file

    Mitek states IDLive Face is "iBeta/NIST Level 1 and 2 PAD accredited" and "ISO/IEC 30107-3 Level 2 PAD tested, achieving a 0% spoof success rate", and that in DHS RIVTD 2025 testing IDLive Face blocked 100% of spoofing attacks; its about page lists SOC 2 and ISO 27001. Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026.

Side by side

Comparison of ZOREAL Identify and Mitek (Mobile Verify, MiVIP and IDLive Face), based on public materials reviewed on 10 September 2026.

AttributeZOREAL IdentifyMitek
How the identity is boundEnrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope.Mobile Verify uses "computer vision (CV) algorithms" and "optical character recognition (OCR)" on "printed bio-data, PDF418 barcode or the MRZ", then "biometric facial comparison algorithms" with passive and active anti-spoofing; IDLive Face "passively detects fraud from a single image without blinking, smiling, head turning or extra steps"; Digital Fraud Defender addresses deepfakes, AI-altered documents, template attacks, presentation attacks and injection attacks (miteksystems.com Mobile Verify, IDLive Face and MiVIP pages, September 2026). NFC chip reading and database checks are not stated in the public materials we reviewed (pages read: Mobile Verify, MiVIP, IDLive Face, documentation portal).
What the relying party receivesTwo halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser.A verification result to the business, through MiVIP’s hosted web interface, SDKs or API; MiPass "Passwordless biometric authentication" re-authenticates a returning user for the same business. A cross-business identifier or login is not stated in the public materials we reviewed (MiVIP page; products navigation).
GuaranteeZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine.Mobile Verify: "95% Acceptance rate", "92% Approval rate" and "99% Match rate", each marked with an asterisk whose footnote was not shown on the page read. IDLive Face: "ISO/IEC 30107-3 Level 2 PAD tested, achieving a 0% spoof success rate" and "DHS RIVTD 2025: IDLive Face blocked 100% of spoofing attacks in DHS testing" (Mobile Verify page; IDLive Face page).
Who issues the credentialZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses.No credential to the person: the result belongs to the business, and Mitek acts as "data processor" or "service provider" except where it is a "data controller" for certain identity verification services (privacy policy, 26 February 2026). MiPass re-authenticates for the same business.
Cost to enrolEnrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person.No published price list as of September 2026: miteksystems.com/pricing returned 404 on 10 September 2026 and the contact page is the route to a quote; no free tier, trial, minimum or set-up fee is stated on the pages read.
Cost per sign-inEnrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers.No published price per verification or per MiPass authentication as of September 2026 (pages read: pricing URL, contact page, MiVIP page).
IntegrationStandard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. One client library per platform: @zoreal/oauth2-react, @zoreal/oauth2-js and @zoreal/oauth2-react-native on npm for the front end, and backends for Node (@zoreal/oauth2-node), Ruby (zoreal-oauth2), Python (zoreal-oauth2), PHP (zoreal/oauth2), Go, Java (com.zoreal:oauth2) and .NET (Zoreal.OAuth2). The React package renders the button and drives the flow itself, with no hosted script and nothing to allowlist in a Content Security Policy. Registration is self-serve in the dashboard (Identify, Assets): redirect addresses, origins and permitted scopes, with domain verification; personal-data scopes require a verified domain and a confidential client.MiVIP: "No-code: Quick integration through our hosted web interface", "Low-code: Simplified integration using our SDKs", "Full-code: Direct API integration for custom implementation". IDLive Face: "Available as an SDK or Docker container with a straightforward RESTful API", with a mobile SDK in beta for on-device use (MiVIP page; IDLive Face page).
Data handlingThe ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when.Privacy policy (updated 26 February 2026): processor or service provider except where controller for certain identity verification services; biometric data destroyed "within 3 years of your last interaction" or when the initial purpose has been satisfied, whichever first; fraud-detection data destroyed within approximately 90 days if no fraud is detected; images may be retained for improvement of Mitek’s facial recognition technology under legitimate interests.
Certifications and evaluationsOrganization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026.About page: "SOC 2, ISO 27001"; MiVIP page: "ISO 27001 and AICPA SOC Certified". IDLive Face: "iBeta/NIST Level 1 and 2 PAD accredited", "ISO/IEC 30107-3 Level 2 PAD tested, achieving a 0% spoof success rate", and DHS RIVTD 2025 results as stated by Mitek; confirmation letters are not linked from the pages read.

Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what Mitek offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.

Where ZOREAL Identify and Mitek agree

Both start from the same evidence: a government identity document and a live face. Mitek reads the printed data, the PDF417 barcode or the machine-readable zone of the document image and compares a selfie to it, with IDLive Face testing liveness from a single image and Digital Fraud Defender watching for injected or altered inputs. ZOREAL ID enrolment photographs the document, reads its machine-readable zone, reads the chip over NFC, checks the issuing country’s signature over the chip data on ZOREAL’s side, and face-matches a liveness capture against the chip portrait. The bar is the same one: a real document and a real person, bound together.

Both also publish a ceiling on how long a face is kept. Mitek’s privacy policy destroys biometric data within three years of the last interaction or when the purpose is satisfied, whichever comes first. ZOREAL’s ID token carries no personal data, and the document portrait is a separately gated tier that a relying party must request and the person must consent to. Neither claims a legal signature or a KYC outcome from the verification alone.

Where they differ is what happens after the check. Mitek’s result goes to the business through MiVIP, and MiPass re-authenticates the same person for that business, under a contract with no published price; Mitek is a listed company whose fiscal 2025 revenue of $179.7 million spans identity and check products. ZOREAL issues the credential to the person, who reuses it as a sign-in at every relying party with a different pairwise identifier at each sector, at a published price; the person pays nothing and the relying party pays nothing for a Tier A login.

ZOREAL Identify may fit you if

  • You want a sign-in rather than a check: a "Continue with ZOREAL" button on standard OpenID Connect that returns a pairwise pseudonymous identifier for a human verified against a government document chip
  • You want the document’s chip read and its authenticity verified at enrolment, not only the printed image, barcode and MRZ checked
  • You want published pricing with no sales call: free enrolment, every Tier A login free without limit, and a charge only on a Tier B login where you request identity disclosure
  • You want the person, not your database, to hold the credential, and to reuse it at every service without being linkable across them

Mitek may fit you if

  • You want a liveness component you can run yourself: IDLive Face ships as an SDK, a Docker container and a REST API
  • You need a no-code hosted verification flow you can switch on without an SDK (MiVIP)
  • You prefer a publicly listed vendor with audited financials on file (NASDAQ: MITK)
  • You must verify people who will not install an app: the MiVIP hosted web interface runs in the browser

Other alternatives to Mitek

35 more vendors compared under ZOREAL Identify, from their own public materials.

All 36 Identify comparisons

Common questions

How we compared

This comparison is based on publicly available information from Mitek’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.

Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.

Sources

ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by Mitek. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.

See ZOREAL Identify for yourself.

A product walkthrough, pricing or volume terms, with the ZOREAL team.