Skip to comparison
ZOREAL

ZOREAL Identify

Alternatives to Regula

Regula is a component supplier: its Document Reader SDK reads the visual zone, MRZ, barcodes and the RFID chip of identity documents and checks authenticity against "16,500+ templates from 254 countries and territories", its Face SDK matches a live face with liveness "iBeta-certified at PAD Level 1 and Level 2 under ISO/IEC 30107-3", and its hardware readers examine documents at counters and borders. ZOREAL Identify is a "Continue with ZOREAL" sign-in on standard OpenID Connect, backed by a credential ZOREAL issues after reading a government document chip in the ZOREAL ID app. This page sets a toolkit an integrator builds its own verification with, which asserts nothing about the person, beside a finished login credential, so the two are not read as like for like.

Information last reviewed 10 September 2026. Compared: Regula’s SDKs, Web APIs and Identity Verification Platform as the building blocks of an onboarding verification against ZOREAL Identify as a sign-in; Regula’s forensic devices and its hardware readers for borders are out of scope beyond a mention.

Where ZOREAL Identify and Regula differ

  • The guarantee

    ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.

  • A toolkit or a finished login

    Regula sells SDKs, Web APIs, hardware readers and a platform that an integrator runs in its own app or server; the integrator owns each result and Regula asserts nothing about the person. ZOREAL runs the verification itself in the ZOREAL ID app and on its servers, issues the credential, and hands the relying party a login on standard OpenID Connect.

  • Both verify the chip; one issues a credential

    Regula’s Document Reader SDK performs "NFC-based verification of electronic documents with RFID chip" and its Face SDK matches a live face with iBeta PAD Level 1 and 2 liveness, for whoever integrates them. ZOREAL reads the chip, re-runs Passive Authentication on its own side against the ICAO master list, face-matches a liveness capture to the chip portrait, and issues two holder certificates over a hardware-bound key.

  • A trial and a quote, or a published list

    Regula offers a "30-day free trial" of its SDKs and prices licences on usage or perpetually, with no amount published for any licence or device. ZOREAL publishes its Identify prices: free to enrol, free tier a logins; only tier b logins charged.

Side by side

Comparison of ZOREAL Identify and Regula (Document Reader SDK, Face SDK and the Identity Verification Platform), from public materials reviewed on 10 and 11 September 2026.

AttributeZOREAL IdentifyRegula
How the claim is madeEnrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope.Document Reader SDK reads the visual zone by OCR, the MRZ and barcodes, reads and verifies the RFID chip by NFC, and runs authenticity checks such as hologram detection and screenshot identification against a template library; Face SDK matches a live face to the document portrait with liveness. The integrator runs these components in its own app or server and owns the result; hardware readers do the same at a counter or border. Regula itself asserts nothing about the person.
GuaranteeZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine.Face SDK is "iBeta-certified at PAD Level 1 and Level 2 under ISO/IEC 30107-3". Whatever assurance results is the integrator’s: Regula supplies the components and states no claim about the person.
Who issues the credentialZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses.No one, on Regula’s side: Regula issues no identity, and each integrator owns the results of its own verifications. A reusable identity or a "sign in with" product is not stated in the pages we reviewed (the homepage, the Document Reader SDK, Face SDK, document readers and Identity Verification Platform pages, the Web API pages and the Terms of Use).
What the relying party receivesTwo halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser.Not applicable as a service: the integrator’s own application receives the SDK’s document, chip and face results and decides. The Identity Verification Platform orchestrates document and biometric verification with "on-prem or cloud hosting".
Cost to enrolEnrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person.Document Reader SDK: "30-day free trial" with full access, then "flexible pricing based on real usage and your business needs" or a perpetual licence; Face SDK and the Web APIs: free trial, contact for licensing; hardware readers: no price stated. No amount is published for any licence or device as of September 2026; a pricing URL returned not found.
Cost per sign-inEnrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers.Not applicable: Regula sells no sign-in, and a "sign in with" flow is not stated in the pages we reviewed. An integrator that re-authenticates its users with Face SDK pays the licence.
Integration and deploymentStandard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. One client library per platform: @zoreal/oauth2-react, @zoreal/oauth2-js and @zoreal/oauth2-react-native on npm for the front end, and backends for Node (@zoreal/oauth2-node), Ruby (zoreal-oauth2), Python (zoreal-oauth2), PHP (zoreal/oauth2), Go, Java (com.zoreal:oauth2) and .NET (Zoreal.OAuth2). The React package renders the button and drives the flow itself, with no hosted script and nothing to allowlist in a Content Security Policy. Registration is self-serve in the dashboard (Identify, Assets): redirect addresses, origins and permitted scopes, with domain verification; personal-data scopes require a verified domain and a confidential client.Document Reader SDK: iOS, Android, web, server, on-premise, mobile demo apps and a Web API. Face SDK: iOS, Android, Flutter, React Native, Ionic, Cordova, .NET MAUI, JavaScript, Java, Python and C#, in the cloud or on-premises via Linux, Windows and Docker. Identity Verification Platform: on-prem or cloud hosting.
Data handling and retentionThe ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when.Not applicable to the SDK model, where the integrator holds the data, and not stated for the hosted platform in the pages we reviewed. Demo versions are provided "as is" under the Terms of Use.
Certifications statedOrganization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026.Face SDK: iBeta PAD Level 1 and Level 2 under ISO/IEC 30107-3. The Identity Verification Platform page lists ICAO 9303, ISO 9001:2015, BSI TR-03105 parts 5.1 and 5.2, ISO 30107-3, WCAG 2.2 AA, GDPR and CCPA statements. ISO 27001 is not stated on the pages we read.

Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what Regula offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.

Where ZOREAL Identify and Regula agree

Both read and verify the chip of an electronic identity document over NFC, and both treat a live face matched to the document portrait as part of the check. Regula’s Document Reader SDK verifies the RFID chip and its Face SDK runs liveness tested to iBeta PAD Levels 1 and 2; ZOREAL reads the chip in the ZOREAL ID app, re-runs Passive Authentication on its own side, and face-matches a liveness capture to the chip portrait. The components are the same class of check; who runs them and who vouches for the result is the difference.

Both offer a free way to start: Regula’s 30-day trial with full access to the Document Reader SDK, and ZOREAL’s Free plan with free enrolment, Tier A logins free without limit and one client configuration. And both list ICAO 9303 and ISO 30107-3 among the standards their document and liveness work follows.

A relying party that wants to run its own document and biometric pipeline, on its own servers, is Regula’s customer, and Regula is a plausible supplier of document templates and chip reading to any verification service. A relying party that wants a finished login it does not have to operate adds "Continue with ZOREAL". The two are not substitutes so much as different layers of the same stack.

ZOREAL Identify may fit you if

  • You want a finished login you do not have to build or host: the provider verifies the chip, the face, the liveness and the device key, and issues the credential
  • You want one enrolment reused at every relying party, with a pairwise identifier per sector and no personal data in the ID token by default
  • You want the pricing structure published before the sales call: free to enrol, free tier a logins; only tier b logins charged
  • You want a standard OpenID Connect provider and an npm package that renders the button, with nothing to allowlist in a Content Security Policy

Regula may fit you if

  • You want to run document and chip verification inside your own app or on your own servers rather than through a hosted service
  • You need a document template library the vendor states as 16,500+ templates across 254 countries and territories
  • You need hardware readers for counters, kiosks or borders
  • You want liveness with an iBeta PAD Level 1 and 2 statement delivered as an SDK for iOS, Android, web and server

Other alternatives to Regula

35 more vendors compared under ZOREAL Identify, from their own public materials.

All 36 Identify comparisons

Common questions

How we compared

This comparison is based on publicly available information from Regula’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.

Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.

Sources

ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by Regula. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.

See ZOREAL Identify for yourself.

A product walkthrough, pricing or volume terms, with the ZOREAL team.