ZOREAL Identify
Alternatives to Shufti Pro
Shufti, formerly marketed as Shufti Pro, sells identity verification for onboarding: document verification across 240+ regions through a nine-layer forensic pipeline, NFC verification of chip-stored data, facial biometrics with "iBeta Level 3 certified liveness detection", address, database and AML checks, video identification, KYB and age verification, through a REST API and mobile SDKs. ZOREAL Identify is a "Continue with ZOREAL" sign-in on standard OpenID Connect, backed by a credential ZOREAL issues after reading a government document chip in the ZOREAL ID app. This page sets a per-check verification service, whose result the business keeps, beside a reusable login credential the person carries.
Information last reviewed 10 September 2026. Compared: Shufti’s identity verification at onboarding against ZOREAL Identify as a sign-in; Shufti’s KYB, AML screening and address verification are out of scope.
Where ZOREAL Identify and Shufti Pro differ
The guarantee
ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.
A per-check price beside a tiered structure
Shufti publishes $0.95 per check on Essentials and ten free verifications a month on Free Forever; a check is a verification at onboarding. ZOREAL publishes its structure, with the amounts on the ZOREAL price list: free to enrol, free tier a logins; only tier b logins charged; a charge applies only to a Tier B login where identity disclosure is requested, and Tier A logins are never charged. The vendor’s amount and ZOREAL’s structure sit side by side; the units differ.
Both verify the chip, at different moments
Shufti states NFC verification that "cryptographically verifies chip-stored biographic data" inside an onboarding check, alongside its forensic checks of the document image. ZOREAL reads the chip at enrolment, re-runs Passive Authentication on its own side against the ICAO master list, and face-matches a liveness capture to the chip portrait; every login that follows states how strongly and how recently that was proven.
A result per check or one credential
Shufti returns a verification result per check to the business that ran it. ZOREAL issues the person a credential once, and the same ZOREAL ID logs in at every relying party with a pairwise identifier per sector and no personal data in the ID token by default.
Side by side
Comparison of ZOREAL Identify and Shufti (Shufti Pro identity verification), from public materials reviewed on 11 September 2026.
| Attribute | ZOREAL Identify | Shufti Pro |
|---|---|---|
| How the claim is made | Enrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope. | The document image passes a "9-layer forensic pipeline" (MRZ and checksum validation, metadata analysis, GenAI detection, screenshot detection, replay defence, synthetic document detection, hologram analysis, print-and-scan detection, manipulation heatmaps); a selfie is tested for liveness and matched; NFC verification reads and "cryptographically verifies chip-stored biographic data" where used; address, database and watchlist checks run alongside. The result is returned to the business per verification. |
| Guarantee | ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. | Shufti states "iBeta Level 3 certified liveness detection" and NFC verification of chip-stored biographic data. A statement of assurance about the person beyond those checks is not stated in the public materials we reviewed. |
| Who issues the credential | ZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses. | Shufti issues no credential to the person; each check returns a result to the business. A reusable identity carried by the person between services is not stated in the public materials we reviewed (the homepage, the identity verification and document verification pages, the pricing page, the about page and the terms and privacy indexes). |
| What the relying party receives | Two halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser. | A verification result per check, through the REST API or the mobile SDKs. |
| Cost to enrol | Enrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person. | Free Forever: "$0 per check", "10 free verifications every month, no card required", pay as you go beyond. Essentials: "$0.95 per check", supporting up to 20,000 verifications (20,000 x $0.95 = $19,000). Enterprise: "Request Pricing". USD; geography not stated (September 2026). |
| Cost per sign-in | Enrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers. | An OpenID Connect or "sign in with" flow is not stated in the public materials we reviewed, so there is no per-sign-in price to quote; Shufti’s published unit is the check. |
| Integration | Standard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. One client library per platform: @zoreal/oauth2-react, @zoreal/oauth2-js and @zoreal/oauth2-react-native on npm for the front end, and backends for Node (@zoreal/oauth2-node), Ruby (zoreal-oauth2), Python (zoreal-oauth2), PHP (zoreal/oauth2), Go, Java (com.zoreal:oauth2) and .NET (Zoreal.OAuth2). The React package renders the button and drives the flow itself, with no hosted script and nothing to allowlist in a Content Security Policy. Registration is self-serve in the dashboard (Identify, Assets): redirect addresses, origins and permitted scopes, with domain verification; personal-data scopes require a verified domain and a confidential client. | REST API with a sandbox and mobile SDKs; "First verification call within hours of integration start". |
| Data handling and retention | The ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when. | Not read: the privacy page is an index to three notices and the Services Privacy Notice was not reachable when we reviewed it, so no retention period is stated here. |
| Certifications stated | Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026. | ISO 27001:2022, SOC 2, PCI DSS and Cyber Essentials Plus; iBeta Level 3 liveness, as listed in September 2026. |
Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what Shufti Pro offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.
Where ZOREAL Identify and Shufti agree
Both read the document chip and both run liveness on a selfie. Shufti states NFC verification of chip-stored biographic data and iBeta Level 3 liveness; ZOREAL reads the chip in the ZOREAL ID app, verifies the issuing country’s signature over the data on its own side, and face-matches a liveness capture to the chip portrait. The page compares the fact that both run these steps, because ZOREAL publishes no liveness test result of its own.
Both publish a free tier and a pricing structure on the website, which is uncommon enough in this group to count as shared ground: Shufti’s ten free verifications a month and $0.95 per check on Essentials, ZOREAL’s free enrolment and free Tier A logins with only a Tier B login charged, its amounts on the ZOREAL price list. The units differ, a check at onboarding against a login where identity disclosure is requested, and the page says so rather than lining them up as if they were the same thing.
Both publish organisation-level security attestations: Shufti lists ISO 27001:2022, SOC 2, PCI DSS and Cyber Essentials Plus; ZOREAL lists SOC 2, PCI DSS (SAQ A), GDPR, ISO/IEC 27001:2022 and CSA STAR Level One for Bynn Intelligence, Inc. A business can run Shufti at onboarding for address, database and AML checks, which ZOREAL does not perform, and add "Continue with ZOREAL" for the logins that follow.
ZOREAL Identify may fit you if
- You want one enrolment reused at every relying party, with a pairwise identifier per sector and no personal data in the ID token by default
- You want the pricing structure published before the sales call: free to enrol, free tier a logins; only tier b logins charged
- You want the chip verified on the provider’s side against the ICAO master list, a live face matched to the chip portrait and a hardware-bound device key
- You want a standard OpenID Connect provider your existing library validates, with client libraries for the front end and for Node, Ruby, Python, PHP, Go, Java and .NET
Shufti may fit you if
- You want a published per-check price and ten free verifications a month to start
- You need iBeta Level 3 liveness stated by the vendor
- You need document coverage the vendor states as 240+ regions with OCR in 150+ languages
- You need address, database, AML and KYB checks from the same API
Other alternatives to Shufti Pro
35 more vendors compared under ZOREAL Identify, from their own public materials.
- LexisNexis Risk SolutionsIDVerse, TrueID, InstantID and ThreatMetrix
A portfolio of fraud and identity services from LexisNexis Risk Solutions: database identity verification (InstantID, US), AI document authentication with face match and liveness (IDVerse, TrueID), email risk (Emailage) and device and behaviour risk (ThreatMetrix, BehavioSec).
- Pricing
- No published price list as of September 2026; contact sales. A UK public-sector G-Cloud listing shows ThreatMetrix at £0.01 a transaction.
- Assurance
- Optical document checks, biometric face match and liveness (IDVerse, TrueID); personal data matched to a reference database the vendor states covers almost 100% of US adults (InstantID); device and behavioural risk scores (ThreatMetrix). Chip reading is not stated in the materials reviewed.
- Reuse
- Results are returned to the calling business per check. A reusable identity carried by the person between services is not stated in the materials reviewed.
- ExperianCrossCore and Precise ID
Experian’s CrossCore is a digital identity and fraud platform that orchestrates Precise ID (US bureau-data identity verification with knowledge-based authentication), device risk and partner document and biometric checks into one decision for the business.
- Pricing
- No published price list as of September 2026; contact sales.
- Assurance
- Applicant personal data matched against Experian data with KBA step-up (Precise ID); device risk (FraudNet); document verification with biometric capabilities via Doc Capture and partners. Liveness method and chip reading are not stated in the materials reviewed.
- Reuse
- Decisions are returned to the calling business per check. A reusable identity carried by the person between services is not stated in the materials reviewed.
- GBGGBG Go, IDscan and greenID
GBG Go is GB Group plc’s identity platform: 110+ identity, fraud and risk modules across 195+ countries, including IDscan document authentication with NFC chip extraction and passive liveness, greenID government-data verification in Australia and New Zealand, sanctions and PEP screening and business verification.
- Pricing
- No published price list as of September 2026; GBG Go offers intro and demo forms, and IDscan and greenID route to a sales enquiry form
- Assurance
- IDscan: document authentication with NFC chip extraction and iBeta accredited ISO 30107-3 Level 2 passive liveness; greenID: identity details matched to government data sources with liveness certified to ISO 30107-3
- Reuse
- Results are returned to the business per journey; a reusable identity carried by the person between services is not stated in the materials we reviewed
- ProveProve Identity Platform and Prove Pre-Fill
Prove verifies identity through the phone: possession of the handset, the phone number’s reputation and ownership of the number by the named person, and pre-fills sign-up forms with verified identity data (Prove Pre-Fill).
- Pricing
- No published price list as of September 2026; the vendor’s AWS Marketplace listing states pricing is agreed customer by customer, with an implementation fee plus tiered transactional fees
- Assurance
- Phone possession (Prove Key, Mobile Auth or SMS), phone reputation (Trust Score) and ownership match against authoritative sources; the vendor states no document scans or selfies are needed
- Reuse
- Results are returned to the calling business per request; a reusable identity carried by the person between services is not stated in the materials we reviewed
- PlaidPlaid Identity Verification and Plaid Identity
Plaid Identity Verification checks a new user’s typed details against records, reads an uploaded government ID from 16,000+ types across 200 countries and territories, and matches a live selfie to it; Plaid Identity separately confirms name, phone, email and address from the user’s linked bank account.
- Pricing
- Plan structure published (Pay as You Go, Growth, Custom) with 200 free API calls per product in Limited Production; per-event amounts for Identity Verification are shown only when applying for Production access (September 2026)
- Assurance
- Data source verification, documentary verification and a selfie check that the video is "a genuine, live video of a real human" matching the document, plus SMS and watchlist screening; chip reading and a liveness test certification are not stated in the materials we reviewed
- Reuse
- Results are returned to the business per session; a reusable identity carried by the person between services is not stated in the materials we reviewed
- SignicateID and Wallet Hub and the KYC and KYB platform
Signicat’s eID and Wallet Hub lets a business accept 35 European national eIDs (BankID, MitID, itsme, SPID and others) and, from 2026, EUDI wallets through one API, alongside identity proofing by document, biometrics, liveness and data sources across 40+ countries.
- Pricing
- Setup, subscription and per-transaction fees by identity method with volume discounts; amounts are shown in the Signicat Dashboard after a free developer sign-up (September 2026)
- Assurance
- The assurance of the national eID or wallet the person already holds, brokered by Signicat; proofing by document checks, biometrics and liveness where no eID exists; Signicat states it is an EU Qualified Trust Service Provider with ISO 27001 and SOC 2 Type II
- Reuse
- Yes: the person reuses the national eID or wallet they hold at every business that integrates Signicat; a Signicat-issued credential is not stated in the materials we reviewed
Common questions
How we compared
This comparison is based on publicly available information from Shufti Pro’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.
Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.
Sources
- Shufti homepage (products, businesses, regions, documents, iBeta statement, certifications) Read 2026-09-11
- Shufti identity verification (methods, coverage, languages, integration, certifications) Read 2026-09-11
- Shufti document verification (NFC, coverage, forensic pipeline) Read 2026-09-11
- Shufti about us (offices) Read 2026-09-11
- Shufti privacy policy index (notices listed) Read 2026-09-11
- Shufti pricing (Free Forever, Essentials, Enterprise) Read 2026-09-11
- ZOREAL pricing (our own published prices) Read 2026-09-11
- ZOREAL Identify product page Read 2026-09-11
ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by Shufti Pro. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.
See ZOREAL Identify for yourself.
A product walkthrough, pricing or volume terms, with the ZOREAL team.