Skip to comparison
ZOREAL

ZOREAL Identify

Alternatives to Shufti Pro

Shufti, formerly marketed as Shufti Pro, sells identity verification for onboarding: document verification across 240+ regions through a nine-layer forensic pipeline, NFC verification of chip-stored data, facial biometrics with "iBeta Level 3 certified liveness detection", address, database and AML checks, video identification, KYB and age verification, through a REST API and mobile SDKs. ZOREAL Identify is a "Continue with ZOREAL" sign-in on standard OpenID Connect, backed by a credential ZOREAL issues after reading a government document chip in the ZOREAL ID app. This page sets a per-check verification service, whose result the business keeps, beside a reusable login credential the person carries.

Information last reviewed 10 September 2026. Compared: Shufti’s identity verification at onboarding against ZOREAL Identify as a sign-in; Shufti’s KYB, AML screening and address verification are out of scope.

Where ZOREAL Identify and Shufti Pro differ

  • The guarantee

    ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.

  • A per-check price beside a tiered structure

    Shufti publishes $0.95 per check on Essentials and ten free verifications a month on Free Forever; a check is a verification at onboarding. ZOREAL publishes its structure, with the amounts on the ZOREAL price list: free to enrol, free tier a logins; only tier b logins charged; a charge applies only to a Tier B login where identity disclosure is requested, and Tier A logins are never charged. The vendor’s amount and ZOREAL’s structure sit side by side; the units differ.

  • Both verify the chip, at different moments

    Shufti states NFC verification that "cryptographically verifies chip-stored biographic data" inside an onboarding check, alongside its forensic checks of the document image. ZOREAL reads the chip at enrolment, re-runs Passive Authentication on its own side against the ICAO master list, and face-matches a liveness capture to the chip portrait; every login that follows states how strongly and how recently that was proven.

  • A result per check or one credential

    Shufti returns a verification result per check to the business that ran it. ZOREAL issues the person a credential once, and the same ZOREAL ID logs in at every relying party with a pairwise identifier per sector and no personal data in the ID token by default.

Side by side

Comparison of ZOREAL Identify and Shufti (Shufti Pro identity verification), from public materials reviewed on 11 September 2026.

AttributeZOREAL IdentifyShufti Pro
How the claim is madeEnrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope.The document image passes a "9-layer forensic pipeline" (MRZ and checksum validation, metadata analysis, GenAI detection, screenshot detection, replay defence, synthetic document detection, hologram analysis, print-and-scan detection, manipulation heatmaps); a selfie is tested for liveness and matched; NFC verification reads and "cryptographically verifies chip-stored biographic data" where used; address, database and watchlist checks run alongside. The result is returned to the business per verification.
GuaranteeZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine.Shufti states "iBeta Level 3 certified liveness detection" and NFC verification of chip-stored biographic data. A statement of assurance about the person beyond those checks is not stated in the public materials we reviewed.
Who issues the credentialZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses.Shufti issues no credential to the person; each check returns a result to the business. A reusable identity carried by the person between services is not stated in the public materials we reviewed (the homepage, the identity verification and document verification pages, the pricing page, the about page and the terms and privacy indexes).
What the relying party receivesTwo halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser.A verification result per check, through the REST API or the mobile SDKs.
Cost to enrolEnrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person.Free Forever: "$0 per check", "10 free verifications every month, no card required", pay as you go beyond. Essentials: "$0.95 per check", supporting up to 20,000 verifications (20,000 x $0.95 = $19,000). Enterprise: "Request Pricing". USD; geography not stated (September 2026).
Cost per sign-inEnrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers.An OpenID Connect or "sign in with" flow is not stated in the public materials we reviewed, so there is no per-sign-in price to quote; Shufti’s published unit is the check.
IntegrationStandard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. One client library per platform: @zoreal/oauth2-react, @zoreal/oauth2-js and @zoreal/oauth2-react-native on npm for the front end, and backends for Node (@zoreal/oauth2-node), Ruby (zoreal-oauth2), Python (zoreal-oauth2), PHP (zoreal/oauth2), Go, Java (com.zoreal:oauth2) and .NET (Zoreal.OAuth2). The React package renders the button and drives the flow itself, with no hosted script and nothing to allowlist in a Content Security Policy. Registration is self-serve in the dashboard (Identify, Assets): redirect addresses, origins and permitted scopes, with domain verification; personal-data scopes require a verified domain and a confidential client.REST API with a sandbox and mobile SDKs; "First verification call within hours of integration start".
Data handling and retentionThe ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when.Not read: the privacy page is an index to three notices and the Services Privacy Notice was not reachable when we reviewed it, so no retention period is stated here.
Certifications statedOrganization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026.ISO 27001:2022, SOC 2, PCI DSS and Cyber Essentials Plus; iBeta Level 3 liveness, as listed in September 2026.

Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what Shufti Pro offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.

Where ZOREAL Identify and Shufti agree

Both read the document chip and both run liveness on a selfie. Shufti states NFC verification of chip-stored biographic data and iBeta Level 3 liveness; ZOREAL reads the chip in the ZOREAL ID app, verifies the issuing country’s signature over the data on its own side, and face-matches a liveness capture to the chip portrait. The page compares the fact that both run these steps, because ZOREAL publishes no liveness test result of its own.

Both publish a free tier and a pricing structure on the website, which is uncommon enough in this group to count as shared ground: Shufti’s ten free verifications a month and $0.95 per check on Essentials, ZOREAL’s free enrolment and free Tier A logins with only a Tier B login charged, its amounts on the ZOREAL price list. The units differ, a check at onboarding against a login where identity disclosure is requested, and the page says so rather than lining them up as if they were the same thing.

Both publish organisation-level security attestations: Shufti lists ISO 27001:2022, SOC 2, PCI DSS and Cyber Essentials Plus; ZOREAL lists SOC 2, PCI DSS (SAQ A), GDPR, ISO/IEC 27001:2022 and CSA STAR Level One for Bynn Intelligence, Inc. A business can run Shufti at onboarding for address, database and AML checks, which ZOREAL does not perform, and add "Continue with ZOREAL" for the logins that follow.

ZOREAL Identify may fit you if

  • You want one enrolment reused at every relying party, with a pairwise identifier per sector and no personal data in the ID token by default
  • You want the pricing structure published before the sales call: free to enrol, free tier a logins; only tier b logins charged
  • You want the chip verified on the provider’s side against the ICAO master list, a live face matched to the chip portrait and a hardware-bound device key
  • You want a standard OpenID Connect provider your existing library validates, with client libraries for the front end and for Node, Ruby, Python, PHP, Go, Java and .NET

Shufti may fit you if

  • You want a published per-check price and ten free verifications a month to start
  • You need iBeta Level 3 liveness stated by the vendor
  • You need document coverage the vendor states as 240+ regions with OCR in 150+ languages
  • You need address, database, AML and KYB checks from the same API

Other alternatives to Shufti Pro

35 more vendors compared under ZOREAL Identify, from their own public materials.

All 36 Identify comparisons

Common questions

How we compared

This comparison is based on publicly available information from Shufti Pro’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.

Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.

Sources

ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by Shufti Pro. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.

See ZOREAL Identify for yourself.

A product walkthrough, pricing or volume terms, with the ZOREAL team.