Solidus Verify
How this works, explained once
Reusable KYC explained end to end: document capture, liveness, credential issuance, and what a verification you already paid for can be used for again.
73 articles
- Reusable KYC. The verification you already built doesn't travel.The unlinkability implementation described here is unaudited.
- The Hosted Verification Flow, copy deckThis is not an article and must not be published as one. It is the copy for the six step components a real person walks through at verify.solidus.network/s/[sessionId], plus the consent and data-handling language.
- How a Solidus verification feelsThe unlinkability implementation described here is unaudited.
- Pay per verification, not again for the credential you already ownNothing on this page is billed to anyone; there is no customer, pilot, or logo yet.
- We Run on a Testnet, We Hold No Certification, and Here Is What We Actually Delete
- Supported documents. The document types Verify's backend actually readsWhat follows is the exact document list the documents.type database constraint and the capture UI enforce today, checked against that source for this page, not copied from an older draft.
- Solidus Verify vs. Sumsub, reusable KYC comparedThe unlinkability implementation described here is unaudited.
- Solidus Verify vs. Persona: matching the DX bar, adding portabilityPersona is the developer-experience benchmark in this category, and we're not going to pretend otherwise.
- Reusable KYC. The verification you already built doesn't travel, until now.No external organization runs this in production yet; the demo shows what portability looks like, not who has bought it.
- KBS-compliant guest verification, done onceBefore anything else: Solidus does not yet have a live filing integration with Turkey's hotel guest-registration system.
- Age verification without storing a birthdateThe unlinkability implementation described here is unaudited.
- Verified SIM activation without a stored ID copySay this plainly first: nothing below is a shipped integration.
- Verify our unlinkability claim yourself, no account, no trust requiredThe unlinkability implementation described here is unaudited.
- QuickstartThe unlinkability implementation described here is unaudited.
- Case studies, framework page, no customer existsThe unlinkability implementation described here is unaudited.
- What's actually inside a Solidus-issued KYC credentialThe unlinkability implementation described here is unaudited.
- Connect Solidus Verify to your existing stackThe useful framing is that there are only three ways in, and which one you want depends on a single question: who talks to the user?
- Solidus Verify vs Stripe Identity: a credential that is not locked to one platformStripe Identity is a live product inside a payments company that processes real money for real businesses today.
- Re-KYC. The repetition a held credential was designed forThis page defines the term and says exactly where a portable credential touches it.
- Periodic review, the scheduled half of ongoing due diligenceSolidus ships no review workflow, no scheduling engine and no case management.
- Risk scoring, defined, and why it is not our productSolidus has no risk engine, and a portable credential contributes nothing to risk scoring.
- Sanctions screening, defined, and explicitly not something Solidus doesSolidus ships no sanctions screening, no PEP screening and no adverse-media screening.
- Adverse media screening, defined, and not something Solidus doesSolidus ships no adverse-media screening. It is not-built in our lexicon, alongside sanctions and PEP screening.
- Remediation, fixing a book of customers that was onboarded badlySolidus runs no remediation programmes and ships no case management.
- False-positive rate. The metric that decides whether screening is survivableSolidus does not ship screening, so we have no false-positive rate to report.
- Drop-off rate, the metric that decides whether your KYC flow worksSolidus measures drop-off in its own verification flow. This is one of the operational metrics we actually track, and this page defines it for a buyer who will ask.
- Pass rate, the number every vendor quotes and nobody definesSolidus measures pass rate in its own verification pipeline. It is one of the metrics we track, and this page defines it, including why the figure you are quoted by any vendor, ours included, is…
- CDD, customer due diligence, and the one step of it we performSolidus does not provide customer due diligence. CDD is not-built in our lexicon.
- PEP, politically exposed persons, and why status is not identitySolidus does not ship PEP screening. It is not-built in our lexicon, along with sanctions and adverse-media screening.
- UBO, ultimate beneficial ownership, and the layer we sit underSolidus does not resolve beneficial ownership. UBO is not-built in our lexicon, as is the KYB work it belongs to.
- Source of wealth and source of funds, two questions, neither of them oursSolidus does not perform source-of-wealth or source-of-funds work.
- VASP, what the designation means, and what it would mean for usSolidus is not a VASP, does not hold any VASP registration or licence, and makes no regulatory claim of any kind.
- MiCA, what it covers, and why Solidus is not inside itSolidus holds no MiCA authorisation, is not a crypto-asset service provider, and makes no compliance claim under any EU regulation.
- The FATF Travel Rule, defined, and categorically not a Solidus productNo Solidus product implements the Travel Rule. This is not a roadmap statement or a scoping nuance, a search across every TypeScript, Rust and SQL file in the codebase for ivms101 and travel_rule…
- Turkish crypto-asset service provider licensing, the regime our buyers operate underSolidus holds no Turkish licence, registration or authorisation of any kind, and implements no Turkish compliance tooling.
- Account takeover, where identity binding actually helpsSolidus does not ship an account-takeover product, and there is no ATO detection, device intelligence or behavioural analytics in anything we build.
- Chargeback, a liability problem, not an identity oneSolidus ships nothing that addresses chargebacks, and unlike most pages in this section, there is no useful identity angle to offer.
- First-party fraud. The case our whole argument does not reachThis is the page where identity verification stops helping, and we would rather write that than stretch an argument to cover it.
- Synthetic identity fraud, where our pipeline bears on it, and where it stopsThe two pages before this one, chargeback and first-party fraud, both concluded that identity verification cannot address the problem.
- The manual review queue, one of the few things on this list we actually shipThis is running code, not a roadmap item, which makes it unusual on a page list where most entries are things we have declined to build.
- GDPR. A law that already applies to us, and a compliance program that does not exist yetGDPR is not something a company obtains. It is binding law that already applies to us, and the documentation a serious buyer would ask for does not exist yet.
- KVKK, Türkiye's data-protection law, and the pincer it puts our buyers inNo Solidus product is KVKK-compliant, and no independent audit says otherwise.
- MASAK. The regime our buyers answer to, and the requirement we do not meetMali Suçları Araştırma Kurulu, the Financial Crimes Investigation Board, is Türkiye's financial intelligence unit, established under the Ministry of Treasury and Finance by Law No.
- TCKN. The number every Turkish system keys off, and the two things we can and cannot do with itSolidus operates no integration with the Turkish population registry, and performs no live TCKN-to-registry match.
- e-Devlet, the incumbent answer in Türkiye, and why we say so on our own pageSolidus has no e-Devlet integration, and no Solidus credential derives from or is co-signed by an e-Devlet authentication event.
- Law No. 6222, identity at the turnstile, and the accreditation we do not holdSolidus has no relationship with any football club, with the Turkish Football Federation, or with any turnstile operator, and no Solidus credential has ever been accepted at any stadium gate.
- The right to erasure versus the audit trail. The law resolves it; we have not built the workflowThe regulation already resolves this tension. What it leaves behind is a clock, and knowing when each record's retention expires is the engineering nobody does.
- SOC 2, not engaged, not started, and not the thing most buyers think it isNo SOC 2 audit has been engaged. No auditor has been selected.
- ISO 27001. A management system we have not built, and an excuse that does not apply hereNo Solidus product has a documented information security management system.
- NIST iBeta". The name is wrong, the testing is real, and we have not been through itNo Solidus product has been submitted to iBeta or to any other accredited laboratory for presentation-attack-detection testing, and no Level 1 or Level 2 result exists.
- Right to work, a name in our design documents, not a capabilitySolidus has never performed, and has never been accredited to perform, a right-to-work check in any country.
- IVMS 101. The schema is the easy part, and we do not even emit thatNo IVMS 101 message construction, parsing or transmission exists anywhere in the Solidus codebase, confirmed by searching every TypeScript, Rust and SQL file, re-run 2026-07-31, not recalled from memory.
- Reliance. The mechanical half runs today; the half our whole argument needs has never happenedReliance has a mechanical half and a human half, and they are not the same achievement.
- Cost per verification. The metric we lose on, and a published price that is softer than it looksOn cost per verification for a single, first-time check, Solidus is more expensive than the incumbents it is compared against.
- Re-verification cost, the half of the arithmetic that favours us, held to the same standardThis is the page where our own pricing draft looks good, which is exactly why it gets the same scepticism as the page where it does not.
- Total cost of ownership. The crossover is a range, not a number, and here is the whole rangeNo Solidus total-cost-of-ownership calculator, worksheet or published multi-year model exists.
- Credential reuse rate, undefined, which is a different thing from zero or smallAny reuse-rate figure quoted for Solidus today would be fabricated.
- Verification reuse. The plumbing runs, and the plumbing was never the hard partThe mechanism is real, and you can check part of it yourself in one command.
- Vendor lock-in. We are also a vendor, and adopting us creates a real dependency of its ownThe sales version of this page would say that a portable credential eliminates lock-in.
- Liveness detection, what is built, what has not cleared review, and what depends on deploymentOur passive anti-spoof model has not cleared an adversarial security review, so we do not describe anything here as anti-spoof or as certified liveness: that claim is withheld until it is earned.
- Presentation attack detection, whose model this actually is, and a threshold we have never evaluatedThis is the clearest "built but not claimable" item in our stack, and we would rather label it that way than let running code imply a finished capability.
- Selective disclosure mechanics, two mechanisms, two different guarantees, one of them unaudited
- The OID4VP verifier, real endpoints, real policy knobs, and one of them means less than it readsThe verifier side is live and auth-gated on the capture API.
- EUDI wallet issuance, not certified, not recognised, and gated on a partner we do not haveSolidus does not ship a wallet that is EUDI-certified, and no Member State recognises anything we issue.
- Trust anchors. There are two of them, and we control bothEvery trust anchor in the Solidus stack is operated by Solidus.
- Data residency. One server in Germany, object storage with no jurisdiction set, and a live page that says otherwiseSolidus offers no data-residency guarantee to anyone, has no regional deployment options, and no signed agreement specifying a storage location.
- Data minimisation, real at the disclosure step, and the opposite of minimal at the collection stepOur architecture is built to minimise what a verification discloses, through an unaudited selective-disclosure path.
- Global KYC Regulatory AtlasThe only two things we hold are a Decentralized Identity Foundation Associate Membership and a did:solidus listing in the W3C DID Method Registry.
- Become a Launch PartnerThere is no launch partner yet. There is no customer, no pilot and no logo to show you, and this page has none.
- Enterprise KYC at any scaleThe headline above is on our live page and we are not going to quietly leave it standing without that paragraph underneath it.
- Crypto & DeFi VerificationNo crypto exchange, broker or protocol uses Solidus. There is no pilot and no named counterparty on this page.
- Try a Solidus verification.Before you upload anything, read the next two paragraphs.
- ChangelogA changelog is a claim about the past, and it rots the same way every other claim on a marketing site rots.