Say you open a trading account on your phone. Within two minutes, you have photographed your PAN card, held your face up to the camera and turned your head when told to. No person looked at any of it. Software read the card, matched your face to the photo on it, and checked your name against the regulator's lists. Then it decided you were real.
This is identity verification. Banks, brokers and wallets must check who you are before they can take you on as a customer. These checks are called know your customer, or KYC. Indian regulators demanded digital KYC at a scale no other country had. So this is one of the industries India built for itself.
Market Segment 4.2, Identity and access management (IAM), was about proving who an employee is. This Market Segment is about proving who a stranger is: at the moment they become a customer, and every time they come back. The companies here sell these checks to banks, lenders, brokers, telecom operators and apps. You, the customer, never deal with them directly.
Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.
This Market Segment has two sub-segments:
Reading the document and matching the face: the checks when you open the account. Indian companies grew up running them for banks and fintechs, the newer financial-technology companies.
Human or bot, customer or fraudster: the quieter checks on every login and every transaction after that. They use the device, the behaviour and the network, not a document.
The rules behind these checks, and the monitoring of transactions that comes after, are in Market Segment 19.2, Fraud prevention, AML and regtech (in Industry Vertical 19, Banking and regtech). Six companies here also appear there: HyperVerge, Signzy, AiPrise, Jumio, Bureau and SecuredTouch.
Reading the document and matching the face
Identity verification, video and document KYC, liveness, business verification, age estimation
Take the trading account from the start of this Market Segment. Behind those two minutes is one API. The broker's app sends it a photo of your identity document and a selfie. The API sends back a verdict on four checks:
- The document is genuine.
- The face on the document is the face in the selfie.
- The selfie shows a live person, not a photo of a photo. This check is called liveness.
- The name is not on a sanctions list or a list of politically exposed persons.
The law requires the last check. Sanctions lists name people and organisations that businesses may not deal with. Politically exposed persons are people in public office and their close family, and banks must check them more carefully. Sometimes the whole check happens on a live video call with an official of the bank or broker instead. This is called video KYC.
Two minutes behind one API. The broker's app sends a photo of your PAN card and a selfie to a verification API from a company such as IDfy, HyperVerge or Signzy. It checks that the document is genuine, that the face matches the photo, that a live person is in front of the camera, and that the name is not on a sanctions or politically exposed persons list, then returns a verdict. Sometimes the whole check is a live video call instead, called video KYC.
In India, this API sits inside the apps of fintechs, lenders, brokers, telecom operators and gig platforms. The companies that sell it are mostly Indian.
IDfyfrom Mumbai, is the largest and the broadest of them. It uses the same platform to verify customers for banks and employees for employers. (More on its employee checks in Market Segment 12.7, Background screening and verification providers, in Industry Vertical 12, HR tech.)
HyperVergein Bengaluru, built the computer-vision models for face matching and liveness. They work on a cheap phone over a weak connection.
Signzydoes automated verification and fraud detection for banks and other financial companies. Deepfake detection, spotting faces and videos faked with AI, is now part of its product.
VIDAfrom Indonesia, adds a digital signature certificate to the verified identity. So the person who was verified can also sign documents. (More on signing in Market Segment 10.4, Document processing, management and e-signature software, in Industry Vertical 10, ERP and business automation.)
AiPriseis the newest. It verifies businesses as well as people. Checking that a business is real, and who owns it, is called know your business, or KYB. AiPrise runs the compliance review with AI agents.
The global companies here have small teams in India:
Jumiois one of the companies that invented verification by document and selfie.
Socurescores how risky an identity is, using a shared pool of American data.
Yotifrom London, estimates a person's age from their face without identifying them. That is how websites meet age-verification laws without collecting documents.
One company here works for employers instead:
OnGridruns the same checks of a document and a face, but for an employer checking a job candidate, not for a bank checking a customer. (More on it in Market Segment 12.7, Background screening and verification providers, in Industry Vertical 12, HR tech.)
Proving a face is real.
Generative AI can now produce the face, the voice and the moving video of a person, real or made up. These fakes, called deepfakes, are now good enough to pass a video KYC call. So liveness detection, the check that the camera is looking at a living person, has become an arms race between the people making fakes and the companies catching them. Signzy is building deepfake detection into its product. HyperVerge sells the liveness check itself.
Human or bot, customer or fraudster
Device intelligence, behavioural biometrics, bot management and account-takeover prevention
Back to the trading account from the start of this Market Segment. Verification happened once, when you opened it. Fraud happens on the ten-thousandth login. Say someone logs in to your account months later with your correct password. The password is right, so only one thing gives the fraudster away: this session does not behave like you.
- The phone is new, and it has been seen on fifty other accounts.
- The typing rhythm is wrong.
- The request came from a script, not a thumb. A script here is a bot: a program pretending to be a person.
This kind of fraud is called account takeover. (More on the employee version in Market Segment 4.2, Identity and access management (IAM).)
The companies in this sub-segment watch for these signs. They use three kinds of signal:
Device intelligencea fingerprint of the phone or browser, built from its settings and hardware, so the same device is recognised when it comes back.
Behavioural biometricshow a person types, swipes and touches the screen.
Bot detectiontelling a program apart from a person.
Checked once, then watched at every login. The document and the face are checked when the account is opened. Months later, a login with the right password still has to behave like you: companies such as Bureau, Arkose Labs, SHIELD and SecuredTouch check the device, the typing and touch rhythm, and whether a person or a script is on the other end.
The companies:
Bureauwas founded in San Francisco, and its engineering is in Bengaluru. It combines identity checks, a device fingerprint and behavioural signals into one risk score. Its buyers are banks fighting fraud.
SecuredTouchwas an Israeli behavioural-biometrics company. It learned to tell a human from a bot by how the screen was touched. It is now part of Ping Identity, and the Bengaluru engineering behind it is Ping's. (More on Ping Identity in Market Segment 4.2, Identity and access management (IAM).)
Arkose Labswith engineering in Pune, specialises in bots. It tells automated attacks apart from people, and makes each attack too expensive to run. That is what stops a sign-up page from being flooded with fake accounts.
SHIELDfrom Singapore, builds the same defence from the device up. It gives every phone and browser an identity that lasts, so a fraudster cannot simply start again.
That is how a stranger becomes a trusted customer. The document and the face are checked once, when the account is opened. After that, the device and the behaviour are checked quietly at every login.