Investigation

Who Actually Checks Your ID: The Vendors Behind Identity Verification

When an exchange rejects your passport, the exchange almost certainly never looked at it. A third party company did. Knowing which one changes what you should do next, and you can usually work it out in under a minute.

Last reviewed 30 July 2026 · by the KYC Rejected team

Key facts

  • Almost no platform builds identity verification itself. They license it from specialist vendors.
  • Coinbase publicly names its verification vendors, listing Onfido, Au10tix, Jumio, Refinitiv, Shufti, Persona, Prove and Sardine on a dedicated disclosure page.
  • One platform can use several vendors at once, routing users by country, product and risk score.
  • You can usually identify the vendor yourself from the redirect domain, the SDK branding, or your browser's network tab.
  • This matters because a rejection produced by a document reader is a different problem from a rejection produced by a fraud or sanctions screen, and only one of them is fixed with a better photograph.

The thing nobody tells you about verification

People reason about identity verification as though the platform is the actor. Binance rejected me. Revolut does not like my passport. That framing feels natural and it is almost always wrong. In the overwhelming majority of cases the platform has handed the entire assessment to a specialist company, received a verdict, and passed that verdict on to you with the detail stripped out.

This is not a secret so much as an unadvertised fact. Building document authentication and biometric matching is genuinely hard. It needs a library of document templates from every issuing authority in the world, face recognition models, liveness detection that resists printed masks and replayed video, and continuous updating as documents get redesigned and fraud techniques evolve. Almost nobody builds that to service their own signup form. They buy it.

Once you see the architecture, a lot of otherwise baffling experiences make sense. It explains why the same document passes one service and fails another. It explains why your friend in a different country had a completely different flow on the same app. And it explains why support staff so often cannot tell you what went wrong, because the decision was not made in their building.

What is actually disclosed

Most platforms do not publish which vendor they use. Some do, usually because privacy law obliges them to tell you who processes your personal data, and biometric data in particular carries heightened obligations in several jurisdictions.

Coinbase is the clearest public example. It maintains a dedicated page listing its third party identity verification service vendors, naming Onfido, Au10tix, Jumio, Refinitiv, Shufti, Persona, Prove and Sardine, and pointing to each vendor's own privacy policy for how they handle the data. That single page tells you something important beyond the names themselves: a large platform does not use one vendor, it uses a panel of them.

This is worth dwelling on, because it kills a comforting assumption. There is no single Coinbase verification standard you can learn and satisfy. Which engine assesses you may depend on your country, the product you are signing up for, and what the risk model already thinks about your session. Two people submitting the same day can be assessed by two different systems with different tolerances.

The companies doing the work

A relatively small group of vendors dominates this market. Here is who they are and what each is generally known for, so that recognising a name tells you something useful.

VendorGenerally known for
Onfido
now part of Entrust
Document authentication paired with facial biometrics and liveness. Very widely deployed across fintech and crypto.
JumioOne of the longest established players. Broad document coverage and an emphasis on automated decisioning at scale.
SumsubFull compliance suite spanning identity, business verification and transaction monitoring. Common in crypto.
VeriffVideo and session based verification with strong emphasis on fraud signals during capture.
Au10tixHigh throughput document forensics, with roots in automated authentication for large institutions.
PersonaConfigurable verification workflows, letting a platform assemble its own sequence of checks.
ShuftiDocument and biometric verification with wide international document coverage.
RefinitivScreening rather than document capture. Sanctions, politically exposed persons and adverse media data.
ProvePhone number and device based identity signals rather than document capture.
SardineBehavioural biometrics and fraud detection, assessing how a session behaves rather than what a document looks like.

Notice that these are not all doing the same job. Onfido, Jumio, Sumsub, Veriff, Au10tix, Persona and Shufti are broadly in the business of looking at a document and a face. Refinitiv is in the business of checking your name against sanctions and adverse media lists. Prove works from phone and device signals. Sardine watches session behaviour. A platform can run several of these in sequence, and a refusal from any one of them ends the process.

How to find out which one is checking you

You do not need insider access. Four methods work, in rough order of effort.

1. Watch the address bar

Many web based flows hand you off to the vendor's own domain for the capture step, then return you to the platform afterwards. If the URL changes to something you do not recognise when the camera opens, that is very often the vendor. Read the domain before you start uploading.

2. Read the fine print in the capture screen

Embedded software development kits frequently carry a small attribution, a logo in the corner, a powered by line at the bottom of the modal, or a privacy link that points at the vendor rather than the platform. It is easy to miss because you are concentrating on holding your passport steady. Look before you tap start.

3. Open the network tab

On a desktop browser, press F12 to open developer tools, select the Network tab, then begin the verification flow. You will see requests going out to third party domains. The vendor is usually obvious from the hostname.

This is entirely passive observation of traffic your own browser is making. You are not interfering with the check, and you should not attempt to. The point is diagnosis, not manipulation.

4. Read the privacy policy and the emails

Look for a sub processor list, a page about third party verification vendors, or a biometric data notice. Search the policy for the vendor names in the table above. Verification related emails sometimes come from or reference the vendor's infrastructure too, which is another giveaway.

Why it changes what you do next

Here is the payoff, and it is the reason this page exists. Rejections come from different stages, and the stage determines whether you can do anything about it.

If the refusal came from the document and biometric stage, it is a capture problem and it is genuinely fixable. Better light, no flash, all four corners in frame, a slower liveness movement. This is the category most people are in, and it is the category our photo standard guide is written for.

If the refusal came from a screening provider, no photograph will change it. Screening compares your name, date of birth and nationality against sanctions lists, politically exposed persons databases and adverse media. Retaking a selfie against that check is like polishing your shoes to pass a spelling test. The route forward is the platform's appeal or review process, not the camera.

If the refusal came from a behavioural or device layer, the trigger might be a VPN, an unusual device fingerprint, a shared IP address, or a session that looked automated. Again, the document was never the issue. Turning off a VPN and completing the flow on a normal connection from your usual device resolves a surprising number of these.

The frustrating part is that the message you receive will look identical in all three cases, which is largely deliberate. Regulators restrict what firms may disclose about why an application was flagged, because explaining the trigger to a genuine bad actor tells them exactly what to change. That constraint is real, and it means the burden of working out the category lands on you.

Reading the flow for clues

Even without naming the vendor, the shape of the process tells you where you failed.

  • Rejected within seconds, immediately after the upload, almost always means an automated document check. Something measurable failed: sharpness, glare across a field, a missing corner, an unreadable machine readable zone.
  • Rejected after you completed the selfie but before any waiting period usually points at the biometric or liveness stage.
  • Accepted, then rejected hours or days later strongly suggests a screening or manual review stage. The images were fine. Something in the data was not.
  • Asked for additional documents such as proof of address or source of funds means you have crossed into enhanced due diligence. This is not a rejection at all, it is an escalation, and it is satisfied with paperwork.
  • Never resolved, stuck on pending, usually means a human queue. Submitting again can reset your position on some platforms, so waiting is often faster.
Stop guessing what went wrong A human specialist corrects the document for you and sends it back ready to submit, usually in under 10 minutes. $1.99, money back if it is not approved. Get my fix

What these companies hold about you

It is reasonable to want to know. When you complete a verification you are typically handing over images of a government document, one or more images or a short video of your face, a biometric template derived from that face, and metadata about the device and session.

Retention is governed by the vendor's own policy and by the platform's regulatory obligations, which frequently require records to be kept for years after an account closes. Coinbase's disclosure, for instance, points users to each vendor's own notice for how long that vendor keeps the data, which is a useful reminder that two different retention regimes can apply to the same submission.

If you are in a jurisdiction with data access rights, you can usually request a copy of what is held and, in some cases, deletion once the retention obligation lapses. The request generally goes to the platform, which is the controller, rather than directly to the vendor. Our security page covers how we handle documents on this site, which is to say we do not store them.

Appealing, and who to actually talk to

When people decide to escalate, they often aim at the wrong target. Contacting the vendor directly almost never works, and the reason is structural rather than unhelpful. Under most data protection regimes the platform is the controller, meaning it decides why and how your data is processed, while the vendor is a processor acting on the platform's instructions. Your rights, your complaint and your appeal all run through the controller.

So the appeal goes to the platform's support channel, and it is worth writing it well because a human will read it. Keep it short and factual. State that verification was declined, give the date and any reference number, confirm the document type and that it is currently valid, and state plainly that your profile details match the document exactly. Ask specifically whether the account can be routed to manual review. Do not speculate about which check failed, and do not send an emotional message, because neither helps the person reading it and both slow the queue.

One right that is frequently overlooked is worth knowing about. Several jurisdictions give individuals the right not to be subject to a decision based solely on automated processing where that decision produces legal or similarly significant effects, along with a right to obtain human intervention. Being refused access to a financial account can fall into that territory. Asking, politely and in writing, for the decision to be reviewed by a person is a legitimate request rather than an unusual one.

Our walkthrough for accounts that have already been restricted is at account locked after KYC, and it includes a template you can adapt.

A note on what not to do

Understanding the machinery is useful for diagnosis. It is not a route to defeating it. Editing a document, generating a synthetic face, or otherwise attempting to trick a verification system is identity fraud, and these vendors exist specifically to detect exactly those attempts. The realistic outcome is a permanent ban and, potentially, a referral. Everything on this site is about getting a genuine document through a system that measures things badly lit photographs cannot satisfy. That is a different objective entirely, and it is the one worth pursuing.

What actually happens between upload and verdict

The gap between pressing submit and receiving an answer feels like a black box, and that opacity is a large part of why rejections are so frustrating. The pipeline is not mysterious though, and knowing its stages helps you locate your own failure.

Stage one is classification. The system works out what it is looking at. Which country issued this, and which document type is it. It does that by matching the layout against a template library covering issuing authorities worldwide. If the document is very newly redesigned, or unusual, this stage alone can fail and you will get a generic error that tells you nothing about the real cause.

Stage two is image quality. Sharpness, contrast, exposure and specular highlight coverage get measured and compared against thresholds. This is where the majority of consumer rejections happen, and it is the only stage where retaking the photograph is the correct response.

Stage three is geometry and extraction. The four corners are located, perspective is corrected, and the printed fields are read by optical character recognition. If the document carries a machine readable zone, that gets parsed too and its check digits validated, giving a second independent reading of your details.

Stage four is authenticity. The system looks for evidence that the thing photographed was a genuine physical document rather than a screen, a printout, or an edited image. Font consistency, expected security features, and the behaviour of the surface under light all feed into this.

Stage five is biometric comparison. Your selfie is compared geometrically against the portrait on the document, and a liveness assessment decides whether a real person was present.

Stage six is data cross checking. The extracted fields are compared against what you typed into your profile. Character level mismatches surface here.

Stage seven is screening and risk. Your identity is checked against sanctions, politically exposed persons and adverse media data, and behavioural or device signals are folded in. This stage frequently runs after the earlier ones have already succeeded, which is exactly why some people are accepted and then rejected later.

Why this market consolidated, and what it means for you

A decade ago identity verification was fragmented, with many small regional providers each covering a handful of document types. That has changed substantially. Acquisitions have folded well known names into larger groups, Onfido becoming part of Entrust being one prominent example, and the surviving vendors have expanded from single purpose document readers into broader compliance platforms covering screening, monitoring and business verification alongside identity.

There are two practical consequences for anyone trying to get verified. The first is that a smaller number of engines now sit behind a very large number of consumer services. If a particular vendor's model dislikes something about how you photograph your document, you may encounter that same judgement across several apparently unrelated platforms. People experiencing a run of rejections across different services are often, without knowing it, meeting the same engine repeatedly.

The second is that the assessment has broadened. Verification used to mean looking at a document. It now routinely means looking at a document, a face, a device, a network path, and a behavioural pattern, and combining those into a single score. That is why advice focused purely on photography, while necessary, is no longer sufficient. A perfect photograph submitted through a VPN on a freshly wiped device from a country your profile does not mention is still a risk signal.

The correct response to that is not to try to game the score. It is to remove unnecessary noise. Complete verification on the device and connection you normally use, with your real address in your profile, in one uninterrupted sitting, with a well captured document. Every avoidable oddity you eliminate is one fewer reason for the model to hesitate.

Frequently asked questions

Which identity verification provider does Coinbase use?

Coinbase publishes a dedicated page naming its third party identity verification vendors, which lists Onfido, Au10tix, Jumio, Refinitiv, Shufti, Persona, Prove and Sardine. It uses a panel rather than a single provider, and which one assesses a given user can depend on country, product and risk. The page also links to each vendor's own privacy policy.

How can I tell which company is verifying me?

Watch whether the address bar changes to an unfamiliar domain when the capture step begins, look for a powered by line or logo inside the capture screen, open your browser's network tab with F12 and start the flow to see which third party hosts receive requests, or search the platform's privacy policy for a sub processor or verification vendor list.

Why does the same passport pass on one platform and fail on another?

Because different vendors, and sometimes different vendors within the same platform, are assessing it with different models and different thresholds. Add to that the fact that each platform sets its own risk tolerance above the regulatory minimum, and identical input producing different outcomes stops being mysterious.

My documents were accepted and then I was rejected days later. Why?

That pattern usually means the images passed the automated document and biometric stage, and the refusal came from a later screening or manual review step. Screening compares your name, date of birth and nationality against sanctions, politically exposed persons and adverse media data. No amount of retaking photographs affects it. The path forward is the platform's review or appeal process.

Could a VPN be causing my rejection?

It can. Behavioural and device layers assess the session as well as the document, and a VPN, an unusual device fingerprint, a shared address or automation like signals can all raise risk. Completing verification on your normal connection and usual device, with the VPN switched off, removes a variable that costs nothing to remove.

Can I ask the vendor directly what went wrong?

Generally not. Your relationship is with the platform, which acts as the data controller, and the vendor processes on its behalf. Requests about the decision, and data access requests, normally go to the platform. Firms are also often restricted in how much they may disclose about why an application was flagged, which is why the answers you receive tend to be non specific.

Rule out the capture problem first

Most rejections are still document quality failures, and those are the ones you can actually fix. Our free checker measures the same properties an automated verifier does, before you spend another attempt.

Check my document free
Out of attempts, or out of patience? Skip the trial and error. A real specialist rebalances the lighting, lifts the glare and squares the edges, then emails it back. Human specialist, under 10 min, $1.99. Get my fix