A customer completing IDToolkit face verification on a smartphone, with the identity confirmed on screen

IDToolkit · Identity Verification

Trusted Identity at Scale.

One person. One identity. One defensible decision.

IDToolkit brings facial liveness, document assurance, duplicate identity detection, device intelligence and compliance screening into one configurable decision platform.

Explainable risk decisions

Seven weighted signals · configurable thresholds

Defensible audit evidence

Hash-chained · customer-defined retention

On-premise or hosted

Customer-controlled · Axon-managed

The short answer

A liveness check is a component. IDToolkit is the system that turns it into a decision — and defends that decision later.

Capture, liveness and matching get most of the marketing attention because they're the visible part. The harder engineering — and the part that actually determines whether an onboarding programme survives contact with real fraud — is everything around them: session security that can't be hijacked or replayed, a risk engine that weighs document, biometric and watchlist signals together instead of trusting any one of them alone, and an audit trail that can be produced, unaltered, years after the transaction closed.

IDToolkit is that system. The biometric engine underneath is independently benchmarked and swappable; the orchestration around it — the part that decides, defends and keeps running when a government database goes down — is Axon's own.

KYC / AML onboardingGovernment IDBanking & FICATelco SIM registrationWatchlist screening

Why Axon

Proven where it matters.

Operating since 2005, with more than 20 years registering and verifying identities for operators and authorities across Africa, the Middle East and Asia.

350M+

SIM cards registered

500M+

Identities registered or verified

20+

Operators & authorities served

15+

Countries deployed

20+

Years registering subscribers

Proven at global scale — the underlying 3D liveness technology processes more than one billion liveness checks annually.

An Axon field agent verifying an identity on a smartphone in a rural community

Spoof resistance

$600,000 spoof bounty.

The 3D liveness engine behind IDToolkit is backed by a standing $600,000 bounty for anyone who can defeat it — a programme run by the engine partner, and one no claimant has collected. Liveness is certified to ISO/IEC 30107-3 Levels 1 and 2, and tested beyond it against injection and deepfake vectors the standard does not cover.

Six steps, one decision

Every signal, in order.

Each step answers a different question. None of them is trusted alone — the decision comes from all six together.

01

Capture

A live selfie plus an identity document — passport, ID card or driving licence — captured through an SDK on web, iOS or Android.

02

Liveness

The capture is proven to belong to a real, present person — not a photo, mask, replayed video or injected camera feed.

03

Document

MRZ, VIZ, barcode and NFC chip data are extracted and cross-checked, and the document itself is tested for tampering.

04

Match

The live face is compared to the document photo — and, where a prior enrolment exists, directly to it.

05

Screen

The verified identity is checked against sanctions and watchlists, and against any fraud list the organisation maintains.

06

Decide

Every signal feeds one risk score. The workflow engine approves, declines or routes to manual review against a configured threshold — automatically.

A phone scanning an identity document, with the capture verified by an on-screen checkmark

What's inside

Every check a verification programme needs.

Built in, not bolted on — each capability feeds the same session, the same risk score and the same audit trail.

Liveness Detection

2D and 3D presentation-attack detection, tested against injection and deepfake vectors that older standards were never built to cover.

Learn more

Face Matching — 1:1 & 1:N

Verify against a single document or enrolment, or search the full registry to catch a duplicate identity under a different name.

Learn more

Document OCR & Anti-Tamper

MRZ, VIZ and barcode extraction, paired with digital-spoof, photo-swap and text-tamper detection on the document itself.

Learn more

NFC & ePassport Chip Reading

Cryptographic verification of ePassport and eID chip data — independent of whatever the printed photo looks like.

Learn more

Biometric Watchlists & Fraud Lists

Automatically check every applicant against known high-risk individuals. Detect repeat attempts and associated identities, then block, escalate or refer the transaction for investigation.

Due Diligence Workflows

Initial onboarding, ongoing re-screening and enhanced due diligence share the same rules, evidence and review history.

Adaptive FaceMap

Each successful re-verification strengthens the customer’s biometric template, improving accuracy and reliability every time they come back.

White Labelling & Configuration

Deploy under your own branding, with verification thresholds, workflows and approval rules configured for your market and risk requirements.

Facial matching

3D face matching, up to 375x more accurate.

Face matching is not one number. Each comparison confirms something different and is measured differently — so no single figure describes all of them.

3D:3D Re-Verification

The returning customer, against their own enrolled 3D template.

1 in 125,000,000

The highest-assurance match. Repeat authentication, account recovery, high-value transactions.

3D:2D — NFC Chip

The live person, against the portrait held on the document’s chip.

1 in 2,000,000

Strong assurance from chip-enabled passports and identity documents.

3D:2D — Printed ID Photo

The live person, against the portrait printed on the document.

1 in 500,000

Broadest coverage. Strongest where the source portrait is clear and well captured.

Log-scale comparison of false acceptance rates: 3D face matching at 8e-9, Apple Face ID at 1e-6 and the NIST number one algorithm at 3e-6

The gap is measurable

125xmore accurate in matching than Apple Face ID
375xmore accurate in matching than NIST #1 algorithm

More accurate means a lower false acceptance rate — fewer non-matches accepted as matches. Comparative values as published in the source material.

Adaptive FaceMap

Each successful re-verification strengthens the customer's biometric template. The more a customer returns, the more confident and faster their verification becomes — the control gets stronger over the life of the account rather than degrading.

Facial liveness

Five levels of attack. Most vendors answer two.

Spoofing is a ladder of increasing sophistication and cost. The top of that ladder is where real fraud now operates — and it cannot be answered by analysing an image.

  1. 01Photos, screens and replayed video
  2. 02Paper and human-worn masks
  3. 033D masks, dolls and lifelike replicas
  4. 04Synthetic data inserted into the FaceScan itself
  5. 05Recorded or deepfake video injected into the camera path

The first three attacks target the image. The last two target the capture itself.

A man holding a lifelike silicone mask of his own face up to a phone camera, with the on-screen result reading Liveness Failed
A dismantled phone with its camera ribbon connected to an interposer board and a laptop — a hardware video injection rig

When the camera feed is fake, the image can look perfect.

Software hooks and hardware adapters can replace a live camera feed with recorded or synthetic video. In a 14-day European biometrics penetration test, nearly 1,000 injection attempts produced zero successful undetected injections.

Bounty over certificate

A certificate proves yesterday. A bounty challenges tomorrow.

A certificate records how a system performed against a fixed test on one day. A standing $600,000 spoof bounty invites the world's best attackers to break it continuously — over 110,000 attacks rebuffed in two years, each analysed and any new method patched before it reaches production fraud.

ENISA's 2023 report on remote identity proofing reaches the same conclusion: 3D data is needed in the liveness assessment, and bounty programmes are currently the most effective way to test known and unknown threats. Certification is to ISO/IEC 30107-3 Levels 1 and 2, and testing goes beyond it.

1:N face search

Same face. Different ID.

A forged ID may look perfect. A real face cannot be replaced. 1:N search compares every new enrolment against your entire identity gallery, exposing when the same person attempts to register under a different identity.

Operator console showing a 1:N gallery hit — the same face found under another identity record, with match strength, candidate record and review status
Duplicate registrationsSynthetic identitiesAccount takeoversIdentity swappingRepeated use of the same face

For existing customers, every new verification is checked against the trusted record already on file. Combined with 1:N search, the system detects both a person pretending to be someone else and a person attempting to create multiple identities — while the operator keeps the policy decision, because legitimate shared, family and multi-account customers are a normal part of any base.

Blacklists

Permanently block confirmed fraudsters from re-entering your ecosystem.

Grey lists

Flag suspicious identities for enhanced review, investigation or manual approval.

1:N alerts

Surface the strongest duplicate matches before a new account is approved.

A hit is a signal, not a verdict — every duplicate is surfaced for review with the biometric evidence attached.

Sanctions, PEP & adverse media

Screening that finds the name you weren't given.

A verified identity is not automatically an acceptable one. Every applicant is screened against sanctions, politically exposed persons, adverse media and configured fraud lists — checked at onboarding, re-screened as lists change, and maintained for the life of the account.

215+

Sanction regimes

3,500+

Official watchlists

50K+

Adverse media sources

2.6M+

PEP profiles

80+

Languages

100K+

Data sources

Beyond sanctions and PEP lists: PEP classification to Level 4, insolvent entities, historical biographies, shadow diplomats and high-risk businesses.

Name matching that survives real names

Most screening failures are matching failures, not database gaps — the right person is there under a spelling the system did not recognise. NLP and contextual matching, transliteration libraries for native-script and romanised variants, and phonetic algorithms catch aliases and misspellings that exact-string comparison misses.

The networks behind the named individual

Sanctioned and politically exposed people rarely transact under their own name. Relatives, close associates, financial-crime facilitators and shell-company operators are held as first-class records and linked by AI entity resolution — including the local-level profiles global databases routinely miss.

Hosted in country.

The screening database can be deployed in country, inside your own environment. No customer data leaves the jurisdiction to complete a check, and screening keeps working when cross-border connectivity does not. A cloud-only screening service cannot offer that.

An agent at a counter verifying a customer, with AML and PEP screening returning clear and the document portrait flagged for review

Integration

Fits the systems you already operate.

IDToolkit can sit behind an existing onboarding journey or provide the complete capture flow, while standards-based interfaces keep identity, compliance and case-management systems connected.

REST APIs

Initiate a workflow, receive structured outcomes and retrieve the evidence your downstream systems are authorised to use.

Web, iOS & Android SDKs

Embed capture and verification into customer-facing apps, browsers, teller journeys and agent tools.

OAuth 2.0 & OpenID Connect

Use standards-based authentication, delegated access and time-limited tokens across integrated applications.

Provider-Agnostic Connectors

Connect national identity databases, AML sources and biometric engines without hardwiring the core workflow to one provider.

If an upstream identity source is unavailable, the workflow can queue the request and resubmit it when connectivity returns, preserving the transaction and its audit context.

Multi-tenancy

One deployment. Many tenants.

Group operating companies, MVNOs, channel partners and resellers can each run as an isolated tenant on the same deployment — with their own branding, journeys, thresholds and enrolled gallery — while you keep central oversight of the whole estate.

Isolated by design

One tenant’s enrolled gallery and 1:N watchlist are never visible to, or matched against, another tenant’s. Data, users and audit trail stay separate.

Branded per tenant

Each tenant’s SDK instance carries its own logo, colours and OEM presentation — configured, not rebuilt, for every brand added.

Configured per tenant

Journey steps, document rules, approval thresholds, workflow rules and user access are set independently for each tenant.

Metered per tenant

Usage is tracked by tenant, channel and service, so volume can be allocated internally or billed on to a partner.

Who runs as a tenant

  • Group operating companies in other markets
  • MVNOs hosted on your network
  • Mobile money and fintech subsidiaries
  • Dealers, distributors and channel partners
  • Resellers on-selling verification as a service
  • Separate brands and sub-brands in one market

The second tenant costs less than the first.

Multi-tenancy, sub-OEM branding and per-tenant usage tracking are platform capabilities, not a bespoke build. Because tenants share the underlying infrastructure and support model, a second or third operator is materially cheaper and faster to bring live than the first — which is what makes on-selling the SDK commercially workable, not just technically possible.

Tenants share the platform. They do not share data — galleries, watchlists, users and audit trails stay isolated.

The differentiator

Seven signals. One score.

Any one of these checks can be individually defeated. A composite score across all of them, at a threshold you control, is what actually holds up.

Bot & Network

Inbound traffic is filtered for automated attacks and scripted fraud before it ever reaches biometric capture.

Liveness

Presentation-attack detection scores the capture itself, not just the eventual match.

Document Authenticity

OCR, template matching and tamper checks confirm the document is original.

Face-to-Document Match

The live face is compared to the document photo to establish identity linkage.

Biometric Watchlists & Fraud Lists

Screened against sanctions, PEP and biometric fraud lists — repeat attempts and associated identities flagged, not just individual hits.

Address Verification

Proof-of-address documents cross-checked against trusted sources where available.

1:N Biometric Search

The identity is searched against every prior enrolment to catch a duplicate registered under a different name.

Approve

All required checks clear the configured threshold.

Review

Borderline or conflicting signals route with their evidence.

Decline

Hard failures and high-risk results stop the transaction.

One composite, weighted score.

Every signal above feeds a single risk score, and the thresholds are configured — per transaction type, customer profile or channel — not hardcoded. A transaction that clears the bar is approved automatically. One that doesn't is declined or routed for manual review, with the full evidence trail preserved either way.

Channels & deployment

One platform. Every verification journey.

Remote, assisted, in-branch or high-risk — every journey runs on the same risk engine and the same audit trail, in your cloud or ours.

Remote Onboarding

Self-guided verification completed on any device, in minutes — no app install required.

Assisted & Field Enrolment

Agent- or teller-assisted enrolment for higher-touch onboarding and challenging connectivity environments.

Branch & Retail

In-branch and point-of-sale verification, running the same risk engine as every other journey.

Call-Centre Verification

Remote identity verification over a supported call flow, tied to the same audit trail.

High-Risk Transaction Approval

Step-up verification triggered at the moment of highest risk, not only at onboarding.

Ongoing Re-Verification

A returning customer proves themselves against their own enrolled biometric — no repeat document capture.

Web, mobile and API integration, all powered by the same verification and risk engine.

Your brand. Your journey. Your rules.

Deploy IDToolkit under your own branding, with verification thresholds, workflows and approval rules configured for your market and risk requirements. Your customers see your product — not ours.

An IDToolkit verification flow shown white-labelled across five phone screens with a customer’s own branding

Choose an Axon-hosted solution or deploy IDToolkit in a private cloud, inside your firewall or fully on-premise. The architecture adapts to your security, sovereignty and operating requirements.

Security & compliance

Built to be defended, not just to work.

Every claim below is something an auditor or a regulator can actually verify — not a badge on a slide.

Federated Access Control

OAuth 2.0 and OpenID Connect provide delegated access, time-limited tokens and interoperable authentication across connected systems.

Replay & Injection Protection

Encrypted capture packages and server-side controls reject reused, altered or injected biometric submissions.

Immutable Audit Trail

Every match, threshold change and decision is hash-chained and written to WORM-compliant storage, with retention configured to the customer’s policy and regulatory needs.

Encryption Everywhere

TLS 1.3 in transit, AES-256 at rest, with encryption keys rotated on a fixed schedule rather than left standing indefinitely.

Consent-Bound Data

Biometric templates are cached separately from customer-identifying data, under explicit, digitally signed consent, with defined retention and deletion.

Regulatory Alignment

Built to POPIA, GDPR and FICA principles — data minimisation, purpose limitation, and the right to erasure.

Operations

Built to stay up, and to say so.

Verification infrastructure that goes down during an onboarding push is worse than no infrastructure at all — this is how it doesn't.

Active-Active High Availability

Every layer runs across multiple nodes. A failed node is routed around automatically, with no manual intervention.

Resilient Recovery

Redundant services and recovery procedures preserve continuity without depending on a single application node or upstream system.

Continuous Monitoring

Axon’s own monitoring platform tracks system-critical thresholds and alerts named support staff before a warning becomes an outage.

Graceful Degradation

If a national identity database is temporarily unreachable, transactions are queued and automatically resubmitted the moment connectivity returns.

Start with the volume

Let us map the risk engine to your journeys.

We'll work from expected transaction volume, regulatory context and existing infrastructure, then design the thresholds, journeys and hosting model around it.

Common questions

IDToolkit, without the fog.

Clear answers for product, compliance, fraud and operations teams.

What is IDToolkit?+

IDToolkit is Axon’s identity verification platform — liveness detection, document verification, face matching, watchlist screening and a configurable risk-scoring engine, combined into one auditable decision. It is built for remote onboarding, government ID checks and in-person enrolment alike.

Is IDToolkit just a face-matching product?+

No. Face matching and liveness are one input among several. IDToolkit is the orchestration around them — secure session handling, document verification, watchlist screening, a composite risk score, and the audit trail behind every decision. A vendor can resell a liveness SDK; the system that turns a check into a defensible decision is the actual product.

Which biometric engine does IDToolkit use?+

Liveness and face matching are powered by an independently benchmarked biometric engine partner, tested to ISO/IEC 30107-3 Levels 1 and 2 and beyond it against injection and deepfake attack vectors the standard does not cover. Axon owns and operates everything else in the pipeline: session security, orchestration, the risk engine, monitoring and the audit trail.

Can IDToolkit integrate with a national identity database?+

Yes. Where a national database is available, verification checks against it directly. If that database is temporarily unreachable, transactions are queued and automatically resubmitted once connectivity returns, so onboarding does not stop while a government system is down.

Is IDToolkit an SDK or a hosted service?+

It is an SDK you embed in your own apps and web journeys — not a third-party app your customer is handed off to. Verification runs inside your experience, under your brand, on your rules. The SDK is available for Android and iOS, as a responsive browser journey needing no app install, and as a REST API for server-to-server integration into CRM, BSS and channel systems. One verification engine sits behind all four, so the journey, thresholds and audit trail are identical whichever surface the customer uses.

Can IDToolkit be sub-tenanted, or resold to other companies?+

Yes. IDToolkit is multi-tenant: group operating companies, MVNOs, mobile money subsidiaries, channel partners and resellers can each run as an isolated tenant on the same deployment, with their own branding, journeys, thresholds and enrolled gallery, while the parent organisation keeps central oversight of the whole estate. Usage is tracked per tenant, channel and service, so volume can be allocated internally or billed on to a partner.

Do tenants share biometric data with each other?+

No. Tenants share the platform, not the data. One tenant’s enrolled gallery and 1:N watchlist are never visible to, or matched against, another tenant’s, and users, audit trails and retention policies stay separate per tenant.

How much does it cost to add a second tenant or market?+

Materially less than the first. Multi-tenancy, sub-OEM branding and per-tenant usage tracking are platform capabilities rather than a bespoke build, and tenants share the underlying infrastructure and support model — so a second or third operator is cheaper and faster to bring live than the first.

Is it hosted in the cloud or on-premise?+

Both. IDToolkit is available as an Axon-hosted solution or can be deployed in a private cloud, inside your firewall or fully on-premise. The deployment model is selected to match your security, sovereignty and operating requirements.

How does the risk engine decide whether to approve a transaction?+

Liveness, document authenticity, face match, watchlist screening, address verification and biometric search each feed a single weighted score. Thresholds are configured per transaction type, customer profile or channel rather than hardcoded, so a transaction that clears the bar is approved automatically and one that does not is declined or routed for manual review.

How does IDToolkit integrate with existing banking and government systems?+

IDToolkit exposes REST APIs and SDKs for web, iOS and Android, with OAuth 2.0 and OpenID Connect for standards-based access. National identity databases, AML sources, biometric engines and downstream onboarding systems connect through provider-agnostic adapters rather than being hardwired into one monolithic flow.

Does IDToolkit support ongoing and enhanced due diligence?+

Yes. The same workflow used at onboarding can re-screen an existing customer against updated sanctions, PEP, fraud and identity signals. Higher-risk cases can be routed into an enhanced due-diligence path with additional evidence and a complete review history.

What stops someone registering twice under different names?+

Every new registration is searched against the full enrolled population — a 1:N search, not just a 1:1 check against the document presented — so a person who already has an identity on file is caught regardless of the name or document used the second time.

How accurate is 3D face matching?+

It depends which comparison is being made, and the figures should never be used interchangeably. A 3D-to-3D re-verification — a returning customer matched against their own enrolled template — operates at a false acceptance rate of 1 in 125,000,000. Matching a live 3D face to the portrait held on a document’s NFC chip is 1 in 2,000,000. Matching to the portrait printed on a document is 1 in 500,000, and is strongest where the printed photo is clear and well captured.

How does 3D face matching compare to Apple Face ID?+

On the published comparative figures, 3D face matching operates at a false acceptance rate of 0.000000008, against 0.000001 for Apple Face ID and 0.000003 for the top-ranked NIST algorithm. That makes it approximately 125 times more accurate than Apple Face ID and 375 times more accurate than the NIST #1 algorithm. Lower false acceptance is better: it means fewer non-matches wrongly accepted as matches.

What is a video injection attack, and how is it prevented?+

A video injection attack replaces the live camera feed with recorded or synthetic video, so the system analyses footage that never came from the camera. Software injection uses breakpoints in the device SDK or a virtual camera; hardware injection splices an adapter onto the device’s camera port. Because the resulting image can look perfect, image analysis alone cannot catch it — protection has to sit around the capture path. In a 14-day European biometrics penetration test, nearly 1,000 injection attempts produced zero successful undetected injections.

What are the five levels of liveness attack?+

Level 1 is photos, screens and replayed video. Level 2 is paper and human-worn masks. Level 3 is 3D masks, dolls and lifelike replicas costing up to about $3,000. Level 4 is decrypting and editing the 3D FaceScan itself so it carries synthetic data never collected in the session. Level 5 is taking over the camera feed and injecting recorded or deepfake video. The first three target the image; the last two target the capture, and cannot be answered by a 2D-only or certificate-only approach.

What does the $600,000 spoof bounty actually prove?+

It is a standing programme run by Axon’s 3D liveness engine partner, not a payout Axon issues, and it has not been collected. Its value is that it tests continuously rather than once: over 110,000 attacks have been rebuffed in two years, with each analysed and any new method patched before it reaches production fraud. ENISA’s 2023 report on remote identity proofing reaches the same conclusion — that 3D data is needed in liveness assessment and bounty programmes are currently the most effective way to test known and unknown threats. A certificate records how a system performed on one day; a bounty shows it is still standing.

What sanctions, PEP and adverse media sources are screened?+

Screening covers 215+ sanction regimes, 3,500+ official watchlists, 50,000+ adverse media sources, 2.6 million+ PEP profiles across 80+ languages, drawn from 100,000+ data sources. It extends beyond sanctions and PEP lists to PEP classification to Level 4, insolvent entities, historical biographies, shadow diplomats and high-risk businesses, along with relatives, close associates and financial-crime facilitators linked by entity resolution.

Can the AML screening database be hosted in our own country?+

Yes. The screening database can be deployed in country, inside the customer’s own environment, so no customer data leaves the jurisdiction to complete a check and screening keeps working when cross-border connectivity does not. This matters where a central bank or regulator requires customer data and check records to remain within national borders — a requirement a cloud-only screening service cannot meet.

Can IDToolkit be white-labelled under our own brand?+

Yes, and it is productised rather than a bespoke build. The journey deploys under your own logo, colours and language, with verification thresholds, onboarding and approval workflows, country-specific document and policy rules, review paths and audit trail all configured for your market and risk appetite.

How long is verification data retained?+

Retention is customer-defined and consent-bound. Audit evidence and underlying biometric data can follow separate retention and deletion policies, configured to the customer’s operational, legal and regulatory requirements.