Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
North America

Identity verification
built for United States Flag of United States

AAMVA-aggregated driver licences, U.S. passports, Green Cards, OFAC SDN on every AML, $0.33 full KYC, 500 free every month, no state surcharge.

Backed by
Y CombinatorRobinhood Ventures
Firecrawl
Slash
Crnogorski Telekom
UCSF Neuroscape
Bit2Me
Shiply

Trusted by 2,000+ organizations worldwide.

Country brief

How identity verification works in United States.

The fraud surface and the frameworks an engineering or compliance lead needs before scoping an integration.
Fraud landscape
Three pressures shape U.S. identity fraud: synthetic-ID attacks fueled by leaked SSNs targeting neobanks, crypto on-ramps, and BNPL onboarding; AAMVA driver-licence forgery across all 50 state templates; and AI-generated deepfake injection on remote-onboarding flows for the licensed iGaming markets (NJ, PA, NY, MI, IL). Didit scores 200+ real-time fraud signals on every session, face morph, replay, injection, document tampering, device intelligence, IP geolocation.
Compliance frameworks
  • Bank Secrecy Act (BSA)
  • FinCEN CDD Final Rule
  • OFAC SDN screening
  • USA PATRIOT Act § 326
  • Corporate Transparency Act
  • CCPA / CPRA + state privacy laws
Regulators

Who supervises identity verification in United States.

These are the supervisors a United States verification flow has to answer to. One Didit hosted flow + one audit log covers every one of them, no separate integration per agency.
  • FinCEN

    Financial Crimes Enforcement Network, Treasury bureau that administers the Bank Secrecy Act, the Customer Due Diligence Rule, and the Corporate Transparency Act beneficial-ownership regime.

  • OFAC

    Office of Foreign Assets Control, issues the Specially Designated Nationals (SDN) sanctions list screened on every Didit AML check, plus consolidated program lists.

  • CSBS / State MTRs

    Conference of State Bank Supervisors, coordinates ~60 state Money Transmitter Licences (MTLs) supervised through the Nationwide Multistate Licensing System (NMLS).

  • SEC + FINRA

    Securities and Exchange Commission and Financial Industry Regulatory Authority, securities + broker-dealer supervision under the Securities Exchange Act and FINRA Rule 3310 AML programs.

  • CFPB

    Consumer Financial Protection Bureau, supervises consumer financial products under the Consumer Financial Protection Act.

  • FTC + State AGs

    Federal Trade Commission and state Attorneys General, enforce the Red Flags Rule, CCPA/CPRA in California, and emerging state privacy regimes (VCDPA, CPA, CTDPA).

Verification flow · One API

Four modules. One verification.

ID, biometric, AML, and a United States database cross-check, composed on one workflow, billed per success, returned in one report.
01 · ID

Capture and read the ID.

Captured on any phone, auto-classified, OCR-parsed, and template-verified.

  • Works for every primary U.S. credential, state Driving Licence and State ID (PDF417 barcode decoded, AAMVA-aggregated, Real ID Act flagged), U.S. Passport (NFC chip read on e-Passport), Passport Card, Permanent Resident Card, and Employment Authorization Document.
  • Returns the name, document number, date of birth, address, and expiry.
Read the docs
Stage 01Capture and read the ID
  • Driving Licence, all 50 states + DC + 5 territories
  • U.S. Passport · Passport Card
  • Green Card · Employment Authorization Document
02 · Biometric

Match the face. Prove it's a real person..

Selfie confirmed live and matched against the ID portrait.

  • Duplicate check: 1:N face search across existing users. Free.
  • Active liveness ($0.15) for elevated-risk flows, user turns or blinks.
Read the docs
Stage 02Match the face. Prove it's a real person.
  • Selfie on any phone or laptop camera
  • Mobile-handoff QR when the user starts on desktop
03 · AML

Screen for sanctions, PEPs, and adverse media.

Didit screens the user's name against the global pool of 1,300+ sanctions, Politically Exposed Persons (PEP), and adverse-media lists, plus every U.S. federal regulatory watchlist:

  • Office of Foreign Assets Control (OFAC), SDN and Blocked Persons List.
  • Office of Foreign Assets Control (OFAC), Non-SDN Consolidated Sanctions List.
  • FinCEN, Money Laundering Concerns List.
  • Bureau of Industry and Security (BIS), Denied Persons List, Entity List, Unverified List, and Military End User List.
  • Department of State, Nonproliferation Sanctions, Cuba Restricted List, and Terrorist Exclusion List.
  • Department of Homeland Security (DHS), UFLPA Entity List.
  • International Trade Administration (ITA), Consolidated Screening List (CSL).
  • Department of Justice, CyberCrime and enforcement actions.

Severity-scored. Ongoing monitoring ($0.07/user/yr) re-checks daily and fires a webhook on new hits.

Read the docs
Stage 03Screen for sanctions, PEPs, and adverse media

Screen for sanctions, PEPs, and adverse media , see the docs for the full module surface.

04 · Registry

Cross-check against U.S. credit-header and government records.

After the ID is captured, Didit cross-checks the name + date of birth + address against seven authoritative U.S. datasets so you know the person actually exists at the address they claimed.

  • `usa_states_death_check` ($0.05), Social Security Death Master File, the cheapest fraud gate to run first.
  • `usa_states_credit_bureau` ($0.11, ~90% coverage), aggregated credit-header data; name + DOB + address + optional SSN matching.
  • `usa_states_financial_services` ($0.19, ~85% coverage), aggregated government + public + background records tuned for financial-services CDD.
  • `usa_states_residential` ($0.54, ~90% coverage), full address-verification rigor for high-risk flows.
  • `usa_states_phone` ($0.30) and `usa_states_phone_2` ($0.52, >90% coverage), telco-billing and MNO phone matching.
  • `usa_states_consumer` ($0.08), lead-generation consumer database for supplementary coverage.

All seven services are documented at docs.didit.me/api-reference/database-validation/united-states/, pay-per-success, no contracts.

Read the docs
Stage 04Cross-check against U.S. credit-header and government records

Cross-check against U.S. credit-header and government records , see the docs for the full module surface.

Documents covered

Every United States document Didit accepts.

One row per accepted credential, flag, document name, document type. Live from the Didit Business Console.
Authoritative datasets

Civil-registry and AML coverage for United States.

One card per dataset Didit cross-checks against, civil registries on the Database Validation API plus the global AML watchlist pool. Each card links to the technical docs.
Compliant by design

Open a new country in one click. We do the hard work.

We open the local subsidiaries, secure the licenses, run the penetration tests, earn the certifications, and align with every new regulation. To ship verifications in a new country, flip a toggle. 220+ countries live, audited and pen-tested every quarter, the only identity provider an EU member-state government has formally called safer than in-person verification.
Read the security & compliance dossier
EU financial sandbox
Tesoro · SEPBLAC · BdE
ISO/IEC 27001
Information security · 2026
SOC 2 · Type I
AICPA · 2026
iBeta Level 1 PAD
NIST / NIAP · 2026
GDPR
EU 2016/679
DORA
EU 2022/2554
MiCA
EU 2023/1114
AMLD6 · eIDAS 2.0
EU-aligned by design
FAQ

Common questions about United States.

What does Didit ship?

Didit is the infrastructure layer for identity and fraud. One Application Programming Interface (API), 25+ composable modules across four product lines:

  • User Verification (KYC, know your customer), Identity Document Verification, liveness, face match, Anti-Money Laundering (AML) screening, Internet Protocol (IP) analysis. $0.33 per full bundle.
  • Business Verification (KYB, know your business), registry, Ultimate Beneficial Owner (UBO), officers, entity AML, plus a linked KYC session per UBO.
  • Transaction Monitoring, real-time rule engine, case management, Suspicious Activity Report (SAR) workflow.
  • Wallet Screening (KYT, know your transaction), on-chain wallet risk at $0.15 per check, or bring your own screening provider and run it inside Didit.

Compose any module into a workflow with the visual no-code builder, ship in 5 minutes, 500 verifications free every month, forever.

How is Didit different from a single-product Know Your Customer (KYC) vendor?

Most identity vendors sell one slice, a KYC check, an Anti-Money Laundering (AML) list, a wallet screen. Didit ships the infrastructure underneath all of them, and the gap shows up on six axes:

  • Pricing. Public price on every module, $0.33 for a full KYC, 500 verifications free every month, no minimums, no contracts. Single-product vendors hide six-figure minimums behind a sales call.
  • Access. Sandbox in one click, self-serve from day one, production keys on signup. Single-product vendors gate the sandbox behind a contract, months to evaluate.
  • Developer experience. Public docs, a Model Context Protocol (MCP) server for Claude Code and Cursor, and native Software Development Kits (SDKs) for Web, iOS, Android, React Native, and Flutter. Integrate in 5 minutes with an AI agent or in a working afternoon by hand.
  • User experience. Highest pass rates in the market, sub-2-second end-to-end inference, country-specialised capture flows, 48+ languages out of the box.
  • Flexibility. One /v3/ Application Programming Interface (API) composes 25+ modules across KYC, Know Your Business (KYB), Transaction Monitoring, and Wallet Screening (KYT, know your transaction). A KYB session spawns a linked KYC for every Ultimate Beneficial Owner (UBO); a flagged transaction spawns a step-up KYC remediation, same session, same webhook contract, same audit trail. Single-product vendors sell one shape of KYC and stop there.
  • AI-era fraud. 200+ real-time fraud signals scored on every session, deepfake, injection, synthetic-ID, document forgery, face-morph, device intelligence, replay. Single-product vendors treat deepfake and injection detection as roadmap items, not defaults.

Common in fintech and crypto, the same architecture fits marketplaces, iGaming, mobility, and any vertical where you need to know who someone is and what they are doing.

What does it cost? Is anything actually free?

500 verifications free every month, forever, on every account. No credit card. No sales call. No expiry.

Above the free tier, every module has a public per-success price on didit.me/pricing, $0.33 per full KYC bundle, $0.15 per Identity Document Verification, $0.15 per Wallet Screening, $0.20 per Anti-Money Laundering (AML) Screening, $0.10 per liveness, $0.05 per face match, $0.03 per Internet Protocol (IP) analysis.

Pay-as-you-go, no minimums, no overage surprises. Volume discounts kick in automatically as you grow.

Which U.S. regulator covers identity verification on a digital onboarding?

Coverage depends on the line of business, but four federal frameworks sit on top of most U.S. identity-verification flows:

  • Financial Crimes Enforcement Network (FinCEN), administers the Bank Secrecy Act and the Customer Due Diligence (CDD) Final Rule for federally regulated financial institutions; pairs with the Corporate Transparency Act for beneficial-ownership reporting.
  • Office of Foreign Assets Control (OFAC), issues the Specially Designated Nationals (SDN) list every AML screen must hit, plus consolidated sanctions programs.
  • State Money Transmitter regulators (CSBS / NMLS), ~60 state-level licences supervised by state banking departments and coordinated through the Nationwide Multistate Licensing System.
  • Federal Trade Commission + state Attorneys General, Red Flags Rule for identity-theft prevention, plus the CCPA/CPRA in California and the new state privacy regimes (VCDPA, CPA, CTDPA, UCPA).

Didit ships the hosted flow + the audit log + the watchlist coverage to satisfy all four at once, same POST /v3/session/ workflow, same JSON report, same SOC 2 Type 1 + ISO/IEC 27001 evidence pack.

Does Didit cross-check U.S. identities against credit-header and government records?

Yes, via seven Database Validation services on POST /v3/database-validation/.

  • `usa_states_death_check` ($0.05, 100% of recorded deaths), Social Security Death Master File first-pass gate.
  • `usa_states_consumer` ($0.08), lead-generation consumer database.
  • `usa_states_credit_bureau` ($0.11, ~90% coverage), aggregated credit-header data.
  • `usa_states_financial_services` ($0.19, ~85% coverage), aggregated government + public + background records tuned for financial-services use cases.
  • `usa_states_residential` ($0.54, ~90% coverage), government + public + professional address verification.
  • `usa_states_phone` ($0.30, >50% coverage) and `usa_states_phone_2` ($0.52, >90% coverage), telco-billing and mobile-network-operator phone matching.

All seven services are documented at docs.didit.me/api-reference/database-validation/united-states/. Pay-per-success, no contracts, optional SSN field for stricter matching on the credit-bureau and financial-services lookups.

How does Didit handle state-by-state Money Transmitter Licence (MTL) requirements?

Didit returns one JSON report shaped around the four FinCEN Customer Due Diligence (CDD) pillars, customer identification, beneficial ownership, risk-based ongoing monitoring, and suspicious-activity reporting. The same evidence pack maps cleanly into every state Money Transmitter Act audit supervised through the Nationwide Multistate Licensing System (NMLS) and the Conference of State Bank Supervisors (CSBS).

One API call covers all ~60 state regimes, AAMVA-aggregated driver licence checks across every state, OFAC SDN screening on every AML run, and a single audit trail with SOC 2 Type 1 + ISO/IEC 27001 attestation. For state-licensed sportsbooks (NJ, PA, NY, MI, IL) the same flow doubles as the operator's KYC + age-verification stack.

How long does it take to integrate Didit in the United States?

5 minutes to a working sandbox, a weekend to a production flow.

  • Sign up at business.didit.me, grab an API key, call POST /v3/session/ with a workflow_id that wires ID Verification + Active Liveness + Face Match + AML + U.S. credit-bureau cross-check, done.
  • AI-agent path: paste the integration prompt at docs.didit.me/integration/integration-prompt into Claude Code, Cursor, Codex, Devin, Aider, or Replit Agent. The agent provisions the application, builds the workflow, wires the webhook, and runs a smoke test.
  • Five SDKs share the same session model: Web, iOS, Android, React Native, Flutter.

The first 500 verifications every month are free, forever, pilot the full U.S. stack at zero cost before flipping production traffic.

Which language does the hosted verification flow use for U.S. users?

English (US), auto-detected from the user's browser / device locale. The hosted UI ships in 48+ languages; U.S. users land on the en-US flow by default, and Spanish (US), Simplified Chinese, Tagalog, and Vietnamese are live on the same flow for the largest non-English-speaking populations.

The document-recognition layer is decoupled from the UI layer, capture works in any language, and the admin console can be set independently to whichever language your compliance team prefers.

What does the United States verification cost end-to-end?

Per-module public pricing, pay only for what runs on the session:

  • ID Verification, $0.15 per document check.
  • Passive Liveness, $0.10. Active Liveness, $0.15.
  • Face Match 1:1, $0.05. Face Search 1:N, free.
  • AML Screening, $0.20 per check (OFAC SDN + 1,300+ lists). Ongoing AML, $0.07 per user / year.
  • `usa_states_death_check`, $0.05. `usa_states_consumer`, $0.08. `usa_states_credit_bureau`, $0.11. `usa_states_financial_services`, $0.19. `usa_states_phone`, $0.30. `usa_states_phone_2`, $0.52. `usa_states_residential`, $0.54.

The full KYC bundle (Identity + Passive Liveness + Face Match + IP Analysis) is `$0.33`, same anchor price worldwide, no state surcharge. 500 verifications free every month, no credit card. Volume discounts auto-apply above the free tier; Enterprise adds a custom Master Services Agreement (MSA) and data-residency choice.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page