Simple plans. Launching January 2027.
The pricing below is indicative. Join the waitlist and we will tell you when accounts open.
Core
For a first integration and low verification volume.
Indicative — final pricing at launch
Join the waitlist- Monthly API request quota
- Hosted verification UI with camera capture and desktop-to-phone QR hand-off
- Admin console: review queue, submissions, subject messages
- Capability-scoped ephemeral tokens per subject
- Reusable token presets and multi-step workflows
- Strict assurance flow — require a face match before approval
- Two-factor authentication (TOTP) for staff
- Hosted in Frankfurt, Germany — data stays in the EU
- Email support
Pro
For platforms running verification in production.
Indicative — final pricing at launch
Join the waitlist- Everything in Core
- Higher monthly API request quota
- Per-tenant IP allow-list (IPv4 and CIDR)
- Raw data export (JSON or CSV) for superusers
Enterprise
For higher volume and teams with a formal review process.
Indicative — final pricing at launch
Contact us- Everything in Pro
- Custom monthly API request quota
- Volume pricing — contact us to discuss
- Security review support: questionnaires and an architecture walkthrough
- Data processing agreement reviewed with your legal team
- Additional document types and regions (roadmap)
Each plan will include a monthly API request allowance; the figures will be confirmed
at launch. There is no overage billing — requests above the allowance are refused
with an HTTP 429 response until the next monthly period begins or you move
to a larger plan.
Prices are in USD, per tenant, per month. The plan contents above describe what each plan is intended to include at launch. Today the platform enforces exactly three plan-level settings: the monthly API request quota, the per-tenant IP allow-list and the flag that gates the raw data export. Plans are indicative and may change before launch; nothing is on sale and no payment can be taken today.
Included on every plan
Security and data-protection properties of the platform, not upsells.
Access control
Three staff roles (superuser, admin, view-only) checked at the router; TOTP two-factor authentication with recovery codes, which a tenant can enforce for all staff; per-user 2FA lockout and per-IP login rate limiting; a password policy on every human-chosen password.
Tenant isolation
Each tenant is assigned to one of several database shards in the EU. Tenant scoping is enforced in every query and mechanically linted in CI. Database identities are least-privilege.
Image handling
Documents and selfies are stored in private, S3-compatible object storage. Files are never served publicly; administrators receive 15-minute pre-signed URLs, and every view is recorded.
Audit trail
An append-only audit log records document views, raw exports, review decisions, erasures, logins, authorisation refusals, 2FA changes, token issuance, role and staff changes, password changes and subject record changes.
Subject rights
Administrators can lodge an erasure request on a subject's behalf, and the API exposes a subject-side erasure route your own client can call; an erasure removes the stored images and the rows together. Subjects can view and correct their own details in the hosted UI when the token allows it.
EU processing
All hosting and processing runs on IONOS Cloud in Frankfurt, Germany, and sub-processors are EU-based. Identiwise acts as processor; you remain the controller.
Frequently Asked Questions
429 response until the next period begins
or you move to a larger plan. There is no overage billing. Nothing is billed
today.