Staging environment — data here is not production data
FAQ

Questions, answered

How Fidera runs your compliance program — and what that looks like in practice.

Can Fidera enforce our CIP and compliance policy?

Yes. Your Customer Identification Program, KYC, and AML rules become configurable verification flows, risk tiers, and decisioning logic — including non-documentary checks and step-up for higher-risk cases. Every decision is logged to an append-only audit trail mapped to the requirement it satisfies, ready for examiners.

Can automated or agent-driven flows run verification through the API?

Yes — Fidera is API-first, and everything the hosted flow does is available as REST endpoints your backend or automated onboarding flow can drive directly. The verification itself still binds the account to a real person: the account holder completes the document, face match, and liveness steps, so every account an agent operates ties back to a verified legal identity, with each decision returned in seconds and logged to the audit trail.

We're a stablecoin platform — what do you cover?

Customer and payment-party screening against sanctions, PEP, export-control, and enforcement lists; designated wallet addresses; ongoing monitors; lookback batches; and holds when required AML data is missing. Not included: payment-message extraction, behavioural transaction monitoring, Travel Rule messaging, and SAR automation.

Can a verified customer be reused across platforms?

Not yet — this is on the roadmap, not in the product. The intent is that with explicit, revocable consent a person verified at one tenant could be reused at the next with a short face check instead of a full document upload. We will say so here when it ships.

How do you stop deepfakes and spoofed selfies?

Face matching plus an on-device face check that proves a live person, not a photo or recording. A verification cannot pass while required evidence is missing. We don’t publish an independently validated deepfake-detection accuracy figure.

What's your security and compliance posture?

AES-256 encryption at rest, TLS 1.2+ in transit, tenant isolation enforced in the database, and GDPR and CCPA rights supported. Our controls follow the SOC 2 Trust Services Criteria; the formal audit is planned, not complete. Control and sub-processor summaries are available on request.

How do I get an API key?

Sign up, confirm your email, and complete one identity check — the same journey your own customers will complete. Your keys are live straight after, with 250 checks included so you can build against real providers rather than fixtures. No card, no sales call.

Why do you verify me before issuing keys?

Two reasons, and they're the same reason. Checks call live providers and cost real money, so an anonymous account is an open tab; verifying the person signing up is what keeps one human from opening ten accounts. It also means you experience the product as your own first applicant before you write a line of code.

How long does integration take?

Drive the documented REST API from your backend, or use the hosted journey and the iOS client. Checks support idempotency keys and signed webhooks. The quickstart works with the key you get at signup — first Check in about five minutes.

Still have questions? Book a 30-minute walkthrough.