Skip to content

Identity Verification & KYC Arena

Sumsub vs Plaid Identity Verification

Sumsub wins · 1810 (19 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userPoint an agent at llms.txt or agent-oriented docs

    weight 2 · round to Sumsub
    Sumsubfullprobed9/10

    A live probe confirms llms.txt exists at docs.sumsub.com/llms.txt (HTTP 200) with explicit guidance that any doc page can be appended with .md for markdown, and docs pages are indeed served as .md variants throughout the evidence pack, directly enabling agent-oriented consumption. Missing for 10: no independent third-party confirmation of an agent actually consuming this successfully.

    • [probe] PROBE llms.txt: HTTP 200 at https://docs.sumsub.com/llms.txt # Sumsub Documentation > Documentation for Sumsub Append .md to any documenta…
    • [claimed-docs] Tailor colors, styles, and step instructions to match your brand across Web and Mobile SDKs.
    • [claimed-docs] Grant your team members access to your Sumsub account.
    • [claimed-docs] Generate a security key or use biometric options to reduce the risk of account compromise.
    Plaid Identity Verificationpartialprobed5/10

    Plaid does have a confirmed llms.txt at plaid.com/llms.txt and a documented MCP server, showing some agent-oriented infrastructure, but the llms.txt content is generic (not IDV-specific) and the docs-as-markdown probe for the Identity Verification pages returned a 404, meaning agent-friendly docs are not reliably available for this product area. missing for 10: a working IDV-specific llms.txt or markdown docs endpoint, evidence the MCP server exposes IDV-specific docs/tools, and independent confirmation of agent consumption.

    • [probe] PROBE llms.txt: HTTP 200 at https://plaid.com/llms.txt # Plaid > Plaid helps all companies build fintech solutions by making it easy, safe …
    • [probe] PROBE docs-md: HTTP 404 at https://plaid.com/docs/identity-verification/.md
    • [probe] official MCP server documented at https://plaid.com/docs/resources/mcp/
  2. ai-native userRun the product headlessly / in CI for automation

    weight 2 · round to Sumsub
    Sumsubpartialclaimed6/10

    Sumsub exposes a RESTful API, sandbox mode for testing integrations, and webhooks for event-driven automation—these together enable headless/CI-style usage without a UI. However, there is no explicit CI/CD tooling, CLI, or documented automation pipeline examples confirming actual CI usage. missing for 10: explicit CI/CD integration examples, official CLI, automated test/build pipeline documentation.

    • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
    • [claimed-docs] Use Sandbox mode to test your integration before going live.
    • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
    Plaid Identity Verificationnone0/10

    Evidence shows Plaid IDV as an API/webhook-driven product with a no-code Dashboard editor and Sandbox testing inputs, but there is no documentation of a CLI, SDK automation, or CI-friendly headless workflow that an AI-native user could run in an automated pipeline. Missing for 10: explicit CI/headless usage docs, CLI or automation SDK evidence, example of scripted/unattended runs.

    • [claimed-docs] No-code editor to create and change verification flows
    • [claimed-docs] In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…
    • [probe] PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …
  3. ai-native userConnect an agent via an official MCP server

    weight 3 · round to Sumsub
    Sumsubfullprobed8/10

    Sumsub explicitly documents an official MCP server that lets AI agents perform Sumsub operations under existing role permissions, corroborated by a probe confirming the doc page exists. missing for 10: independent/hands-on third-party confirmation of the MCP server working in practice, and details on setup/authentication scope.

    • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
    • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
    Plaid Identity Verificationfullprobed6/10

    Plaid is a platform/service (not itself an agent), so the axis applies, and evidence confirms an official MCP server exists at plaid.com/docs/resources/mcp/. However, the pack only shows the existence of the page, not details on what tools/capabilities are exposed via MCP or independent corroboration of its use. Missing for 10: documentation of specific MCP tool/resource definitions, usage examples, and independent/hands-on confirmation of successful agent connection.

    • [probe] official MCP server documented at https://plaid.com/docs/resources/mcp/
  4. ai-native userUse an official CLI

    weight 2 · round drawn
    Sumsubnone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      Plaid Identity Verificationnone0/10

      No evidence of an official CLI for Plaid Identity Verification; evidence only covers docs, dashboard, no-code editor, and an MCP server, none of which constitute a CLI tool.

      • ai-native userDrive the product through a documented public API

        weight 3 · round to Sumsub
        Sumsubfullprobed8/10

        Sumsub documents a public RESTful API for verification workflows, webhooks for events, sandbox testing, and even an official MCP server enabling AI agents to perform operations via the API. This directly satisfies the AI-native driving-via-API story. Missing for 10: a discoverable formal OpenAPI/Swagger spec (probe found 404s), and independent third-party corroboration of API usage.

        • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
        • [claimed-docs] Use Sandbox mode to test your integration before going live.
        • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
        • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
        • [probe] PROBE openapi: all candidate paths 404 (https://docs.sumsub.com/openapi.json, https://docs.sumsub.com/swagger.json, https://docs.sumsub.com/…
        • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
        Plaid Identity Verificationpartialprobed6/10

        Plaid IDV is documented as a REST API with webhooks, events, and workflow configuration, indicating a documented public API surface (plaid-idv-docs-1,2,3,5), and Plaid also publishes an official MCP server (plaid-idv-probe-4) supporting agentic access. However, an OpenAPI spec could not be located at standard paths and the docs-md probe 404'd, suggesting incomplete machine-readable API discoverability. missing for 10: publicly discoverable OpenAPI/schema spec, confirmation that MCP server covers IDV endpoints specifically, independent developer corroboration of API-driven automation.

        • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
        • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…
        • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
        • [claimed-docs] onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.
        • [probe] PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …
        • [probe] official MCP server documented at https://plaid.com/docs/resources/mcp/
      • ai-native userIssue scoped/least-privilege API credentials for an agent

        weight 2 · round to Sumsub
        Sumsubpartialprobed5/10

        Sumsub's MCP server docs state that AI agent access is controlled by existing Sumsub role permissions, implying some scoping via role-based access control, and separate docs confirm team member access management exists. However, there's no explicit documentation of issuing distinct, least-privilege API credentials/tokens scoped specifically to an agent (e.g., token-level scopes, expiring keys, or granular per-agent permission sets). Missing for 10: dedicated API-key/token scoping mechanism, documented permission granularity for agent-specific credentials, and independent confirmation of least-privilege enforcement in practice.

        • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
        • [claimed-docs] Grant your team members access to your Sumsub account.
        • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
        Plaid Identity Verificationnone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        • ai-native userBuild against official SDKs

          weight 2 · round to Plaid Identity Verification
          Sumsubpartialprobed5/10

          Docs confirm Web and Mobile SDKs plus a RESTful API and sandbox for integration testing, and even an MCP server for agentic use, but there is no evidence of broader official language SDKs (e.g., server-side Python/Node/Java), GitHub repos, or independent developer corroboration. missing for 10: list of official server-side/language SDKs, GitHub repo links, independent developer confirmation of SDK quality.

          • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
          • [claimed-docs] Use Sandbox mode to test your integration before going live.
          • [claimed-docs] Tailor colors, styles, and step instructions to match your brand across Web and Mobile SDKs.
          • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
          • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
          Plaid Identity Verificationpartialprobed6/10

          Plaid provides official docs, webhooks, and an llms.txt for AI-native discovery, plus a documented official MCP server, but there's no direct evidence of official language-specific SDKs for Identity Verification itself (probes for OpenAPI spec and docs.md all 404). missing for 10: explicit official SDK references/links, independent developer corroboration of SDK usage.

          • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
          • [probe] PROBE llms.txt: HTTP 200 at https://plaid.com/llms.txt # Plaid > Plaid helps all companies build fintech solutions by making it easy, safe …
          • [probe] official MCP server documented at https://plaid.com/docs/resources/mcp/
          • [probe] PROBE docs-md: HTTP 404 at https://plaid.com/docs/identity-verification/.md
          • [probe] PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …
        • ai-native userSubscribe to events via webhooks

          weight 2 · round to Sumsub
          Sumsubfullclaimed8/10

          Sumsub's documented Webhooks feature explicitly allows automatic subscription to applicant verification events and status changes, directly matching the story. Missing for 10: independent/hands-on corroboration of webhook reliability and detailed payload/event-type documentation in the evidence pack.

          • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
          Plaid Identity Verificationfullclaimed7/10

          Plaid IDV documents a clear webhook subscription mechanism with defined events (STEP_UPDATED, STATUS_UPDATED, RETRIED) that fire on verification progress, allowing programmatic/agentic subscription to state changes. Missing for 10: no explicit documentation of webhook payload schema, retry/delivery guarantees, or independent/hands-on confirmation that agentic systems actually consume these webhooks in production.

          • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
          • [claimed-docs] onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.

        Agentic features

        1. ai-native userGet AI-generated insights and suggestions from my data inside the product

          weight 2 · round drawn
          Sumsubnone0/10

          Evidence covers AI-driven verification checks (liveness, document verification, AML screening) and an MCP server for agents to perform actions, but there is no evidence of AI-generated insights, summaries, or suggestions surfaced to users from their own data inside the product dashboard. missing for 10: any documented AI-generated analytics/insights feature, dashboard summarization, or recommendation engine within the Sumsub UI.

          • [claimed-docs] Configure your AML screening settings to suit your needs by screening against targeted lists and categories that are relevant to your busine…
          • [claimed-docs] In under a second, it confirms the applicant is a real, live person (not a deepfake, AI-generated image, paper mask, photo of a screen, or d…
          • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
          Plaid Identity Verificationnone0/10

          Evidence shows Plaid IDV as a verification/workflow product with risk scores, dashboards, and webhooks, but nothing about AI-generated insights or suggestions surfaced to end users within the product itself; the MCP server reference is about agent connectivity, not in-product AI insights.

          • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…
          • [probe] official MCP server documented at https://plaid.com/docs/resources/mcp/
        2. ai-native userSet up automations that run autonomously in the background

          weight 2 · round drawn
          Sumsubpartialprobed5/10

          Sumsub supports background automation implicitly via webhooks (automatic event notifications), verification levels (automated multi-step verification sequences), and AML screening configuration that runs automatically — plus an MCP server letting AI agents perform operations autonomously under role permissions. However, there's no dedicated workflow/rules builder or scheduler described as enabling arbitrary user-defined 'set and forget' automations beyond the verification pipeline itself. Missing for 10: an explicit automation/workflow orchestration feature, scheduling capability, and independent evidence of autonomous background runs beyond webhook triggers.

          • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
          • [claimed-docs] A level is a sequence of steps that your applicants have to take to verify their identity. Each level may include document-based or selfie-b…
          • [claimed-docs] Configure your AML screening settings to suit your needs by screening against targeted lists and categories that are relevant to your busine…
          • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
          • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
          Plaid Identity Verificationpartialclaimed5/10

          Plaid IDV supports background automation via webhooks (STEP_UPDATED, STATUS_UPDATED, RETRIED) and a no-code Workflow Management editor that can run conditional verification checks without manual intervention, which enables some autonomous background processing. However, there is no evidence of AI-agent-specific automation setup, natural-language automation configuration, or scheduling/triggering by an AI agent itself. Missing for 10: explicit AI-agent-driven automation setup, natural-language workflow configuration, evidence of autonomous agent-triggered verification chains beyond webhook/workflow primitives.

          • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…
          • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
          • [claimed-docs] No-code editor to create and change verification flows
          • [claimed-docs] onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.
        3. ai-native userOperate the product with natural-language commands

          weight 2 · round to Sumsub
          Sumsubpartialprobed6/10

          Sumsub documents an official MCP server that lets AI agents perform Sumsub operations on the user's behalf under role-based permissions, which enables natural-language/agentic control via an AI agent interface rather than the product itself exposing an NL command layer. Missing for 10: direct evidence of a native natural-language command interface within Sumsub's own UI/API, and independent/hands-on confirmation of the MCP server's real-world usability.

          • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
          • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
          Plaid Identity Verificationpartialprobed4/10

          Plaid documents a no-code visual workflow editor for configuring Identity Verification, not natural-language command operation, but a probe confirms Plaid has an official MCP server (plaid.com/docs/resources/mcp/) which could allow AI agents to invoke Plaid APIs including IDV via natural language. There is no direct evidence that this MCP server specifically exposes Identity Verification actions or that end-users can operate IDV flows via NL commands. missing for 10: IDV-specific MCP tool documentation, examples of natural-language driven verification commands, independent confirmation of agentic usage.

          • [probe] official MCP server documented at https://plaid.com/docs/resources/mcp/
          • [claimed-docs] No-code editor to create and change verification flows

        Api quality

        1. ai-native userExplore an interactive API reference with runnable examples

          weight 2 · round drawn
          Sumsubnone0/10

          There's mention of a REST API and docs, but no evidence of an interactive API reference with runnable examples (e.g., try-it-out console, embedded code sandbox); the OpenAPI/Swagger probe returned 404s, suggesting no interactive spec is publicly exposed.

          • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
          • [probe] PROBE openapi: all candidate paths 404 (https://docs.sumsub.com/openapi.json, https://docs.sumsub.com/swagger.json, https://docs.sumsub.com/…
          Plaid Identity Verificationnone0/10

          No evidence of an interactive API reference with runnable examples; OpenAPI spec probes returned 404s and docs are plain markdown pages, not interactive/runnable explorer.

          • [probe] PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …
          • [probe] PROBE docs-md: HTTP 404 at https://plaid.com/docs/identity-verification/.md
        2. ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

          weight 2 · round drawn
          Sumsubnone0/10

          Sumsub documents a RESTful API and provides llms.txt for markdown docs, but direct probes for OpenAPI/Swagger spec files all returned 404, and no evidence pack item points to a downloadable machine-readable API spec.

          • [probe] PROBE openapi: all candidate paths 404 (https://docs.sumsub.com/openapi.json, https://docs.sumsub.com/swagger.json, https://docs.sumsub.com/…
          • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
          Plaid Identity Verificationnone0/10

          Probes explicitly show no OpenAPI/swagger spec found at any candidate path and no machine-readable .md/doc spec at the IDV docs endpoint; documentation is prose-based rather than a downloadable API spec.

          • [probe] PROBE docs-md: HTTP 404 at https://plaid.com/docs/identity-verification/.md
          • [probe] PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …
        3. ai-native userTest against a sandbox environment without touching production data

          weight 1 · round to Sumsub
          Sumsubfullclaimed8/10

          Sumsub explicitly documents a Sandbox mode for testing integrations before going live without touching production data, directly matching the story. Missing for 10: independent/hands-on corroboration beyond vendor docs, and details on how sandbox data isolation is guaranteed.

          • [claimed-docs] Use Sandbox mode to test your integration before going live.
          Plaid Identity Verificationfullclaimed7/10

          Plaid IDV documents a dedicated Sandbox mode with fixed test inputs to simulate successful/failed verification checks without touching production data, which directly supports safe testing. missing for 10: no independent/hands-on developer confirmation of sandbox fidelity, and no explicit mention of automated/agentic test workflows against the sandbox.

          • [claimed-docs] In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…
        4. ai-native userRely on versioned APIs with a documented deprecation policy

          weight 2 · round drawn
          Sumsubnone0/10

          No evidence of API versioning scheme or a documented deprecation policy; OpenAPI spec probes returned 404s and docs only describe general REST usage, sandbox testing, and webhooks without mentioning version lifecycle or deprecation timelines.

          • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
          • [probe] PROBE openapi: all candidate paths 404 (https://docs.sumsub.com/openapi.json, https://docs.sumsub.com/swagger.json, https://docs.sumsub.com/…
          Plaid Identity Verificationnone0/10

          No evidence of API versioning scheme or documented deprecation policy for Plaid Identity Verification's APIs; docs cover verification features, webhooks, sandbox testing, but nothing on version lifecycle or deprecation commitments. The openapi.json probe also 404s, suggesting no discoverable machine-readable API spec that would typically accompany versioning docs.

          • [probe] PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …
          • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
          • [claimed-docs] In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…

        Automation depth — how much of the product can run unattendedAutomation depth

        How much of the product can run unattended

        1. ai-native userPerform bulk operations across many items at once

          weight 2 · round drawn
          Sumsubnone0/10

          Evidence shows a RESTful API, webhooks, and an MCP server for automating individual applicant verification workflows, but nothing documents batch/bulk endpoints or bulk-processing capabilities across many applicants or items at once.

          • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
          • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
          • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
          Plaid Identity Verificationnone0/10

          No evidence of batch/bulk API operations, bulk session creation, or programmatic multi-item processing for Identity Verification; documentation covers single-session workflows, webhooks, and dashboard-based overrides only, with no mention of bulk endpoints or automation-scale operations across many items.

          • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…
          • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
          • [claimed-docs] you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.
        2. ai-native userDefine rules that trigger actions automatically on events

          weight 3 · round to Plaid Identity Verification
          Sumsubpartialclaimed5/10

          Sumsub's webhook system lets applicants' verification events (e.g., status changes) automatically trigger outbound notifications, which can drive downstream actions, and AML/verification level configuration lets you set some conditional check rules — but there's no documented rules engine for defining custom 'if event X then action Y' automation beyond webhooks and level configuration. Missing for 10: a dedicated rules/automation engine, conditional branching logic, and evidence of user-defined trigger-action workflows beyond webhook notifications.

          • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
          • [claimed-docs] A level is a sequence of steps that your applicants have to take to verify their identity. Each level may include document-based or selfie-b…
          • [claimed-docs] Configure your AML screening settings to suit your needs by screening against targeted lists and categories that are relevant to your busine…
          Plaid Identity Verificationpartialclaimed6/10

          Plaid IDV supports webhooks that fire on defined events (STEP_UPDATED, STATUS_UPDATED, RETRIED) and a Workflow Management editor that lets you run certain verification checks conditionally (e.g., only if another check fails or based on country), which together give a rule/event-driven automation capability. However, this is scoped to verification-flow logic and webhook notifications rather than a general-purpose 'define rules that trigger arbitrary actions' engine. missing for 10: evidence of a broader rule/action engine beyond conditional verification checks, and evidence of user-defined custom actions (not just webhook notifications) triggered by events.

          • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…
          • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
          • [claimed-docs] onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.
          • [claimed-docs] No-code editor to create and change verification flows

        Biometric liveness — stories about biometric liveness in this arenaBiometric liveness

        Stories about biometric liveness in this arena

        Deepfake defense

        1. risk analystThe vendor documents specific defenses against AI-generated faces, deepfakes, and camera-injection attacks — named detection capabilities, not just a marketing mention of fraud

          weight 2 · round to Sumsub
          Sumsubpartialclaimed6/10

          Sumsub's liveness docs explicitly name defenses against deepfakes, AI-generated images, paper masks, photos of screens, and dolls, going beyond generic marketing language (sumsub-docs-12) and includes a review workflow for liveness results (sumsub-docs-13). However, there is no explicit mention of 'camera injection' attacks or deeper technical detail on how each attack vector is detected. missing for 10: explicit camera-injection attack defenses, technical/algorithmic detail on detection methods, independent validation of these claims.

          • [claimed-docs] In under a second, it confirms the applicant is a real, live person (not a deepfake, AI-generated image, paper mask, photo of a screen, or d…
          • [claimed-docs] Open the Applicants page and select an applicant who passed the Liveness check. In the profile, navigate to the Liveness section and review …
          Plaid Identity Verificationnone0/10

          The evidence pack covers document verification, workflow management, webhooks, sandbox testing, risk scoring, and dashboard overrides, but contains no mention of liveness detection, anti-spoofing, deepfake detection, AI-generated face detection, or camera-injection defenses by name. Community items are off-topic (data trust/competition) and irrelevant to biometric liveness. Missing for 10: named liveness/anti-spoofing detection capabilities, deepfake or synthetic-face detection mentions, camera-injection attack defenses.

          Duplicate detection

          1. risk analystThe platform detects repeat and duplicate identities across verifications — the same face or document resurfacing under different names is flagged automatically

            weight 2 · round drawn
            Sumsubnone0/10

            The evidence covers liveness detection, document verification, AML screening, and reusable KYC, but none of it describes cross-applicant duplicate/repeat identity detection (e.g., flagging the same face or document reused under a different name). This is a plausible and common KYC capability, but no evidence pack item documents it for Sumsub.

              Plaid Identity Verificationnone0/10

              The evidence covers document/identity verification checks, risk scoring, webhooks, and dashboard overrides, but nothing describes cross-session duplicate or repeat-identity detection (e.g., matching the same face/document under different names). Missing for 10: any documentation of duplicate-identity or repeat-fraud detection across sessions, biometric/face matching against prior submissions, or deduplication reporting.

              • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
              • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…
              • [claimed-docs] The conversion rate is defined as the percentage of sessions begun that were completed, regardless of whether the user passed or failed veri…

            Liveness

            1. risk analystSelfie checks match the live user to the document portrait with liveness detection — documented defenses against printed photos, screens, and replayed video

              weight 3 · round to Sumsub
              Sumsubfullclaimed8/10

              Sumsub's docs explicitly describe liveness detection that confirms the applicant is a real, live person and not a deepfake, AI-generated image, paper mask, or photo of a screen, and matches them to the account/document on file, plus a review workflow for liveness results and a broader Liveness & Face match check within verification levels. Missing for 10: independent/hands-on corroboration of anti-spoofing efficacy (e.g., third-party pentest or lab results) and explicit mention of replayed-video defenses beyond screen-photo detection.

              • [claimed-docs] In under a second, it confirms the applicant is a real, live person (not a deepfake, AI-generated image, paper mask, photo of a screen, or d…
              • [claimed-docs] Open the Applicants page and select an applicant who passed the Liveness check. In the profile, navigate to the Liveness section and review …
              • [claimed-docs] A level is a sequence of steps that your applicants have to take to verify their identity. Each level may include document-based or selfie-b…
              Plaid Identity Verificationnone0/10

              The evidence pack covers document verification, workflows, webhooks, sandbox testing, risk scoring, and dashboard overrides, but never mentions selfie/facial matching or liveness detection defenses against photos, screens, or replayed video. No documentation cites a selfie check or anti-spoofing mechanism at all.

              Data checks — stories about data checks in this arenaData checks

              Stories about data checks in this arena

              Db checks

              1. developerVerify identity against authoritative databases without documents — SSN, national registries, or credit-header data — for lower-friction flows where a doc scan is overkill

                weight 2 · round to Plaid Identity Verification
                Sumsubnone0/10

                The evidence pack covers document verification, liveness, AML screening, and reusable KYC, but contains no mention of no-document database verification methods such as SSN checks, national registry lookups, or credit-header data — the specific capability the story asks about.

                  Plaid Identity Verificationpartialclaimed4/10

                  Docs show IDV can check ID numbers, phone, address, name/DOB and combine checks conditionally (skipping some verifications like documents based on risk/country), implying some document-free paths exist, but no evidence explicitly names SSN, national registry, or credit-header-only verification flows as a distinct low-friction option. missing for 10: explicit mention of SSN-only or credit-header verification, explicit 'no-doc' database-only workflow example, independent confirmation of doc-free flows in production.

                  • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
                  • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…
                  • [claimed-docs] Authenticate IDs Verify that global ID documents are authentic and valid.

                Kyb

                1. ops leadVerify businesses, not just people — registry lookups, UBO identification, and documented KYB flows that chain into KYC on the owners

                  weight 2 · round drawn
                  Sumsubnone0/10

                  The evidence pack covers individual KYC flows (document/liveness checks, verification levels, AML screening, reusable KYC) but contains no mention of business/KYB verification, company registry lookups, or UBO identification chaining into KYC. Since none of the provided evidence addresses business verification specifically, this applicable axis is unsupported.

                    Plaid Identity Verificationnone0/10

                    All evidence describes Plaid Identity Verification as a personal KYC flow (documents, phone, DOB, ID numbers, risk scoring) with no mention of business registry lookups, UBO identification, or a documented KYB workflow chaining into KYC on owners.

                    • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
                    • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…
                    • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…
                    • [claimed-docs] Monitor also integrates directly with Identity Verification for an end-to-end verification and KYC solution.

                  Risk signals

                  1. developerEnrich verifications with phone, email, and device risk signals — carrier checks, address history, device fingerprint — as additional documented check types

                    weight 2 · round to Plaid Identity Verification
                    Sumsubnone0/10

                    The evidence pack covers document verification, liveness, AML screening, verification levels, and reusable KYC, but contains no mention of phone/carrier checks, email risk scoring, address history validation, or device fingerprinting as check types.

                      Plaid Identity Verificationpartialclaimed5/10

                      Docs confirm phone and email risk scoring plus granular risk assessments shown per session, and address/name/ID verification is documented as a check type, but there is no explicit documentation of carrier checks, address history checks, or device fingerprinting as distinct check types. missing for 10: explicit carrier check documentation, address history verification, device fingerprint/risk signal documentation.

                      • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
                      • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…

                    Document coverage — stories about document coverage in this arenaDocument coverage

                    Stories about document coverage in this arena

                    Doc types

                    1. ops leadThe platform verifies government IDs from a documented breadth of countries and document types — passports, national IDs, driver licenses, residence permits — with the supported list published

                      weight 3 · round to Sumsub
                      Sumsubpartialclaimed6/10

                      Sumsub publishes a broad claim of covering '14,000+ document types from 220+ countries and territories' and describes verification levels including document-based checks, but the evidence pack lacks a documented published list/breakdown by specific document type (passports, national IDs, driver licenses, residence permits) per country. missing for 10: a searchable/published per-country per-document-type coverage list, independent verification of the 14,000+ document claim.

                      • [claimed-docs] Instantly verify 14,000+ document types from 220+ countries and territories.
                      • [claimed-docs] A level is a sequence of steps that your applicants have to take to verify their identity. Each level may include document-based or selfie-b…
                      Plaid Identity Verificationpartialclaimed3/10

                      Plaid's docs assert it verifies 'identification documents' and 'global ID documents' broadly, but no evidence provides an actual published list of supported countries or document types (passports, national IDs, driver licenses, residence permits) as the story requires. missing for 10: a published country/document-type coverage list, explicit mention of residence permits or other document categories, independent corroboration of coverage breadth.

                      • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
                      • [claimed-docs] Authenticate IDs Verify that global ID documents are authentic and valid.
                      • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…

                    Extraction

                    1. developerVerified sessions return the extracted document fields as structured data — name, date of birth, document number, address, expiry — retrievable via the API, not just a pass/fail flag

                      weight 2 · round to Plaid Identity Verification
                      Sumsubnone0/10

                      The evidence pack shows Sumsub exposes applicant data via RESTful APIs and covers document verification broadly, but none of the cited docs mention retrieving structured extracted fields (name, DOB, document number, address, expiry) via API rather than a pass/fail result. missing for 10: explicit API/field reference docs showing extracted document data payload, sample response schema, or field-level API endpoint.

                      • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
                      • [claimed-docs] Instantly verify 14,000+ document types from 220+ countries and territories.
                      Plaid Identity Verificationpartialclaimed5/10

                      Docs confirm Plaid extracts and verifies fields like name, DOB, ID numbers, and address from documents, and risk scores/results are viewable in the Dashboard, implying this data exists per session. However, there's no explicit evidence that these individual extracted document fields are retrievable via API as structured data in the response payload (as opposed to just Dashboard viewing or an overall pass/fail status). Missing for 10: explicit API schema/response example showing per-field structured output (name, DOB, document number, address, expiry) retrievable via API call, independent developer confirmation of this data access pattern.

                      • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
                      • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…
                      • [claimed-docs] Authenticate IDs Verify that global ID documents are authentic and valid.

                    Idv agent access — stories about idv agent access in this arenaIdv agent access

                    Stories about idv agent access in this arena

                    Agent decisions

                    1. ai-native userVerification outcomes come back structured enough for an agent to decide on — machine-readable check results, risk signals, and failure reasons an automated onboarding flow can branch on

                      weight 2 · round drawn
                      Sumsubpartialprobed6/10

                      Sumsub's REST API and webhook system (sumsub-docs-1, sumsub-docs-3) provide machine-readable verification events, and verification levels/AML screening (sumsub-docs-5, sumsub-docs-6) imply structured check results and risk categorization that an automated flow could branch on; the MCP server (sumsub-docs-4, sumsub-probe-3) further supports agent-driven access. However, the evidence never shows the actual JSON schema, specific risk-score fields, or enumerated failure-reason codes, and no OpenAPI spec is discoverable (sumsub-probe-2), so it's unclear how granular/structured the failure reasons truly are. Missing for 10: explicit schema/examples of check-result payloads, documented risk-signal taxonomy, and enumerated failure-reason codes for automated branching.

                      • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
                      • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
                      • [claimed-docs] A level is a sequence of steps that your applicants have to take to verify their identity. Each level may include document-based or selfie-b…
                      • [claimed-docs] Configure your AML screening settings to suit your needs by screening against targeted lists and categories that are relevant to your busine…
                      • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
                      • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
                      • [probe] PROBE openapi: all candidate paths 404 (https://docs.sumsub.com/openapi.json, https://docs.sumsub.com/swagger.json, https://docs.sumsub.com/…
                      Plaid Identity Verificationpartialclaimed6/10

                      Plaid IDV exposes structured webhook events (STEP_UPDATED, STATUS_UPDATED, RETRIED) and per-session risk signals (email/phone risk, overall risk score) that a workflow could branch on, plus conditional check logic in templates. However, evidence doesn't show a documented API response schema with explicit machine-readable failure-reason codes for programmatic branching, and there's no independent/hands-on confirmation of how granular or reliable these signals are for automated agent decisioning. Missing for 10: explicit API/webhook payload schema with structured failure-reason enums, and independent corroboration of agent-usable structured outputs.

                      • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
                      • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…
                      • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…
                      • [claimed-docs] onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.

                    Agent operations

                    1. ai-native userAn agent can operate the verification pipeline — create sessions, poll outcomes, retrieve extracted data, and trigger re-checks through the API or an MCP surface with scoped credentials

                      weight 3 · round to Sumsub
                      Sumsubpartialprobed6/10

                      Sumsub has a documented REST API and an official MCP server explicitly described for letting AI agents perform Sumsub operations under scoped role-based permissions (sumsub-docs-4, sumsub-probe-3), plus webhooks for outcome notification (sumsub-docs-3). However, evidence doesn't confirm specifics like polling outcomes, retrieving extracted data, or triggering re-checks explicitly through the MCP surface, nor is there an OpenAPI spec confirming full API surface (sumsub-probe-2 shows 404s). Missing for 10: explicit documentation of session creation/polling/re-check operations via MCP, confirmation of scoped credential granularity within MCP, and independent/hands-on validation of the MCP server's agent workflows.

                      • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
                      • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
                      • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
                      • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
                      • [probe] PROBE openapi: all candidate paths 404 (https://docs.sumsub.com/openapi.json, https://docs.sumsub.com/swagger.json, https://docs.sumsub.com/…
                      Plaid Identity Verificationpartialprobed4/10

                      Plaid IDV has a documented API/webhook model (create sessions, poll status via STEP_UPDATED/STATUS_UPDATED/RETRIED events, retrieve data) and an official MCP server is referenced, suggesting some agent-friendly surface exists. However, there is no evidence describing scoped credentials for agent use, no documentation of MCP tools specifically exposing IDV session creation/polling/data retrieval/re-check triggers, and no confirmation of programmatic re-check triggering beyond dashboard override. missing for 10: MCP server tool documentation specific to IDV endpoints, scoped/least-privilege credential model for agents, programmatic re-check/retry trigger via API, independent confirmation of agent usage.

                      • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
                      • [claimed-docs] you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.
                      • [probe] official MCP server documented at https://plaid.com/docs/resources/mcp/

                    Integration dx — sandboxes, test modes, webhooks, and how fast a developer gets to a working integrationIntegration dx

                    Sandboxes, test modes, webhooks, and how fast a developer gets to a working integration

                    Sandbox

                    1. developerA sandbox lets me exercise every outcome before going live — documented test documents, personas, or magic values that deterministically produce pass, fail, and review results

                      weight 3 · round to Plaid Identity Verification
                      Sumsubpartialclaimed4/10

                      Sumsub documents a Sandbox mode for testing integrations before going live (sumsub-docs-2), but the evidence pack contains no specifics on documented test documents, personas, or magic values that deterministically trigger pass/fail/review outcomes. Missing for 10: documented deterministic test data/personas, explicit mapping of test inputs to pass/fail/review results, and any hands-on confirmation of sandbox behavior.

                      • [claimed-docs] Use Sandbox mode to test your integration before going live.
                      Plaid Identity Verificationfullclaimed8/10

                      Plaid's docs explicitly document a Sandbox mode with a fixed set of inputs that deterministically produce specific Data Source and Documentary Verification check outcomes, directly matching the story's requirement for documented test values to exercise pass/fail scenarios. Missing for 10: explicit confirmation of a 'review' outcome test value and independent/hands-on developer corroboration beyond first-party docs.

                      • [claimed-docs] In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…

                    Session api

                    1. developerThe whole verification lifecycle is drivable through the API — create a session, get its status, retrieve results and captured media, and cancel or redact it — with every step documented

                      weight 3 · round to Sumsub
                      Sumsubpartialprobed5/10

                      Sumsub confirms a RESTful API, sandbox testing, and webhooks for applicant verification events, implying core lifecycle operations exist, but the evidence pack never documents explicit endpoints for session status polling, retrieving captured media, or cancel/redact actions, and probes for an OpenAPI/swagger spec all 404. Missing for 10: documented endpoints for status retrieval, media/result retrieval, and cancel/redact operations, plus a discoverable API reference (OpenAPI) confirming full lifecycle coverage.

                      • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
                      • [claimed-docs] Use Sandbox mode to test your integration before going live.
                      • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
                      • [probe] PROBE openapi: all candidate paths 404 (https://docs.sumsub.com/openapi.json, https://docs.sumsub.com/swagger.json, https://docs.sumsub.com/…
                      Plaid Identity Verificationpartialclaimed4/10

                      Docs confirm session lifecycle events (webhooks for STEP_UPDATED/STATUS_UPDATED/RETRIED) and sandbox testing, implying some API-driven flow, but there is no explicit documentation of endpoints for creating a session, fetching status/results, retrieving captured media, or canceling/redacting a session via API — most control (overrides, flow editing) is shown as Dashboard/no-code actions rather than API calls. missing for 10: explicit API reference for create/get/retrieve-media/cancel/redact endpoints, first-party API examples for each lifecycle step.

                      • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
                      • [claimed-docs] In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…
                      • [claimed-docs] you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.
                      • [claimed-docs] No-code editor to create and change verification flows

                    Webhooks

                    1. developerVerification lifecycle events arrive as signed webhooks — created, processing, verified, requires-input — so my system reacts to outcomes without polling

                      weight 2 · round drawn
                      Sumsubpartialclaimed5/10

                      Sumsub docs confirm a webhooks system that automatically notifies of applicant verification status changes, satisfying the core 'react without polling' need, but the evidence pack never documents webhook signing/signature verification or enumerates specific lifecycle event types like created/processing/verified/requires-input. missing for 10: signature verification mechanism details, explicit list of lifecycle event payload types, independent/hands-on confirmation of webhook reliability.

                      • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
                      Plaid Identity Verificationpartialclaimed5/10

                      Plaid IDV documents webhook events (STEP_UPDATED, STATUS_UPDATED, RETRIED) that let a developer react to verification lifecycle changes without polling, but the evidence never confirms these webhooks are cryptographically signed nor does it list the specific status values (created, processing, verified, requires-input) named in the story. Missing for 10: explicit documentation of webhook signature verification, and confirmation of the exact lifecycle status enum matching the story's terms.

                      • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
                      • [claimed-docs] onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.

                    Openness — open source, data portability, and self-hosting storiesOpenness

                    Open source, data portability, and self-hosting stories

                    1. ai-native userDo everything through the API that I can do in the UI

                      weight 2 · round to Sumsub
                      Sumsubpartialprobed5/10

                      Sumsub exposes a REST API for core verification flows (processing applicants/documents, webhooks, AML screening) and even an MCP server for agent-driven operations, showing strong API coverage of the verification workflow. However, several UI-configured capabilities (team member access management, branding/styles, security-key/biometric account settings) are documented only as console actions with no evidence of equivalent API endpoints, and no public OpenAPI/swagger spec was found (probe returned 404s), so full UI-API parity isn't demonstrated. Missing for 10: API/CLI equivalents for team access management, branding customization, and security settings; a public API reference confirming full endpoint coverage.

                      • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
                      • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
                      • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
                      • [claimed-docs] Configure your AML screening settings to suit your needs by screening against targeted lists and categories that are relevant to your busine…
                      • [claimed-docs] Tailor colors, styles, and step instructions to match your brand across Web and Mobile SDKs.
                      • [claimed-docs] Grant your team members access to your Sumsub account.
                      • [claimed-docs] Generate a security key or use biometric options to reduce the risk of account compromise.
                      • [probe] PROBE openapi: all candidate paths 404 (https://docs.sumsub.com/openapi.json, https://docs.sumsub.com/swagger.json, https://docs.sumsub.com/…
                      Plaid Identity Verificationnone0/10

                      Evidence shows several capabilities are explicitly UI/Dashboard-only — e.g., the no-code Workflow Management editor for creating flows (plaid-idv-docs-8) and overriding failed verifications 'via the Dashboard by clicking the Override Result button' (plaid-idv-docs-7) — with no documented API equivalent for either. There is no evidence of a full API surface mirroring these UI actions, so the story is not shown to be delivered.

                      • [claimed-docs] you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.
                      • [claimed-docs] No-code editor to create and change verification flows
                      • [probe] PROBE openapi: all candidate paths 404 (https://plaid.com/openapi.json, https://plaid.com/swagger.json, https://plaid.com/api/openapi.json, …
                    2. ai-native userExport all of my data in open formats and leave

                      weight 3 · round drawn
                      Sumsubnone0/10

                      Sumsub is a KYC/verification platform storing applicant data, but no evidence shows a user-facing data export feature in open/portable formats or an account-closure data portability workflow; only API access for processing applicant data during integration is documented, not a 'take your data and leave' capability.

                      • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
                      • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
                      Plaid Identity Verificationnone0/10

                      No evidence of a user-facing data export/portability feature in open formats or account deletion/leave capability for Identity Verification data; evidence covers verification flows, webhooks, dashboard overrides, and risk scoring only.

                      Privacy posture — data-handling and privacy storiesPrivacy posture

                      Data-handling and privacy stories

                      1. ai-native userChoose where my data is stored (region/residency)

                        weight 2 · round drawn
                        Sumsubnone0/10

                        No evidence in the pack mentions data residency options, regional data storage, or the ability to choose a storage location; nothing addresses this axis at all.

                          Plaid Identity Verificationnone0/10

                          No evidence in the pack addresses data residency, regional storage options, or data localization controls for Identity Verification; the community citation reflects general distrust, not a data-residency dispute.

                          • ai-native userPrevent my data from being used to train AI models

                            weight 3 · round drawn
                            Sumsubnone0/10

                            No evidence in the pack addresses AI-training data usage or opt-out policies; Sumsub's docs cover verification, AML, and API features but nothing about preventing data from being used to train AI models.

                              Plaid Identity Verificationnone0/10

                              No evidence of an AI-training opt-out or data-usage control for AI models; docs cover verification workflows, webhooks, and dashboard features only, and community comments express general distrust rather than confirming/denying such a control.

                              • ai-native userControl data retention and deletion

                                weight 2 · round drawn
                                Sumsubnone0/10

                                No evidence in the pack addresses data retention policies, deletion controls, or data lifecycle management for applicant data; the docs cover verification, AML, MCP, and API features but nothing on retention/deletion mechanisms.

                                  Plaid Identity Verificationnone0/10

                                  The evidence pack contains no documentation of data retention settings, deletion APIs, or user-facing controls for purging identity verification data — only unrelated docs on verification checks, webhooks, and dashboard workflows. The negative community comment expresses general distrust but is not concrete evidence of a retention/deletion feature failing, so it doesn't support 'disputed'; it simply confirms no capability is evidenced.

                                  • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
                                  • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…
                                  • [community] Wow. I truly hate having to use plaid. This is disappointing. I have zero faith that they hold my data safely or that it won't be stolen or …
                                • ai-native userOpt out of telemetry and usage tracking

                                  weight 2 · round drawn
                                  Sumsubnone0/10

                                  No evidence pack item addresses telemetry/usage tracking or an opt-out mechanism; Sumsub's docs cover verification, API, security, and MCP features but nothing about analytics/telemetry controls.

                                    Plaid Identity Verificationnone0/10

                                    No evidence in the pack addresses telemetry/usage-tracking opt-out controls for Plaid Identity Verification; docs cover verification workflows, webhooks, and reporting but nothing about disabling analytics or usage data collection.

                                    Privacy retention — stories about privacy retention in this arenaPrivacy retention

                                    Stories about privacy retention in this arena

                                    Consent

                                    1. founderThe vendor documents how biometric data is handled lawfully — GDPR bases, US biometric statutes like BIPA, and the consent language my flow needs — so legal review has something to review

                                      weight 2 · round drawn
                                      Sumsubnone0/10

                                      The evidence pack shows Sumsub does biometric liveness/face-match checks, but contains no documentation of legal bases (GDPR), US biometric statutes like BIPA, or consent language guidance for legal review — missing for 10: GDPR lawful-basis documentation, BIPA/state biometric statute references, consent language templates or legal review materials.

                                        Plaid Identity Verificationnone0/10

                                        The evidence pack contains only general product/API documentation (verification checks, webhooks, sandbox testing, dashboard features) with no mention of GDPR legal bases, BIPA or other biometric statutes, or required consent language for biometric data collection. Community items are off-topic sentiment about data trust, not legal compliance documentation.

                                        Redaction

                                        1. ops leadControl what happens to collected identity data — documented retention windows and a redaction or deletion API that scrubs PII on demand

                                          weight 2 · round drawn
                                          Sumsubnone0/10

                                          No evidence pack item documents retention windows, PII redaction, or a deletion/scrubbing API — the pack covers verification levels, AML, liveness, webhooks, and MCP, none of which address data retention or deletion controls.

                                            Plaid Identity Verificationnone0/10

                                            The evidence pack covers verification checks, webhooks, dashboards, and risk scoring, but contains no documentation of data retention windows or a redaction/deletion API for scrubbing PII on demand. The community comments express general distrust about data safety but do not concretely confirm or deny a deletion/retention mechanism, so they cannot be used to dispute the claim either way.

                                            • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
                                            • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…

                                          Verification flows — stories about verification flows in this arenaVerification flows

                                          Stories about verification flows in this arena

                                          Hosted flows

                                          1. developerLaunch a complete document-plus-selfie verification with a hosted or drop-in flow — create a session server-side, redirect or embed, and read the result — without building capture UI myself

                                            weight 3 · round to Sumsub
                                            Sumsubfullclaimed7/10

                                            Docs show server-side REST API for creating verification sessions, prebuilt Web/Mobile SDKs for drop-in capture UI (document+selfie, liveness), webhooks to read verification results, and sandbox testing — covering the full story without requiring custom capture UI. Missing for 10: explicit documentation of the hosted redirect flow vs embedded SDK distinction, an explicit 'create applicant/session' API code sample, and independent/hands-on corroboration beyond first-party docs.

                                            • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
                                            • [claimed-docs] A level is a sequence of steps that your applicants have to take to verify their identity. Each level may include document-based or selfie-b…
                                            • [claimed-docs] Tailor colors, styles, and step instructions to match your brand across Web and Mobile SDKs.
                                            • [claimed-docs] In under a second, it confirms the applicant is a real, live person (not a deepfake, AI-generated image, paper mask, photo of a screen, or d…
                                            • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
                                            • [claimed-docs] Use Sandbox mode to test your integration before going live.
                                            Plaid Identity Verificationpartialclaimed6/10

                                            Docs show a Link-based embeddable flow (onEvent updates), webhook events to read session status, and document/ID verification checks, indicating Plaid provides the capture UI and hosted/drop-in flow with server-driven session lifecycle. However, evidence never explicitly confirms a selfie/facial biometric step combined with document checks, nor explicitly describes server-side session creation API or a hosted redirect option (only Link embed and no-code editor are mentioned). Missing for 10: explicit selfie/liveness verification documentation, explicit server-side create-session API reference, and confirmation of a hosted (non-Link) redirect flow.

                                            • [claimed-docs] Using Identity Verification, you can verify identification documents, phone numbers, name, date of birth, ID numbers, addresses, and more.
                                            • [claimed-docs] onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.
                                            • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
                                            • [claimed-docs] Authenticate IDs Verify that global ID documents are authentic and valid.
                                            • [claimed-docs] No-code editor to create and change verification flows

                                          Native sdks

                                          1. developerI get native iOS, Android, and web SDKs with guided camera capture — glare, blur, and edge detection coaching the user to a usable document photo on the first try

                                            weight 2 · round drawn
                                            Sumsubnone0/10

                                            Evidence confirms Sumsub offers Web and Mobile SDKs with brand/style customization and document verification across many types, but there is no evidence describing native iOS/Android capture guidance features like glare, blur, or edge detection coaching during document photo capture. Missing for 10: explicit documentation of guided camera capture UX, glare/blur detection, and edge-detection coaching in the SDKs.

                                            • [claimed-docs] Tailor colors, styles, and step instructions to match your brand across Web and Mobile SDKs.
                                            • [claimed-docs] Instantly verify 14,000+ document types from 220+ countries and territories.
                                            Plaid Identity Verificationnone0/10

                                            The evidence confirms Plaid IDV supports document verification and has Link SDK flows with event callbacks (onEvent), but nothing describes native iOS/Android/web SDKs offering guided camera capture with glare, blur, or edge-detection coaching. Missing for 10: mention of native mobile SDKs, in-flow camera guidance features, and any glare/blur/edge detection capability documentation.

                                            • [claimed-docs] onEvent will fire at certain points throughout the IDV flow with updates on the user's progress at each point.
                                            • [claimed-docs] In Sandbox mode, Identity Verification accepts the fixed set of inputs below in order to result in successful Data Source and Documentary Ve…

                                          No code

                                          1. ops leadSend a verification to someone with a no-code link or QR code — no engineering ticket to verify a one-off customer, contractor, or seller

                                            weight 2 · round to Plaid Identity Verification
                                            Sumsubnone0/10

                                            The evidence pack covers APIs, SDKs, webhooks, verification levels, AML screening, and an MCP server, but contains no mention of a no-code shareable verification link or QR code that an ops person could generate and send without engineering involvement.

                                              Plaid Identity Verificationpartialclaimed3/10

                                              Plaid documents a no-code editor for building verification flows and a Dashboard for managing sessions, suggesting some non-engineering control, but there is no explicit evidence of an ops-facing feature to generate a shareable verification link or QR code for a one-off customer/contractor without engineering involvement. Missing for 10: explicit dashboard 'send link/QR code' feature, evidence of ops-only workflow without developer setup, and confirmation that Link integration isn't required for a single verification.

                                              • [claimed-docs] No-code editor to create and change verification flows
                                              • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…

                                            Reuse

                                            1. developerA person verified once can be recognized and reused across sessions or products — documented re-verification and reuse of a prior passed check instead of forcing a full re-run

                                              weight 2 · round to Sumsub
                                              Sumsubfullclaimed8/10

                                              Sumsub explicitly documents Reusable KYC, letting clients share verification data via agreement with other Sumsub clients so applicants can reuse a prior passed check instead of re-running full verification. This directly matches the story's theme of recognizing and reusing a verified identity across products/sessions. Missing for 10: no independent/hands-on corroboration of reuse working across separate live products, and no detail on cross-session recognition mechanics (e.g., token/session persistence) beyond the Reusable KYC agreement model.

                                              • [claimed-docs] With Reusable KYC, you can conclude an agreement with other Sumsub clients to share verification data, and enable applicant data reuse to co…
                                              Plaid Identity Verificationnone0/10

                                              The evidence pack covers verification checks, workflows, webhooks, sandbox testing, and dashboard overrides, but nowhere documents a mechanism to recognize a previously verified user and reuse a passed check across sessions or products instead of re-running verification.

                                              Verification orchestration — stories about verification orchestration in this arenaVerification orchestration

                                              Stories about verification orchestration in this arena

                                              Analytics

                                              1. founderSee verification funnel analytics — pass rates, drop-off points, completion time by country and document type — to know what verification is costing me in signups

                                                weight 2 · round to Plaid Identity Verification
                                                Sumsubnone0/10

                                                The evidence pack covers API, webhooks, verification levels, AML, liveness, MCP server, and account management, but contains no mention of analytics dashboards, funnel/pass-rate reporting, drop-off analysis, or completion time breakdowns by country/document type.

                                                  Plaid Identity Verificationpartialclaimed4/10

                                                  Plaid documents a 'reporting' page defining conversion rate (session completion rate) and a Dashboard showing per-session risk scores, implying some analytics exist, but there is no evidence of drop-off-point analysis, completion-time metrics, or breakdowns by country or document type. missing for 10: drop-off funnel visualization, completion-time-by-country/document-type metrics, independent confirmation of dashboard analytics depth.

                                                  • [claimed-docs] The conversion rate is defined as the percentage of sessions begun that were completed, regardless of whether the user passed or failed veri…
                                                  • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…

                                                Review

                                                1. ops leadBorderline verifications land in a manual review queue with the full evidence — document images, extracted fields, check results — and reviewer decisions feed back into the record

                                                  weight 2 · round to Plaid Identity Verification
                                                  Sumsubpartialclaimed4/10

                                                  Sumsub's docs show applicant profiles where reviewers can inspect check results (e.g., liveness section) and levels aggregate document/selfie/liveness checks, implying some review workflow, but there is no explicit documentation of a dedicated manual review queue for borderline cases or of how reviewer decisions are written back into the applicant record. missing for 10: explicit manual review queue feature docs, description of extracted-field/document display in review UI, evidence that reviewer decisions feed back into verification status/record.

                                                  • [claimed-docs] Open the Applicants page and select an applicant who passed the Liveness check. In the profile, navigate to the Liveness section and review …
                                                  • [claimed-docs] A level is a sequence of steps that your applicants have to take to verify their identity. Each level may include document-based or selfie-b…
                                                  Plaid Identity Verificationpartialclaimed5/10

                                                  Docs confirm a Dashboard-based review path — failed verifications can be manually overridden and each session shows risk assessments and status updates via webhooks — implying some human-in-the-loop review, but there is no explicit description of a dedicated 'manual review queue' surfacing document images/extracted fields for borderline cases, nor documented mechanics for how reviewer decisions are recorded back into the verification record beyond a simple override click. missing for 10: explicit manual review queue UI, evidence bundling (docs+fields+checks) presented together for review, and documented reviewer-decision audit trail feeding back into the record.

                                                  • [claimed-docs] you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.
                                                  • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…
                                                  • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
                                                  • [claimed-docs] The conversion rate is defined as the percentage of sessions begun that were completed, regardless of whether the user passed or failed veri…

                                                Workflows

                                                1. ops leadConfigure verification logic without code — conditional steps, risk-based routing, country-specific requirements, and template changes that don't need an engineering deploy

                                                  weight 3 · round to Plaid Identity Verification
                                                  Sumsubpartialclaimed5/10

                                                  Docs confirm verification 'levels' as configurable sequences of steps with many check types and adjustable AML screening settings, implying dashboard-based configuration rather than code changes (sumsub-docs-5, sumsub-docs-6). However, there is no explicit evidence of conditional branching logic, risk-based routing rules, or country-specific requirement templates being configurable without an engineering deploy. Missing for 10: explicit no-code workflow/conditional-logic builder documentation, evidence of risk-based routing configuration, and country-specific rule templates managed purely via UI without deploys.

                                                  • [claimed-docs] A level is a sequence of steps that your applicants have to take to verify their identity. Each level may include document-based or selfie-b…
                                                  • [claimed-docs] Configure your AML screening settings to suit your needs by screening against targeted lists and categories that are relevant to your busine…
                                                  • [claimed-docs] Instantly verify 14,000+ document types from 220+ countries and territories.
                                                  Plaid Identity Verificationfullclaimed8/10

                                                  Plaid's docs explicitly describe a no-code Workflow Management editor for building templates, combining conditional checks (run only if another fails or is high-risk), and country-based routing, plus a dashboard for overrides and risk scoring—matching the ops-lead story closely. missing for 10: independent/hands-on validation of the no-code editor's actual usability and confirmation that template changes deploy without any engineering involvement in practice.

                                                  • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…
                                                  • [claimed-docs] No-code editor to create and change verification flows
                                                  • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…
                                                  • [claimed-docs] you can override a failure via the Dashboard by clicking the Override Result button on the verification detail page in the Dashboard.

                                                Watchlist screening — stories about watchlist screening in this arenaWatchlist screening

                                                Stories about watchlist screening in this arena

                                                Monitoring

                                                1. ops leadScreening is not one-shot — previously verified users are continuously re-screened against watchlist updates, and changes raise events I can act on

                                                  weight 2 · round to Sumsub
                                                  Sumsubpartialclaimed5/10

                                                  Sumsub documents configurable AML/watchlist screening (sumsub-docs-6) and a generic webhook system for verification-related events and changes (sumsub-docs-3), which together imply an ops lead could be notified of screening changes, but the evidence never explicitly confirms ongoing/continuous re-screening of already-approved applicants against watchlist updates or that such updates specifically fire webhook events. Missing for 10: explicit documentation of automated periodic re-screening post-approval, and confirmation that watchlist-update hits generate a distinct actionable event/webhook type.

                                                  • [claimed-docs] Configure your AML screening settings to suit your needs by screening against targeted lists and categories that are relevant to your busine…
                                                  • [claimed-docs] Sumsub’s Webhooks is a tool that allows you to automatically receive notifications for various events and changes related to your applicants…
                                                  Plaid Identity Verificationnone0/10

                                                  Plaid IDV's webhooks (STEP_UPDATED, STATUS_UPDATED, RETRIED) fire during a verification session's flow, not as ongoing re-screening of already-verified users against new watchlist hits. The docs explicitly point to a separate product, Plaid Monitor, for continuous monitoring/KYC, implying IDV itself does not perform continuous re-screening.

                                                  • [claimed-docs] For Identity Verification, there are three events: STEP_UPDATED, STATUS_UPDATED, RETRIED
                                                  • [claimed-docs] Monitor also integrates directly with Identity Verification for an end-to-end verification and KYC solution.

                                                Screening

                                                1. ops leadScreen verified users against sanctions, PEP, and adverse-media watchlists as part of the same verification — one vendor, one API, one review surface

                                                  weight 2 · round to Sumsub
                                                  Sumsubfullclaimed8/10

                                                  Sumsub documents configurable AML screening (sanctions, PEP, adverse media implied by 'categories') integrated into the same verification flow/API and reviewable via the applicant profile alongside other checks, all under one platform. Missing for 10: explicit mention of adverse-media list coverage and independent/hands-on corroboration of screening accuracy or review UI beyond docs.

                                                  • [claimed-docs] Configure your AML screening settings to suit your needs by screening against targeted lists and categories that are relevant to your busine…
                                                  • [claimed-docs] A level is a sequence of steps that your applicants have to take to verify their identity. Each level may include document-based or selfie-b…
                                                  • [claimed-docs] Open the Applicants page and select an applicant who passed the Liveness check. In the profile, navigate to the Liveness section and review …
                                                  • [claimed-docs] With the Sumsub API, you can process the applicant data and documents submitted for verification through simple RESTful APIs.
                                                  Plaid Identity Verificationpartialclaimed5/10

                                                  Plaid's docs show that its separate Monitor product 'integrates directly with Identity Verification for an end-to-end verification and KYC solution,' implying sanctions/PEP/adverse-media screening is available from the same vendor, but the evidence never describes this as a single unified API call or review surface — it reads as two distinct products stitched together rather than one seamless verification session. Missing for 10: explicit documentation of sanctions/PEP/adverse-media screening as a native check within the IDV template/workflow itself, unified webhook/events covering watchlist results, and independent confirmation of a single review surface across both products.

                                                  • [claimed-docs] Monitor also integrates directly with Identity Verification for an end-to-end verification and KYC solution.
                                                  • [claimed-docs] You can combine multiple verification checks within a single Identity Verification template via the Workflow Management editor, and even run…
                                                  • [claimed-docs] Identity Verification will also display a set of granular risk assessments (email risk, phone risk, etc.) in the Dashboard for each session,…

                                                Not comparable on these axes

                                                1. ai-native userPlug MCP servers into this product so it can use their tools

                                                  weight 3 · not comparable
                                                  Sumsubn/a

                                                  Sumsub is a KYC/verification SaaS platform, not an AI agent or assistant runtime; the evidence only shows Sumsub exposing its own MCP server for other agents to consume (docs-4, probe-3), which is the reverse role from 'plugging MCP servers into this product.' There is no agentic client capability in Sumsub itself that could consume external MCP servers, making this axis a category error for this product type.

                                                  • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
                                                  • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
                                                  Plaid Identity Verificationn/a

                                                  Plaid Identity Verification is a verification/KYC SaaS API, not an AI agent or assistant that itself consumes external tools via MCP; the evidence shows Plaid offers an MCP server (docs/resources/mcp) exposing its own APIs, which is the reverse (server) role, not the client-side 'plug MCP servers in so it can use their tools' capability this story asks about. This axis is a category error for a non-agentic verification product.

                                                  • [probe] official MCP server documented at https://plaid.com/docs/resources/mcp/
                                                2. ai-native userDelegate tasks to a built-in AI assistant inside the product

                                                  weight 3 · not comparable
                                                  Sumsubnone0/10

                                                  Evidence only shows an MCP server that lets external AI agents call Sumsub operations, which is the reverse of a built-in AI assistant that users delegate tasks to inside the product. No evidence of an in-product AI assistant/copilot for end users.

                                                  • [claimed-docs] Use the MCP server to let AI agents perform Sumsub operations on your behalf, while keeping access controlled by your existing Sumsub role p…
                                                  • [probe] official MCP server documented at https://docs.sumsub.com/docs/mcp-server
                                                  Plaid Identity Verificationn/a

                                                  Plaid Identity Verification is a backend identity-verification/KYC API and dashboard product, not an AI assistant or agentic interface; delegating tasks to a built-in AI assistant is a category error for this type of product. Evidence shows no-code workflow editor and dashboard tools, not any conversational/agentic assistant.

                                                  • [claimed-docs] No-code editor to create and change verification flows
                                                3. ai-native userSchedule recurring jobs or workflows

                                                  weight 2 · not comparable
                                                  Sumsubnone0/10

                                                  Sumsub's evidence covers APIs, webhooks, sandbox testing, and an MCP server for AI agents, but nothing describes a scheduling mechanism for recurring jobs or workflows (e.g., cron-like triggers, periodic re-verification automation). Missing for 10: any documented scheduler, recurring job configuration, or workflow automation engine.

                                                    Plaid Identity Verificationn/a

                                                    Plaid Identity Verification is a KYC/identity verification API/dashboard product, not an automation or workflow-scheduling platform; scheduling recurring jobs is outside its category (webhooks for event-driven updates exist, but not user-initiated recurring job scheduling).

                                                    • ai-native userVersion, review, and roll back my automations

                                                      weight 1 · not comparable
                                                      Sumsubnone0/10

                                                      Sumsub's evidence covers verification levels, AML screening, webhooks, and an MCP server for agent operations, but nothing addresses versioning, reviewing, or rolling back automations/workflows (e.g., verification level configs or rule changes). No changelog, version history, or rollback mechanism is documented anywhere in the pack.

                                                        Plaid Identity Verificationn/a

                                                        This story concerns versioning/reviewing/rolling back AI-agent automations, which is not applicable to Plaid Identity Verification, an identity-verification API/workflow product for developers, not an AI automation builder.

                                                        • ai-native userRead the product's source under an open license

                                                          weight 2 · not comparable
                                                          Sumsubn/a

                                                          Sumsub is a closed-source SaaS identity verification platform; there is no open-source codebase to read. Source-availability/licensing is not a relevant axis for this kind of product.

                                                            Plaid Identity Verificationn/a

                                                            Plaid Identity Verification is a closed-source commercial SaaS API; open-sourcing product source code is not a plausible axis for this kind of product and no evidence suggests otherwise.

                                                            • ai-native userSelf-host the core product

                                                              weight 3 · not comparable
                                                              Sumsubn/a

                                                              Sumsub is a cloud-based identity verification/KYC SaaS platform; self-hosting the core verification engine is not offered or implied anywhere in the evidence, and this is a category error for a compliance SaaS product relying on centralized data processing and hosted infrastructure.

                                                                Plaid Identity Verificationn/a

                                                                Plaid Identity Verification is a hosted SaaS/API product with no self-hosted deployment option; self-hosting the core product is a category error for this type of cloud identity-verification service.