FAQ

Questions, answered

How Fidera runs your compliance program — and what that looks like in practice.

Can Fidera enforce our CIP and compliance policy?

Yes. Your Customer Identification Program, KYC, and AML rules become configurable verification flows, risk tiers, and decisioning logic — including non-documentary checks and step-up for higher-risk cases. Every decision is logged to an append-only audit trail mapped to the requirement it satisfies, ready for examiners.

Can automated or agent-driven flows run verification through the API?

Yes — Fidera is API-first, and everything the hosted flow does is available as REST endpoints your backend or automated onboarding flow can drive directly. The verification itself still binds the account to a real person: the account holder completes the document, face match, and liveness steps, so every account an agent operates ties back to a verified legal identity, with each decision returned in seconds and logged to the audit trail.

We're a stablecoin platform — what do you cover?

Customer screening against sanctions, OFAC, PEP, and watchlists at onboarding; wallet-address screening against OFAC and global sanctions lists before funds move; and Travel Rule data exchange with counterparty VASPs per FATF guidance. As US issuers take on formal federal compliance obligations, we map these checks to the requirements in your program — your counsel defines the policy, Fidera operationalizes it.

How does the shareable model work?

With explicit, revocable consent, a person verified at one tenant can be reused at the next with a quick liveness re-check instead of a full document upload. Every reuse is logged to the same audit trail and honors GDPR and CCPA rights, and it costs a fraction of a fresh verification.

How do you stop deepfakes and spoofed selfies?

The biometric path pairs active-liveness presentation-attack detection with face match to the document portrait, plus deepfake and face-morph checks, so a photo, replay, or synthetic face is rejected before a decision.

What's your security and compliance posture?

Fidera's controls are designed and operated in line with the SOC 2 Trust Services Criteria, and a formal SOC 2 audit is planned. Data is protected with AES-256 encryption at rest and TLS 1.2+ in transit, with GDPR and CCPA alignment. A summary of our controls and sub-processors is available on request.

How long does integration take?

Drop in a hosted flow in an afternoon, or drive the REST API directly from your backend or automated onboarding flow via the web, iOS, or Android SDK. Signed webhooks and idempotency keys are on the near-term roadmap. A free sandbox ships test fixtures for every document type.

Still have questions? Book a 30-minute walkthrough — no sales pressure.