Questions, answered
How Fidera runs your compliance program — and what that looks like in practice.
Can Fidera enforce our CIP and compliance policy?
Yes. Your Customer Identification Program, KYC, and AML rules become configurable verification flows, risk tiers, and decisioning logic — including non-documentary checks and step-up for higher-risk cases. Every decision is logged to an append-only audit trail mapped to the requirement it satisfies, ready for examiners.
Can automated or agent-driven flows run verification through the API?
Yes — Fidera is API-first, and everything the hosted flow does is available as REST endpoints your backend or automated onboarding flow can drive directly. The verification itself still binds the account to a real person: the account holder completes the document, face match, and liveness steps, so every account an agent operates ties back to a verified legal identity, with each decision returned in seconds and logged to the audit trail.
We're a stablecoin platform — what do you cover?
Pre-release APIs support customer and payment-party checks against configured sanctions, PEP, export-control, enforcement, and other watchlist topics; matching of designated wallet addresses; ongoing monitors; lookback batches; and hold decisions when required AML data is unavailable. Production coverage remains subject to licensed data and release validation. Payment-message extraction, behavioral transaction monitoring, Travel Rule messaging, SAR automation, and unsupported ownership coverage are not part of the current product.
How does the shareable model work?
With explicit, revocable consent, a person verified at one tenant can be reused at the next with a quick liveness re-check instead of a full document upload. Every reuse is logged to the same audit trail and honors GDPR and CCPA rights, and it costs a fraction of a fresh verification.
How do you stop deepfakes and spoofed selfies?
Configured biometric flows combine face matching with active-liveness evidence and fail closed when required server-side evidence is incomplete. Fidera does not currently publish an independently validated deepfake-detection performance claim.
What's your security and compliance posture?
Fidera's controls are designed and operated in line with the SOC 2 Trust Services Criteria, and a formal SOC 2 audit is planned. Data is protected with AES-256 encryption at rest and TLS 1.2+ in transit, with GDPR and CCPA alignment. A summary of our controls and sub-processors is available on request.
How long does integration take?
Drive the documented REST API from your backend or use the current iOS client. Unified AML checks support idempotency keys and signed webhooks. A production-equivalent customer sandbox and deterministic fixture catalog remain launch-gated work; contact us for an implementation assessment instead of relying on an unsupported timeline.
Still have questions? Book a 30-minute walkthrough.