The statistics landed quietly in a January fraud report, but their implications weren't subtle: Sumsub's annual analysis of identity fraud documented a shift from simple document forgery to complex multi-step schemes, with AI-generated documents representing a growing threat. The forgeries are getting better. Fast.
Into that uneasy moment steps Didit, a San Francisco outfit barely two years old, backed by Y Combinator and staffed by—of all things—a pair of former professional tennis players turned technologists. On March 2, the company launched the third version of its identity verification platform with a pointed thesis: when documents can be convincingly faked by algorithms, maybe the face should come first.
It's a gamble on what the founders see as an inevitable shift. "Document verification is still critical," CEO Alberto Rosas said in a recent company update, "but we think liveness and face matching need to be the default starting point." Whether that conviction holds up against increasingly sophisticated attacks remains an open question.
The All-in-One Pitch
Didit's platform bundles the usual KYC machinery—ID document checks, anti-money laundering screening, proof of address, phone and email verification—but leads with biometric validation. Passive liveness detection (the kind that doesn't ask users to blink or turn their head) pairs with one-to-one face matching against submitted documents. The company claims support for IDs from over 230 countries and territories across 130-plus languages, with extras like NFC chip verification for passports and national ID cards.
The v3 release introduced node-based workflow orchestration, essentially visual decision trees that let companies route users through different verification gauntlets based on risk scores, geography, or transaction value. A marketplace might verify sellers with stricter checks than buyers. A crypto exchange could escalate to document verification only when a withdrawal crosses a certain threshold. It's the kind of granular control that matters when regulatory requirements vary by jurisdiction—or when you're trying to balance fraud prevention against user abandonment rates.
There are native SDKs for the standard mobile platforms, plus plugins for Shopify and WordPress that went live in February. More unusual: an MCP server for AI agent integration, anticipating a future where identity checks happen programmatically, without any human clicking through verification screens. Whether that future arrives soon enough to matter is anybody's guess.
Free Tier Economics

Here's where Didit makes its most assertive move: 500 free verification checks per month, covering ID review, face matching, passive liveness, and IP analysis. Beyond that, pricing runs à la carte—15 cents for ID verification, a dime for passive liveness, a nickel for face matching, three cents for IP checks.
For early-stage startups or platforms testing identity requirements for the first time, that's non-trivial volume. Didit told Y Combinator it's processing "millions of humans every month" through roughly 700 active business customers as of February, claiming 20% month-over-month growth and 90% retention among paying clients after six months. The numbers suggest product-market fit, though at this stage it's still early to tell whether the company can scale into the enterprise contracts that typically define this market.
The free tier also functions as customer acquisition in a space where procurement cycles can drag on for months. Get developers hooked on the API, let them build product flows around it, and the budget conversation follows naturally.
The Fraud Arms Race
The timing feels deliberate. Sumsub's latest report, covering 2025 into early 2026, documented what researchers called a shift from "simple document forgery to complex multi-step schemes." AI-generated documents still represent a small slice of the fraud pie, but the trajectory worries platform operators. Jumio added premium liveness detection mid-2025 specifically to counter deepfakes and injection attacks—where fraudsters feed pre-recorded videos or synthetic imagery into verification systems.
On the same day Didit launched v3, Incode announced it had achieved iBeta's highest Level 3 presentation attack detection certification, a technical benchmark measuring how well liveness systems resist spoofing. Didit holds iBeta PAD Level 1 certification for its iOS biometric authentication as of early February—a credible baseline, though visibly a step behind what some competitors are advertising. The company also maintains ISO 27001:2022 certification through Bureau Veritas, valid through mid-2027.
Then there's the Discord situation, which probably did more to raise awareness of identity verification vendors than any white paper could. The platform faced sharp user backlash over its age verification approach, eventually severing its relationship with its chosen partner by late February. Public sensitivity around who handles biometric data is real, which makes Didit's accessible pricing and self-serve model perhaps more relevant than the company initially anticipated. If platforms want to avoid vendor lock-in or minimize dependence on a single identity provider, an API-first approach with no minimum spend looks more attractive.
The Tennis Players Turned Founders

Alberto and Alejandro Rosas bring an unusual pedigree to enterprise software. Both played professional tennis before pivoting to technology—Alberto as an AI engineer, Alejandro with a focus on mathematics and backend infrastructure. The company, founded in 2023, raised approximately $2 million before entering Y Combinator's Winter 2026 batch, according to a December blog post. The team has since grown to a dozen people.
Whether athletic discipline translates to startup endurance is one of those unprovable founder narratives, but the brothers have managed to ship a platform with meaningful traction in a crowded market. That counts for something.
What Comes Next
Identity verification is transitioning from optional friction to essential infrastructure. Regulatory pressure is mounting—age verification mandates, KYC requirements for financial services, platform liability for fraud losses. The question facing most platforms isn't whether to implement verification, but how fast, at what cost, and with what degradation to user experience.
Didit's face-first approach with generous free-tier economics positions the company squarely in the path of marketplaces, fintech apps, and social platforms that need verification but lack the budget or patience for enterprise sales cycles. The vulnerability, of course, is whether passive liveness and Level 1 PAD certification can withstand the next wave of attack sophistication. And whether the workflow orchestration and global document coverage prove robust enough when regulators come knocking.
For now, the company has assembled the signals investors look for: millions of monthly verifications, customer growth, retention above 90%. The market tailwind from surging fraud doesn't hurt. The demo center is live at demos.didit.me, and the free tier makes it trivially easy for technical teams to kick the tires without a procurement process.
The real test, as always, comes when the fraudsters get smarter. They always do.
