Skip to main content

Travel Rule for Crypto Transfers

When your users send or receive crypto, regulators increasingly require you to exchange sender and recipient details with the counterparty institution before the transfer settles. Didit now handles that end to end.
  • Encrypted information exchange — sender and recipient details are exchanged automatically using IVMS 101, the industry data standard, with encrypted payloads
  • Broad interoperability — Didit routes each transfer over the counterparty’s preferred network and includes a native implementation of the open TRP messaging standard
  • Secure email fallback — when a counterparty isn’t reachable on any network, Didit sends a protected pickup link so the transfer still gets compliant treatment
  • Counterparty directory and address book — find virtual asset service providers (VASPs) in a directory seeded from the EU’s official register of authorized crypto-asset providers, then save and reuse tagged wallet addresses
  • Self-custody ownership proof — a white-labelled widget lets users prove control of their own wallet by signature (or screenshot proof where you allow it) across Ethereum-compatible networks, Solana, Bitcoin, and Tron — connecting any major wallet, including by QR code
  • Ready-made EU rules — start from a preset bundle for the EU Transfer of Funds Regulation, and set your jurisdiction: EU, UK, Switzerland, Singapore, US, or UAE
  • Due diligence and timeouts — every counterparty gets a due-diligence score that can gate a transfer, and you choose what happens when a confirmation deadline passes
  • Built-in testing and events — create sample transfers in the Console, track usage, and receive a webhook for each status change

Didit Copilot in the Console

Didit Copilot helps you operate the Business Console from every page while keeping you in control of consequential actions.
  • Ask from anywhere — open the resizable Copilot panel from the Ask pill in the Console header and get starting prompts tailored to the page you are viewing
  • Build and navigate for you — create workflows, apply list filters, and open the right dialogs through natural-language requests
  • You approve every change — anything that writes or deletes waits for your explicit confirmation
  • Watch the work happen — see workflow blocks appear node by node, and stop the Copilot whenever you need to
  • Talk, type, or attach — use voice input, add a file, and return to searchable conversation history that resumes after a dropped connection

ID Verification Data Review

A new applicant review step lets users confirm or correct extracted identity-document fields before they submit.
  • Review in every language — applicants can check standard and document-specific fields in every supported language, including flows that also use chip reading
  • Actions by mismatch severity — configure separate outcomes for critical and minor corrections while protecting fields validated by the document’s machine-readable zone (MRZ) from edits
  • Complete correction history — session details show each original value beside the applicant-confirmed value
  • Capture quality check — optionally let applicants inspect and retake the cropped document image before submitting; this screen appears only for camera scans
Applicant reviewing and correcting extracted document data before submitting

Test Mode

Sandbox applications now provide a complete Test mode for exercising integrations without contacting external providers.
  • Choose the result first — pick approved, declined, or in review, including review scenarios for individual feature groups
  • Test more paths quickly — run business-verification registry scenarios, upload sample documents with one tap, and enter any one-time password (OTP) code
  • Clear in every surface — persistent banners identify Test mode in both the verification flow and the Console, while API keys carry environment badges
  • Visible simulated usage — zero-price activity remains in usage tables, and mocked sections carry simulated-data chips
  • Real captures, mocked results — captured media stays available for realistic review while extracted data remains synthetic
  • Integration-ready scenarios — no external provider is ever called, your automated tests can assert the armed scenario (returned as sandbox_scenario in the v3 decision payload), and native SDKs support Test mode from version 4.2.0

Device & Capture Integrity

New device and capture signals help you respond to tampered apps, emulators, and manipulated camera input without adding friction for legitimate users.
  • Operating-system attestation — verify app and device integrity with Apple App Attest and Google Play Integrity
  • Capture integrity signals — detect frame injection and show the attack subtype on face-attack warnings
  • Virtual-camera flag — mark sessions that present a virtual or external capture device as a risk signal
  • Actions per workflow — decline, review, or record device and capture risks according to each workflow’s policy
  • Safe outage behavior — configuration outages on Didit’s side do not decline legitimate applicants, and risk reasons are translated
  • Escape from in-app browsers — users in chat apps’ built-in browsers get a clear screen for reopening camera steps in their main browser
Hardware-backed device attestation and capture integrity signals

Workflow Builder Upgrades

The workflow builder now supports richer branching, clearer controls, and safer version management.
  • Merge and regional branches — bring branches back to one merge point, route by US state, and apply IP geofencing rules
  • More configurable actions — decide what happens when a phone number is flagged as high risk, when the same face appears under a different name, or when a database check does not apply
  • Recorded chip-read outcomes — see the specific reason when near-field communication (NFC) is skipped
  • More KYB control — configure registry fields and VAT actions, toggle beneficial owner (UBO) and shareholder collection, and accept business licences or tax registration certificates
  • True version recovery — delete drafts and restore earlier versions for both workflows and questionnaires
  • Clearer build decisions — see each step’s price and a warning when file upload reduces forgery protection compared with camera capture
  • Safer standalone checks — document liveness now starts enabled for the standalone ID Verification API

Business Verification (KYB)

Business verification now collects the right registry and document information with less applicant effort across more markets.
  • EU VAT validation — validate VAT numbers through the EU’s VAT Information Exchange System (VIES)
  • Configurable company search — choose registry fields and prefill and lock both company name and registration number for applicant confirmation
  • Local documents in 103 countries — show familiar local document names and recognize business licences and tax registration certificates
  • Fewer false declines — accept notarial deeds more reliably and treat user-entered information as the source of truth
  • Document AI results in KYB — receive newly available extracted custom-document results in KYB payloads and the PDF report
  • Only enabled sections appear — keep disabled UBO, shareholder, registration-number, and contact sections hidden from applicants
  • Larger uploads — accept business, proof-of-address, and custom-document files up to 30 MB

Ongoing AML Monitoring for Users and Businesses

You can now manage ongoing anti-money laundering (AML) monitoring directly for each user or business.
  • Per-record controls and status — enable or disable monitoring from list rows and follow it in a dedicated column on the Users and Businesses tables, with screening categories explained inline
  • Know the impact first — see a cost estimate before enabling monitoring and automatically screen identities that have not been checked before
  • One record per identity — reuse a single monitored record instead of creating duplicates and duplicate charges
  • Transparent bulk jobs — process many records together and see explicit skip reasons for every record that could not be monitored

Transaction Monitoring: SDK Submission and Step-Up Remediation

Transaction monitoring now connects native submission, device intelligence, and biometric step-up remediation in one flow.
  • Submit from native SDKs — send transactions with device intelligence attached, and receive an action_required response whenever the user has to do something
  • One-selfie step-up — hold a flagged transaction while awaiting the user, then reuse the stored face for biometric remediation with one selfie and no document
  • Choose the remediation path — select a workflow or workflow group for user-action rules
  • Richer rule inputs — compare sender fields with receiver fields and use your custom lists in text rules
  • Faster list review — use verification-style filters with currency and asset icons across transaction lists

Verification Flow Experience

The verification flow is more reliable on real devices and clearer about what applicants need to do next.
  • Reliable auto-capture — removed capture deadlocks and false “too dark” messages while improving distance guidance
  • Better camera control — added pinch-to-zoom, localized rear-camera selection, iOS black-screen recovery, and clean camera release between document and face steps
  • Visible capture recovery — camera failures show a retry action, microphone access never blocks the camera, and the frame border provides live feedback
  • Clearer waiting screens — redesigned processing screens explain what is happening instead of leaving applicants guessing
  • Progress from start to finish — the Welcome screen shows estimated time, while the progress bar, completion screens, error screens, one-time-code entry, and phone input use refreshed designs
  • Clearer proof of address — show country and accepted languages, use canonical subtypes, and order document types by country, with Australia added to the per-country ordering

Native SDK Updates

Versions 4.0.9 through 4.5.3 brought the latest Didit capabilities to iOS, Android, React Native, and Flutter.
  • Transactions and wallet ownership — submit and retrieve transactions with automatic user actions, and run wallet-ownership proof natively
  • Test mode from 4.2.0 — use the scenario picker and sample documents directly in native integrations
  • Swift Package Manager support — integrate the iOS SDK through Swift Package Manager in React Native and Flutter while keeping CocoaPods support
  • Smaller Flutter variants — choose didit_sdk_core, didit_sdk_autodetection, or didit_sdk_nfc with the same Dart API and a smaller native footprint
  • Right-to-left and language coverage — use Arabic right-to-left layouts and Hebrew localization
  • Capture polish and stability — get image review by default, SMS OTP autofill, per-country document ordering, an unmirrored front camera, and more stable face capture on high-resolution Android cameras
Didit native SDK releases 4.0.9 through 4.5.3 for iOS, Android, React Native, and Flutter

Document Coverage & AI Extraction

We continued June’s extraction expansion with new documents, regions, and more precise field mapping.
  • New supported documents — added Australia’s Larrakia Nation ID Card and Northern Territory Proof of Identification Card, plus another Israeli ePassport variant
  • AI-powered extraction expanded again — added coverage for Israeli and Kyrgyzstani documents, German health insurance cards, New Jersey IDs, Pennsylvania commercial driving licences, and the British Columbia ID family
  • Canonical issuing regions — return a document’s state or province as ISO 3166-2 so you can distinguish regional documents without parsing text
  • More precise document controls — exclude the legacy Chilean carnet subtype and receive distinct Australian licence-number and card-number fields

Database Validation & Analytics

New analytics and validation behavior make it easier to evaluate coverage, speed, and real-world outcomes.
  • Coverage and latency widgets — compare match coverage and median and 95th-percentile response times by country and database
  • Flexible analytics views — expand coverage to a full-screen world map and let charts choose the right time grouping for the selected range
  • Cleaner catalog — low-coverage databases have been removed instead of returning consistently empty results
  • Regional validation updates — derive Spain DNI/NIE addresses from proof-of-address data, while India Aadhaar no longer requires organization onboarding
  • Clearer outcomes — incomplete requests return a clear validation error, and empty validation responses resolve to In Review instead of passing silently

Right-to-Left Languages & Translation Quality

Arabic, Hebrew, and document translations now feel consistent across both the Console and the verification flow.
  • Arabic and Hebrew coverage — use right-to-left Arabic layouts across the Console, Copilot, and verification flow, with Hebrew coverage throughout the flow
  • Reviewed labels and events — get improved proof-of-address and business-document names in Estonian, Slovak, Korean, Japanese, Chinese, Catalan, Portuguese, and other supported languages, plus translated event labels
  • Locale links stay respected — explicit language URLs keep the selected locale as you navigate

New Certifications

Two independent credentials to announce, both verifiable from our public Security & Compliance center.
  • SOC 2 Type 2 — an independent audit against the AICPA Trust Services Criteria confirmed that Didit’s security, availability, and confidentiality controls operated effectively over a five-month observation period (March–July 2026) — the operational follow-up to April’s Type 1. The report is available to customers under NDA
  • Certified for youth protection in Germany — Germany’s youth-protection self-regulator (FSM) certified that Didit’s Age Verification System reliably establishes a closed user group under Section 4(2) of the Interstate Treaty on the Protection of Minors (JMStV), so only verified adults reach age-restricted content
  • Every credential in one place — the docs gained a dedicated Certifications page listing every audit and attestation we hold, with dates and how to get each report — and we’re adding more all the time
Didit certifications — SOC 2 Type 2 and FSM youth-protection certification

Improvements

  • Reusable verification imports — imported individual and business sessions return the complete decision, with session_kind and shared_from_session fields so you can trace where a reused verification came from; existing v2 integrations are untouched
  • Use Didit inside your identity provider — identity providers can now delegate verification to Didit over OpenID Connect (with Pushed Authorization Requests and PKCE) and receive standards-based verified claims back
  • Reliable final webhooks — the webhook that closes out a session can no longer be lost, and signature validation now works consistently for events carrying dates and amounts
  • Sessions never get stuck — verifications stalled on a background step resume on their own, and session-list requests are answered once instead of twice
  • Balance safeguards — balances update in real time, and new billable work stops when an account has a negative balance
  • Questionnaire drafts — delete unpublished questionnaire versions cleanly
  • Accurate date and cost views — custom date ranges follow your local calendar and every cost-breakdown row has a complete label
  • True-to-device customization preview — preview every screen with the same proportions and presentation applicants see
  • Calmer Console updates — real-time changes patch lists in place, and the sidebar stays open while you navigate
  • Findable session warnings — the warnings filter adds search, collapsible groups, and per-group counts
  • Workflow-aware resubmission — the resubmit dialog is built from your actual workflow graph, including branches, so you re-request only the steps you need
  • Honest check states — checks that never ran show as “not evaluated”, disabled validations read “Not applicable”, and a skipped chip read states its reason
  • Sessions for existing users — search your users when creating a session and reuse their stored portrait
  • Account security — require a two-factor code to delete applications, recover accounts through identity-verified support, reset passkeys, protect sandbox applications from deletion, and keep application mode immutable
  • Longer, clearer invitations — invitations remain valid for 30 days, show when expired, and correctly match email addresses from providers that treat dots as optional
  • Organization-wide administration — owners and admins span every application, and the members page stays fast as teams grow
  • MCP server updated — supports the latest Model Context Protocol revision (2026-07-28) while remaining compatible with existing clients
  • Deploy-safe flow reloads — recover from a stale page after a deployment and continue the current session
  • Fewer false liveness rejections — borderline passive-liveness results are automatically double-checked before a decision is made
  • Smarter proof-of-address review — handle abbreviated or reordered names and respect printed expiration dates
  • More proof-of-address coverage — accept India driving licences as proof of address
  • Safer manual checks — run document liveness by default for individual checks started from the Console