Trust CenterUpdated August 2026

Trust, made inspectable.

See how Candour combines certified assurance, independent face-matching evaluation and standards-compliant controls to protect remote identity verification against modern fraud.

02current certifications
FRTE 1:1externally evaluated face matching
EU/EEAstandard SaaS processing region

Precise by design

One word can change a claim.

Certified

Assessed against a defined scheme by an independent or accredited party.

Externally evaluated

A defined algorithm was tested by an independent public benchmark under a common protocol.

Compliant / aligned

Applicable requirements are implemented or mapped for the product and service scope stated here.

Verified assurance

Independent evidence. Compliant controls.

Two current certifications and one independent NIST evaluation provide distinct evidence across organisational security, end-to-end face verification and biometric matching.

Certified Organisational assurance

Information security management

Candour operates an ISO/IEC 27001:2022-certified Information Security Management System for biometric person identity verification services and supporting functions.

  • Risk and asset management
  • Access control and secure development
  • Supplier, incident and continuity management
  • Ongoing surveillance and improvement
Certified Product assurance

FIDO® Identity Verification · Face Verification

FIDO IDV Type 1
Level 1 v4.0

Candour-Biometrics v1.4.0 was independently evaluated by TÜV Informationstechnik GmbH. FIDO’s scenario-based programme exercises the complete selfie-to-document face verification flow through at least 10,000 tests.

  • Deepfakes & spoof mediaPrint, screen, replay, mask and synthetic-face attack species
  • Passive liveness / PADEvidence that the user is genuine and present in real time
  • Demographic performanceBias analysis across skin tone, age and gender
  • Biometric matchingSelfie-to-ID accuracy measured through FAR and FRR
  • Injection resistanceCapture-bypass attempts using prior or synthetic image and video data
FAR
0.00%
FRR
4.40%
IAPAR
1.76%

Results apply to the certified test setting. Certificate IDV100020241213001 · valid through 24 January 2028.

Externally evaluated Independent US government benchmark

NIST FRTE 1:1 · formerly FRVT

Face matching tested at scale.

Candour’s candour-004 face recognition algorithm was evaluated by the US National Institute of Standards and Technology under its ongoing one-to-one verification protocol. The Visa–Border scenario is particularly relevant to remote identity verification because it compares document-style portraits with border-capture images.

FNMR at FMR 10−6 0.003 Visa ↔ Border
Application0.00%
Border0.00%
Kiosk0.00%
Mugshot0.00%

Failure to Enrol (FTE) across all four reported datasets · candour-004 · NIST report dated 31 July 2026.

Trust at every layer

Protection follows the identity journey.

No single control carries the whole system. Candour combines capture safeguards, verification signals, data controls and operational governance.

  1. 01

    Capture provenance

    Session binding, freshness checks, payload integrity, secure transport and anti-replay controls preserve the link between the device capture and the backend decision.

    Provenance
  2. 02

    Certified identity evidence

    Document checks, ICAO-compliant NFC/eMRTD validation, NIST-evaluated 1:1 face matching and FIDO-certified passive liveness/PAD can be combined for the required evidence route.

    Binding
  3. 03

    Modern-attack resistance

    Deepfake and presentation-attack detection are reinforced by CEN/TS 18099-aligned controls for injected video, virtual cameras, emulators, runtime integrity, sensor coherence and replayed genuine media.

    Resilience
  4. 04

    Operational assurance

    The certified ISMS provides the governance foundation for access, risk, suppliers, incidents, continuity, monitoring and continuous improvement.

    Governance

Standards & regulation map

The framework—and our position.

This map shows where Candour is certified, externally evaluated, compliant or aligned. The stated position applies to the named controls and service scope.

Framework Why it matters Candour position
ETSI EN 319 401 A principal eIDAS trust-services standard covering policy, security, service operation and trustworthy electronic transactions. Compliance alignmentCandour aligns its service policies and architecture with ETSI EN 319 401 through secure data protocols, encryption in transit and at rest, risk and access controls, auditability, business continuity and interoperable integration patterns for eIDAS 2.0 ecosystems.
ETSI TS 119 461 Policy and security requirements for identity proofing used as a trust-service component. Conformity alignmentThe identity-proofing flow implements requirements for evidence collection, biometric binding, liveness, attack resistance, secure processing, traceability and auditable decisions to support compliant trust-service deployments.
CEN/TS 18099:2024 Evaluation of biometric data injection attacks that bypass or manipulate the capture channel. Conformity implementationCandour implements live and release-stage IAMDM/IAIDM controls aligned to its requirements: secure messaging, capture provenance, app and device integrity, virtual-camera and emulator detection, passive liveness, deepfake detection, motion analysis and multi-sensor coherence.
ICAO Doc 9303 Machine-readable travel documents, NFC chip data and document PKI. Compliant capabilityNFC/eMRTD reading, data-group integrity and PKI validation implement applicable ICAO Doc 9303 structures and validation requirements.
ISO/IEC 19795 & 30107 Biometric performance measurement and presentation attack detection testing and reporting. Certified evidenceThe FIDO IDV Type 1 Level 1 v4.0 evaluation applies the relevant performance and mobile PAD profiles to matching, bona fide use and presentation-attack resistance.
eIDAS 2.0 European digital identity, EUDI Wallets and trust-service requirements. Compliance-readyCandour provides compliant building blocks for high-assurance evidence routes, EUDI Wallet onboarding and interoperable trust-service integrations, with deployment evidence mapped to the complete scheme.
GDPR & UK GDPR Lawful, transparent and secure handling of identity and biometric data. Compliant programmePrivacy-by-design, data minimisation, DPAs, restricted access, encryption, configurable retention and deletion controls support GDPR-compliant identity verification.
EU AI Act AI governance, data quality, transparency, robustness and oversight. Compliance programmeRisk management, performance and fairness monitoring, technical documentation, human oversight and security practices support compliant use in the applicable customer context.
NIS2 & Cyber Resilience Act Risk governance, resilience and secure software lifecycle expectations. Compliance readinessISO 27001-governed risk, vulnerability, incident, supplier, continuity and secure-development processes support NIS2- and CRA-compliant deployments.
ETSI EN 301 549 & WCAG 2.2 AA Accessible digital services and user-facing verification flows. Fully compliantCandour’s user-facing verification flow fully complies with WCAG 2.2 AA and applicable ETSI EN 301 549 requirements, including assistive-technology support, scalable text, AA contrast, reduced motion and passive liveness without flashing prompts.

Compliance descriptions apply to the stated Candour controls and service scope. Certificates, external results, control mappings and deployment-specific evidence are available through the customer assurance process.

Data protection & deployment

Control the route your data takes.

In the standard EU SaaS configuration, processing takes place in EU/EEA data centres. Private-cloud, on-premises, hybrid and regional options can be agreed where data residency, sovereignty or certification requirements call for a different model.

Read our privacy policy
Candour Identity
verification
StandardEU SaaS
Customer-specificPrivate cloud
Customer-controlledOn-premises
CombinedHybrid
01

Purpose & minimisation

Data collection and processing are limited to the agreed verification purpose and customer configuration.

02

Protection

Sensitive data is protected in transit and at rest, with access restricted through least-privilege controls.

03

Retention

Retention is configurable by data category and customer requirement, subject to applicable legal obligations.

04

Accountability

DPAs, sub-processor information, data-flow material and customer-specific processing plans are available.

Questions worth asking

Trust should survive scrutiny.

These answers define the boundaries behind the headline claims. For a customer-specific assessment, ask us for the applicable evidence set.

Which claims are independently verified?

ISO/IEC 27001:2022 and FIDO IDV Type 1 Level 1 v4.0 are current certifications. NIST FRTE 1:1 is an independent government evaluation of Candour’s face-matching algorithm. The standards map identifies compliant controls, conformity implementation and alignment within each stated scope.

Can Candour support high-assurance identity proofing?

Candour combines ICAO-compliant NFC/eMRTD validation, biometric binding, certified passive liveness/PAD, capture-channel defences and auditable decisions to support high-assurance evidence routes. The evidence package maps these controls to the policy, integration and conformity scope of each deployment.

What protects against deepfakes and injection attacks?

FIDO-certified testing covers deepfakes, liveness, biometric matching, bias and injection resistance. Candour complements content analysis with CEN/TS 18099-aligned capture-channel controls, including secure messaging, session freshness, app and device integrity, virtual-camera and emulator detection, micro-motion analysis and multi-sensor coherence across live and release-stage capabilities.

What assurance material can customers review?

Depending on scope and confidentiality, Candour can provide certificates, supporting evaluation material, architecture and data-flow documentation, DPA and sub-processor information, control mappings, accessibility material and security policies. Sensitive evidence may require an NDA.

How does Candour approach biometric fairness?

The FIDO evaluation includes demographic testing and bias analysis across skin tone, age and gender. Candour reinforces this independent evidence with ongoing performance and fairness monitoring at the relevant operating thresholds.

Who is responsible for regulatory compliance?

Candour documents service responsibilities in the DPA and deployment scope. We provide GDPR-compliant controls, security and data-flow evidence, standards mappings and customer-specific processing documentation for the complete assurance review.

Assurance is contextual

Match the evidence to your risk.

Tell us your market, evidence route, deployment model and assurance target. We will provide the applicable certificates, NIST results, compliance mappings and implementation evidence.