Identity proofing with 360 Identities

Quick start

Boost client conversion while preventing fraud

Swiss identity proofing service provider (IPSP) through NFC chip reading for KYC workflows, onboarding, age assurance


Last update: 26 August 2026


Topics


Age assurance

Authentication server
Authorization server

Biometrics

Biometric passports

Cryptography

Device fingerprinting

Device onboarding

Digital fraud prevention

Digital identities

Digital onboarding CDD

E-banking access

Fraud intelligence

Identity and access management (IAM)

Identity proofing

Injection attack detection (IAD)

Liveness detection

NFC chip reading

Public Key Infrastructures (PKI)

Presentation attack detection (PAD)

Sole control

Transaction authentication

"360 Identities eliminates digital identity fraud by relying solely on the digital chip in an ID, rather than on its vulnerable physical surface. We create a biometric anchor that connects and protects people and devices, including AI agents."

Fully automated identity proofing compliant with ETSI standards.


360 Identities is fast (< 3 minutes) and fully automated ("self-service") without human interaction. It performs unattended remote digital identification through biometric chip capture under ETSI TS 119 461, AMLA's RTS on Customer Due Diligence and FINMA Circular 2016/7 Margins 32-39 ("Online identification").

Radio frequency identification (RFID) with NFC chip reading.


The Near Field Communication (NFC) protocol enables data exchange within a range of 4 cm and is set to become the new gold standard for remote identity proofing. Most passports worldwide have an NFC chip that can be read (here). By 2030, biometric chips will also feature in most Swiss and European ID cards.

Liveness detection with zero tolerance for fraud (APCER = 0%).


Instead of investing resources in AI-powered tools to detect fraud only after it has occurred, block attackers as early as during identity verification. Combine identity document checks with a liveness detection component to create a tamper-proof biometric anchor as a baseline across all your channels and devices.

Prevent fraud 100% by sorting out fake customers from day one.


We draw on best-in-class email intelligence and screen billions of fraudulent emails right at client origination. 360 Identities completely prevents identity fraud by relying solely on the digital chip in an identity document, and not its high-risk printed surface.

Use geolocation tools to avoid dealing with sanctioned regions.


Blind reliance on customer self-declarations no longer meets regulatory expectations. Verify both the customer's identity and their actual location by capturing the IP address. Spot discrepancies in location and ensure you don't provide goods or services to prohibited areas.

Authenticate people, their AI agents, and critical transactions.


360 Identities secures mission-critical transactions such as authenticating customers and AI agents, digital signatures, payments, and KYC workflows using a biometric baseline certified to ZertES and eIDAS - giving you the highest level of trust offered on the market.

Pricing models

Up to 1,000 identifications per year


CHF 4.00 per applicant


  • Minimum: CHF 1,200 p.a.
  • No monthly usage fee
  • No integration fee
Start integration

Up to 10,000 identifications per year


CHF 3.00 per applicant


  • Minimum: CHF 3,000 p.a
  • No monthly usage fee
  • No integration fee
Start integration

Over 10,000 identifications per year


CHF 2.00 per applicant


  • Minimum: CHF 6,000 p.a.
  • No monthly usage fee
  • No integration fee
Start integration

What is identity signal integrity


If it is indeed true that "personality is an unbroken series of successful gestures" (The Great Gatsby), then digital identity is an unbroken series of successful authentications and verifications between machines.


We believe that viewing digital identity as a continuous stream of trustworthy signals - rather than a one-time pass/fail check - is a more faithful implementation of the principles of the zero trust architecture.


Identity signal integrity is the confidence that the totality of identity attributes relating to the initiator of a digital transaction are trustworthy.


Identity signals include:


  • Network environment and IP address
  • Device fingerprint
  • Biometric identity
  • Login credentials
  • Authentication and session tokens
  • Expected user behaviour


What is the business context for identity proofing and how can you integrate


The business context for the identity proofing with 360 Identities could be the need to conduct an electronic transaction that requires strong customer authentication, such as when a user wishes to generate a qualified electronic signature (QES) on a digital signature platform such as 360 Signatures (here), also operated by 360core, in order to sign a contract with a signature equivalent to the handwritten signature, or open a bank account digitally.


In general, 360 Identities can be integrated into customer user journeys, business processes, and workflows in several ways:


  • Deeplink or QR code in a web or mobile application: The applicant is presented with a deeplink or QR code starting the identity proofing process including guidance for downloading 360 Identities on a common marketplace
  • App-to-App: if already installed, 360 Identities can be launched via a relying party's own app


360 Identities gives identity assurance


The data points returned by 360 Identities can be used by relying parties (that is, relying on the accuracy of the identity information) to issue legally valid qualified electronic signatures (for example to sign a document or authenticate an AI agent) or to generate other certificates such as electronic seals (typically used to certify the integrity of important emails, digital documents such as invoices, or submissions to authorities).


Generally, the identity assurance issued by 360core can be used for any online transactions where a digital identity is associated with an electronic document, an email, a webform or any other important data exchange:


Business contexts for 360 Identities include:


  • Customer authentication
  • AI agent authentication
  • Signatories management
  • Age verification
  • Onboarding and KYC workflows
  • Ongoing due diligence
  • Transaction authentication


What is the output of 360 Identities for relying parties such as financial institutions, online marketplaces, government agencies, AI agents


The output of 360core's identity proofing process ("export payload") or, in data protection terminology, the full scope of its personal data processing activity, comprises the following collected and validated identity attributes of online users ("applicants"), derived from the input of their digital identity document and the biometric selfie liveness video.


Data points from identity documents returned by the API of 360 Identities


1. Connection data - Captured from network and mobile device


  • IP address, VPN signals of the ID holder
  • Mobile device fingerprint: Mobile device metadata about the hardware and software of the document holder's mobile device (such as device manufacturer, brand, model, OS, screen resolution, etc.). The corresponding a hash string acts as a persistent identifier additionally linking a digital identity to a specific device for user analytics or to prevent identity theft
  • Web browser information of the ID holder


2. Header data (Zone 1): Textual - Captured from chip


  • Document code / type: National or ordinary passport (PP), Emergency passport (PE), Diplomatic passport (PD), Official and service passport (PO), Refugee passport (PR), Alien and non-citizen passport (PT), Stateless passport (PS), Laissez-passer passport (PL), Military passport (PM)
  • Issuing state or organization: Three-letter ISO 3166 code, in addition to special codes as outlined in ICAO 9303 Part 3, Section 5 (here)
  • Document number: Nine-digit alphanumeric string as given by the issuing state or organization to uniquely identify the identity document


3. Personal data (Zone 2): Textual - Captured from chip


  • First name, middle name, last name: The full name of the holder, as identified by the issuing state or organization captured from DG1 or DG11 if available
  • Date of birth: The document holder's date of birth as recorded by the issuing state or organization
  • Age assurance: The age of the document holder at date of capture
  • Sex: Female (F), Male (M), Unspecified (<)
  • Nationality: Three-letter ISO 3166 code representing the holder's nationality
  • Place of birth: Field optionally used for the city and state of the document holder's birthplace
  • Optional personal data elements: Optional data elements (such as personal identification numbers given to holders by the issuing state or organization) accommodate the diverse requirements of issuing states and organizations while maintaining sufficient uniformity to ensure global interoperability


4. Personal data (Zone 2 and Zone 4): Imagery - Captured from document surface, chip, selfie video


  • Image of the physical identity document: Captured through OCR and transmitted in jpeg format
  • High-quality portrait of the holder at date of document issuance: Captured from DG2 or DG5 if available
  • 4 high-quality audit images of the holder at date of document capture: Captured from the selfie liveness video
  • Holder's signature or usual mark: Captured from the NFC chip (to be displayed on signed documents where appropriate)


5. Document data (Zone 3): Textual - Captured from chip


  • Date of issue: Date in accordance with the Gregorian calendar as captured from the Visual Inspection Zone (VIZ)
  • Authority or issuing office: The issuing authority or issuing organization and, optionally, its location
  • Date of expiry: Date in accordance with the Gregorian calendar
  • Optional document data elements: This field may include (i) necessary endorsements as to entitlements which attach to a visa such as a) the maximum authorized duration of stay b) conditions related to the granting of the visa c) the date of issue if different from the "Valid from" date and d) record of any fees paid (ii) an optional signature or authorization which may be the signature of the issuing officer or an official stamp

Quick start

Get 360 Identities on Google Play (here) or in the App Store (here)

Take a photo of your ID using natural light and focus on the text.

Move your device in small circles over your ID to read its NFC chip.

Read the NFC chip embedded in your digital identity document

Record a short selfie video to allow liveness detection.

Let us detect that you are real by recording a short face video

Product features of 360 Identities - Version 1.0.29

Business logic


  • Process initiation: Have the applicant scan an identification link with their mobile device
  • Attribute and evidence collection: Extract identity attributes from the identity document's visual inspection zone (VIZ), machine readable zone (MRZ), biometric chip
  • Attribute and evidence validation: Determine the freshness, reliability, and consistency of the collected identity attributes
  • Passive authentication: Validation of the electronic machine readable travel document's (eMRTD) country signing certificate via the ICAO PKD (Public Key Database)
  • Binding to applicant: Liveness detection through a video selfie in order to verify that the applicant is the legitimate passport holder and not a bad actor using spoofs

Usability


  • Dedicated app: 360 Identities is available in the App Store (here) and on Google Play (here)
  • Clear UI: Intuitive interface for corporates and public authorities avoiding unnecessary complexity
  • In-context user guidance: Clear and informative instructions increase your conversion rate and reduce our support requests
  • Remote, unattended, and fully automated: 360 Identities operates 24/7, 365 days a year guaranteeing 99.99% uptime
  • Multilanguage: All screens are in 4 languages (EN, DE, FR, IT)
  • Technical support hotline: Support is in EN, DE, FR, IT during office hours (+41 44 700 28 88)
  • Productivity ecosystem: Integrated into the eSignatures solution 360 Signatures (here), the DMS 360 Documents (here), a financial-grade CRM 360 Relationships (here), and 360 Screenings (here), a sanctions and adverse media screening tool

Regulatory


  • Conformance to European standards: 360 Identities is certified and recertified to ETSI TS 119 461 and ETSI EN 319 401 by KPMG Switzerland
  • Compliance with Art. 3 AMLA ("Verification of the identity of the customer"): "When establishing a business relationship, the financial intermediary must verify the identity of the customer on the basis of a document of evidentiary value"
  • Compliance with Art. 5 AMLA ("Repetition of the verification of the identity of the customer"): "If doubt arises in the course of the business relationship as to the identity of the customer or of the beneficial owner, the verification of identity [...] must be repeated"

Security


  • Penetration testing: 360 Identities undergoes yearly testing by TÜV Rheinland
  • Security by design: To prevent identity fraud, 360 Identities only accepts identity documents equipped with a biometric chip
  • Privacy by design: Personal data is processed only during identity verification, but is not stored
  • Cryptography: All personal data is encrypted at rest, in transit, and in use (FIPS 140-3)
  • Robust injection attack detection (IAD): Root detection, emulator detection, virtual camera detection, code obfuscation, biometric challenge-response
  • Information security: ISO 27001 certified data centres located in Switzerland in compliance with FINMA requirements
  • Zero trust security: All client-server data traffic is mutually authenticated (mTLS)

Compliance hub

Download Identity Proofing Practice Statement.

Download current Terms of Use for 360 Identities.     

Download Privacy Statement for 360 Identities.

Download the Privacy statement applicable to 360 Identities

Download list of accepted identity documents.

Related Reading


AMLA (2026) Draft Regulatory Technical Standards on Customer Due Diligence under AMLR 28(1) (here)


Jürgen Anke Michael Kubach Jan Sürmeli (2025) Digitale Identitäten und Nachweise - Lösungsansätze für vertrauenswürdige Interaktionen zwischen Menschen, Unternehmen und Verwaltung (here)


Gary Archer, Judith Kahrer, Michał Trojanowski (2025) Cloud Native Data Security with OAuth (here)


Frank Arretz (Hrsg.) (2022) Digitale Authentifizierung (here)


Biometric Update (2026) 2026 Age Assurance & Digital Age Credentials Market Report (here)


Biometric Update (2026) The Deepfake Fraud Detection Market 2026: Securing Identity in the AI Era (here)


Biometric Update (2026) 2026 Injection Attack Detection Market Report and Buyer's Guide (here)


Alan Calder, Steve Watkins (2019) IT Governance: An International Guide to Data Security and ISO 27001/ISO 27002 (here)


Kévin Carta (2024) Biometric Data Injection Attacks on Facial Recognition used in Remote Identity Proofing (here)


Comité européen de normalisation (CEN) (2024) TS 18099:2024 Biometric data injection attack detection (here)


ENISA (2021) Remote ID Proofing - Analysis of methods to carry out identity proofing remotely (here)


ENISA (2022) Remote Identity Proofing: Attacks & Countermeasures (here)


ENISA (2024) Remote ID Proofing Good Practices (here)


ETSI (2026) ETSI TS 119 461 Electronic Signatures and Trust Infrastructures (ESI); Policy and security requirements for trust service components providing identity proofing of trust service subjects (here)


ETSI (2026) ETSI TS 119 431-1 Electronic Signatures and Trust Infrastructures (ESI); Policy and security requirements for trust service providers; Part 1: TSP services operating a remote QSCD / SCDev (here)


ETSI (2026) ETSI EN 319 401 Electronic Signatures and Trust Infrastructure (ESI); General Policy Requirements for Trust Service Providers (here)


FINMA (2021) Circular 2016/7 Video and online identification. Due diligence requirements for client onboarding via digital channels (here)


FINMA (2026) FINMA publishes guidance on managing digital fraud risks (here)


ICAO (2021) Doc 9303 - Machine Readable Travel Documents (here)


Internet Engineering Task Force (2003) RFC 3647: Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework (here)


ISO 25456 Information technology - Biometrics - Biometric data injection attack detection (here)


ISO 27000:2018 Information technology - Security techniques - Information security management systems - Overview and vocabulary (here)


ISO 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements (here)


ISO 27002:2022 Information security, cybersecurity and privacy protection - Information security controls (here)


ISO/IEC 27005:2022 Information security, cybersecurity and privacy protection - Guidance on managing information security risks (here)


ISO 27017:2015 Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services (here)


Ev Kontsevoy, Sakshyam Shah, Peter Conrad (2023) Identity-Native Infrastructure Access Management (here)


Liliane Obrecht, Anna Kuhn (2026) Kommentierung zu Art. 21 DSG - Informationspflicht bei einer automatisierten Einzelentscheidung (here)


Eve Maler (2026) Mastering Digital Identity (here)


NIST (2025) NIST SP 800-63 Digital Identity Guidelines (here)


NZZ (2026) Sollten wir Jugendlichen soziale Netzwerke verbieten? Ist das technisch überhaupt machbar? Und was sagt die Forschung über solche Verbote? (here)


Gilit Saporta, Shoshana Maraney (2022) Practical Fraud Prevention. Fraud and AML Analytics for Fintech and eCommerce (here)


Anton Stravinsky (2025) Passport Scams, How to Spot a Fake ePassport, NFC Chip Reading, PKI Signatures, and Passive Authentication (here)


Swisscom Trust Services (2026) Why must the evidence and log data be archived for a long time? (here)


André Tanner, Robert Iliev (2025) Kommentierung zu Art. 3 GwG - Identifizierung der Vertragspartei (here)


UK Home Office (2026) Top tips on how to scan a passport biometric chip: video (here)


Phillip J. Windley (2023) Learning Digital Identity (here)


Phil Windley (2026) Dynamic Authorization - Adaptive Access Control (here)

Integrate 360 Identities to your workflow via API