fidentity logo

Questions and Answers About Digital Signatures and Identification

FAQ

You have questions—we have answers. Whether about digital identification, electronic signatures in general, or our solutions IDENT, SIGN, and ONBOARD: our FAQ provides compact, easy-to-understand information on the most common topics related to fidentity.

Search

Security & Compliance

What measures does fidentity use to detect fraud?

fidentity uses a multi-layered security concept that reliably detects attacks using fake photos, videos, masks, or deepfakes. The resilience of our system is measured against internationally recognized standards (ISO, DIN, ETSI): fidentity withstands a highly skilled attack for at least thirty days. We are continuously working to increase this security margin even further.

Does fidentity meet FINMA requirements?

Yes. Our solutions are audited by KPMG and comply with the requirements of FINMA Circulars 2016/7 (video identification), 2018/3 (outsourcing), and 2008/21 (operational risks).

What certifications does fidentity hold?

fidentity is comprehensively certified and meets the relevant Swiss and European requirements:

  • FINMA Circular 2016/7 for video and online identification in the financial sector,
  • CDB 20 (Swiss banking due diligence standards),
  • TAV OFCOM for technical requirements for digital signatures
  • ETSI TS 119 461 as the European standard for secure identity and signature services

Regular KPMG audits independently confirm compliance with these requirements.

How does fidentity handle personal data?

All data is processed and stored exclusively in Switzerland. We meet the requirements of both the Swiss Data Protection Act (FADP) and the European General Data Protection Regulation (GDPR).

How does fidentity ensure the security of its solutions?

We follow a "security by design" approach: security aspects are integrated into development from the very beginning. In addition, we conduct regular penetration tests and participate in bug bounty programs.

Does fidentity cover the requirements of anti-money laundering (AML) laws?

Yes. Our solutions are KPMG-audited and comply with all FINMA circular requirements as well as AML regulations.

How does fidentity handle regulatory changes?

We undergo regular recertification under signature legislation and continuously adapt our systems to new regulatory requirements—for example, with regard to eIDAS changes or digital identity wallets.

What additional security measures does fidentity have in place?

We rely on two-factor authentication, privileged access management, encrypted backups, dedicated containers per customer, and fraud detection mechanisms such as liveness and replay detection.

Where is the data stored and how is it protected?

All data is stored exclusively in Switzerland in the Swisscom Wankdorf data center (Tier IV). The data center offers maximum availability, physical access controls, redundant systems, and a sustainable energy supply.

When and how is data deleted?

At fidentity, data is deleted either in accordance with legal requirements or upon request.

In the EU, the "right to be forgotten" (GDPR) applies. In Switzerland, the FADP requires that data be deleted or anonymized as soon as it is no longer needed—and here, too, you can request deletion at any time.

How is administrator access to customer data protected?

Sensitive administrator access is controlled through privileged access management (PAM). In addition, all systems are secured with two-factor authentication. Access to customer data is only possible from defined IP addresses (IP allowlist), effectively preventing unauthorized access.

What service level agreements (SLAs) does fidentity offer?

We guarantee clear service levels for availability, response times, and support. This ensures that our solutions operate reliably and meet your requirements at all times. Since our customers have very different needs regarding response time, uptime, and conversion, the specific SLA terms are defined individually.

How is data protected during transmission?

All data is transmitted using current encryption standards, including end-to-end encryption and TLS 1.2/1.3. This ensures that sensitive information remains protected at all times.

General

Which companies use fidentity solutions?

Our solutions are used across industries—not just by banks. Financial service providers, insurers, and public administrations also rely on fidentity's secure identification and signature processes.

What are the costs of using fidentity solutions?

Costs depend on your individual requirements, your transaction volume, and the modules you choose (IDENT, SIGN, ONBOARD). We are happy to prepare a customized quote tailored to your processes. (LINK contact/quote)

Is there a demo or trial option?

Yes, we offer test environments and demos. Please contact our sales team.

In which regions can fidentity solutions be used?

Our solutions are certified for use in Switzerland and the European legal area (ZertES, eIDAS), ideal for companies focused on these markets.

Which industries are fidentity solutions suitable for?

Our solutions are used across industries, especially by financial service providers and fintechs, but also in other areas where secure identification and signature processes are required.

How is fidentity prepared for future digital identity solutions such as eID wallets?

We closely follow developments in digital identification and signatures and continuously adapt our systems to new regulatory and technological standards. This keeps our solutions future-proof in the long term.

Solutions

What products does fidentity offer?

Our core solutions are

  • IDENT for certified online identification
  • SIGN for legally valid digital signatures
  • ONBOARDfor complementary tools and checks during onboarding

All modules can be combined flexibly and integrate seamlessly into your processes.

Can the entire identification and signature process be completed on a smartphone?

Yes. Both IDENT and SIGN are web-based and work on any smartphone. No app installation is required—an ID document, a smartphone, and a smile are all it takes.

Can the qualified electronic signature (QES) be linked to an existing customer identification?

Yes. If a valid identification already exists, it can be used for the signature process. This speeds up your workflows and reduces costs.

Does the onboarding process always require a signature?

No. With IDENT and ONBOARD, you can run identification and verification processes without a signature. If needed, SIGN adds a legally valid digital signature.

What advantages does fidentity offer over traditional video identification solutions?

With fidentity, there are no waiting times or manual checks. Identification is fully automated, available around the clock, and completed in less than 90 seconds. Over 85% of users succeed on their first attempt. Unlike video identification, users do not have to reveal their identity to a stranger—which significantly increases acceptance and leads to higher customer satisfaction, better conversion rates, and lower costs.

Are fidentity's digital signatures legally valid?

Yes. With SIGN, we offer qualified electronic signatures (QES) that are legally equivalent to handwritten signatures under the Swiss ZertES and the European eIDAS regulation.

Can fidentity be used in international markets?

Yes. Our solutions are legally compliant in both the Swiss and European legal areas. This makes them particularly suitable for companies operating in both markets.

Which ID documents are supported?

fidentity supports identity cards and passports. In addition, residence permits, driver's licenses, or student IDs can be captured as supporting credentials. Documents from more than 70 countries worldwide are already covered (List of allowed documents).

fidentity is also ready for the Swiss e-ID, which can be seamlessly integrated into the identification process as an additional option alongside passports and identity cards.

Does fidentity also offer repeat signatures without re-identification?

Yes. Thanks to secure authentication—such as Face ID or device login—repeat signatures are quick and easy, without requiring a new identification.

Does fidentity also support traditional digitized signatures?

Yes. In addition to the qualified electronic signature (QES) and all levels of electronic signatures, handwritten signatures can also be captured on a tablet or mobile device and inserted into the document.

Does fidentity work with certified trust service providers?

Yes. fidentity is not a trust service provider (TSP) itself but is certified as a registration authority. For qualified electronic signatures (QES), we work with several recognized qualified TSPs, including Swisscom Trust Services and SIGN8. This collaboration gives us maximum flexibility and allows us to always offer our customers the right solution in the Swiss and European legal areas.

What features does fidentity offer for process design?

In addition to identification and signature, further steps can be integrated: form capture—for example, on the source of funds—PDF generation, additional document uploads, or KYC checks.

Is there user management for companies?

Yes. fidentity provides an SSO-enabled back-office dashboard for managing and reviewing all identification and signature processes.

What types of electronic signatures does fidentity support?

fidentity supports simple (SES), advanced (AES), and qualified electronic signatures (QES). The QES is the highest standard and is legally equivalent to a handwritten signature in Switzerland (ZertES) and the EU (eIDAS).

From what age can online identification be used?

Online identification with QES is generally available from age 18. On request, the minimum age can be lowered to 14, depending on the use case.

Can IDENT also be used for HR processes?

Yes. With IDENT, companies can securely identify not only customers but also new employees digitally. For example, during HR onboarding.

Are fidentity solutions compatible with all common browsers and devices?

Yes. fidentity works on all modern browsers—such as Chrome, Safari, Firefox, or Edge—and on mobile devices running iOS or Android. No separate app is required.

Supported versions are iOS 16.4 or later (Safari 16.4+, Chrome 100+) and Android 8 or later (Chrome/Edge 100+, Samsung Internet 20+). Tablets are treated as desktop devices by the system, so identification requires switching to a smartphone.