Questions and Answers About Digital Signatures and Identification
FAQ
Search
Security & Compliance
fidentity uses a multi-layered security concept that reliably detects attacks using fake photos, videos, masks, or deepfakes. The resilience of our system is measured against internationally recognized standards (ISO, DIN, ETSI): fidentity withstands a highly skilled attack for at least thirty days. We are continuously working to increase this security margin even further.
Yes. Our solutions are audited by KPMG and comply with the requirements of FINMA Circulars 2016/7 (video identification), 2018/3 (outsourcing), and 2008/21 (operational risks).
fidentity is comprehensively certified and meets the relevant Swiss and European requirements:
- FINMA Circular 2016/7 for video and online identification in the financial sector,
- CDB 20 (Swiss banking due diligence standards),
- TAV OFCOM for technical requirements for digital signatures
- ETSI TS 119 461 as the European standard for secure identity and signature services
Regular KPMG audits independently confirm compliance with these requirements.
All data is processed and stored exclusively in Switzerland. We meet the requirements of both the Swiss Data Protection Act (FADP) and the European General Data Protection Regulation (GDPR).
We follow a "security by design" approach: security aspects are integrated into development from the very beginning. In addition, we conduct regular penetration tests and participate in bug bounty programs.
Yes. Our solutions are KPMG-audited and comply with all FINMA circular requirements as well as AML regulations.
We undergo regular recertification under signature legislation and continuously adapt our systems to new regulatory requirements—for example, with regard to eIDAS changes or digital identity wallets.
We rely on two-factor authentication, privileged access management, encrypted backups, dedicated containers per customer, and fraud detection mechanisms such as liveness and replay detection.
All data is stored exclusively in Switzerland in the Swisscom Wankdorf data center (Tier IV). The data center offers maximum availability, physical access controls, redundant systems, and a sustainable energy supply.
At fidentity, data is deleted either in accordance with legal requirements or upon request.
In the EU, the "right to be forgotten" (GDPR) applies. In Switzerland, the FADP requires that data be deleted or anonymized as soon as it is no longer needed—and here, too, you can request deletion at any time.
Sensitive administrator access is controlled through privileged access management (PAM). In addition, all systems are secured with two-factor authentication. Access to customer data is only possible from defined IP addresses (IP allowlist), effectively preventing unauthorized access.
We guarantee clear service levels for availability, response times, and support. This ensures that our solutions operate reliably and meet your requirements at all times. Since our customers have very different needs regarding response time, uptime, and conversion, the specific SLA terms are defined individually.
All data is transmitted using current encryption standards, including end-to-end encryption and TLS 1.2/1.3. This ensures that sensitive information remains protected at all times.
General
Our solutions are used across industries—not just by banks. Financial service providers, insurers, and public administrations also rely on fidentity's secure identification and signature processes.
Costs depend on your individual requirements, your transaction volume, and the modules you choose (IDENT, SIGN, ONBOARD). We are happy to prepare a customized quote tailored to your processes. (LINK contact/quote)
Yes, we offer test environments and demos. Please contact our sales team.
Our solutions are certified for use in Switzerland and the European legal area (ZertES, eIDAS), ideal for companies focused on these markets.
Our solutions are used across industries, especially by financial service providers and fintechs, but also in other areas where secure identification and signature processes are required.
We closely follow developments in digital identification and signatures and continuously adapt our systems to new regulatory and technological standards. This keeps our solutions future-proof in the long term.
Solutions
Yes. Both IDENT and SIGN are web-based and work on any smartphone. No app installation is required—an ID document, a smartphone, and a smile are all it takes.
Yes. If a valid identification already exists, it can be used for the signature process. This speeds up your workflows and reduces costs.
No. With IDENT and ONBOARD, you can run identification and verification processes without a signature. If needed, SIGN adds a legally valid digital signature.
With fidentity, there are no waiting times or manual checks. Identification is fully automated, available around the clock, and completed in less than 90 seconds. Over 85% of users succeed on their first attempt. Unlike video identification, users do not have to reveal their identity to a stranger—which significantly increases acceptance and leads to higher customer satisfaction, better conversion rates, and lower costs.
Yes. With SIGN, we offer qualified electronic signatures (QES) that are legally equivalent to handwritten signatures under the Swiss ZertES and the European eIDAS regulation.
Yes. Our solutions are legally compliant in both the Swiss and European legal areas. This makes them particularly suitable for companies operating in both markets.
fidentity supports identity cards and passports. In addition, residence permits, driver's licenses, or student IDs can be captured as supporting credentials. Documents from more than 70 countries worldwide are already covered (List of allowed documents).
fidentity is also ready for the Swiss e-ID, which can be seamlessly integrated into the identification process as an additional option alongside passports and identity cards.
Yes. Thanks to secure authentication—such as Face ID or device login—repeat signatures are quick and easy, without requiring a new identification.
Yes. In addition to the qualified electronic signature (QES) and all levels of electronic signatures, handwritten signatures can also be captured on a tablet or mobile device and inserted into the document.
Yes. fidentity is not a trust service provider (TSP) itself but is certified as a registration authority. For qualified electronic signatures (QES), we work with several recognized qualified TSPs, including Swisscom Trust Services and SIGN8. This collaboration gives us maximum flexibility and allows us to always offer our customers the right solution in the Swiss and European legal areas.
In addition to identification and signature, further steps can be integrated: form capture—for example, on the source of funds—PDF generation, additional document uploads, or KYC checks.
Yes. fidentity provides an SSO-enabled back-office dashboard for managing and reviewing all identification and signature processes.
fidentity supports simple (SES), advanced (AES), and qualified electronic signatures (QES). The QES is the highest standard and is legally equivalent to a handwritten signature in Switzerland (ZertES) and the EU (eIDAS).
Online identification with QES is generally available from age 18. On request, the minimum age can be lowered to 14, depending on the use case.
Yes. With IDENT, companies can securely identify not only customers but also new employees digitally. For example, during HR onboarding.
Yes. fidentity works on all modern browsers—such as Chrome, Safari, Firefox, or Edge—and on mobile devices running iOS or Android. No separate app is required.
Supported versions are iOS 16.4 or later (Safari 16.4+, Chrome 100+) and Android 8 or later (Chrome/Edge 100+, Samsung Internet 20+). Tablets are treated as desktop devices by the system, so identification requires switching to a smartphone.