Why IDnow
Security built for regulated industries.
Our customers operate in banking, insurance, automotive, gaming and other regulated industries across Europe — each subject to their own supervisory authority. They audit their third parties seriously, so we built our programme to satisfy that scrutiny.
Purpose-built
More than a decade of regulated identity.
Since 2014, IDnow has delivered identity verification at the assurance level financial regulators require — from one of the first BaFin-approved remote KYC methods to today's AI-driven, multi-modal Trust Platform.
People
Our identity experts are vetted like bank staff.
Every ident-center specialist passes thorough background checks, including police clearance, and receives rigorous training. Sites run two-factor access control and continuous CCTV — one customer at a time.
Sovereignty
European hosting, in-house core.
Production data stays in the EU. Ident services run in IDnow locations or on a European cloud. The core platform is built in-house, with selected modules from European partners.
Cryptography
Strong encryption you can verify.
Data is encrypted in transit and at rest. Master keys are held on-premise in dedicated HSMs, inaccessible to cloud providers. All traffic between ident centers and data centers runs over encrypted VPN tunnels.
Ready for what's next
Built for eIDAS 2.0, AMLR and the EUDI Wallet.
The Trust Platform is built for EUDI Wallet acceptance and AMLR compliance. IDnow Trust Services AB adds the full qualified layer — QES, QSeals, Timestamps and QEAA — for customers who need it.
Continuously monitored
An ISMS that works between audits.
30 versioned policies backed by an automated control system that collects evidence continuously — not just at audit time. Every questionnaire response traces to a live control and evidence.
Certifications & frameworks
What we're certified for.
All four IDnow group entities. Development, maintenance and operation of identity verification solutions and signature services.

eIDAS 2.0
TSP-12353/25-1-1-2, TSP-12353/25-1-2-2, TSP-12353/25-1-3-2, LSTI N° 11109-201-2401-ETSI V1
AutoIdent, VideoIdent and IdentityTM certified as QES components under eIDAS 2.0 (ETSI EN 319 401/411/412, TS 119 461). IDCheck PVID additionally certified to ETSI TS 119 461 V2.1.1.
IDcheck.io Identity Proofing Service certified at niveau substantiel under the French PVID framework. Enables KYC/AML-compliant remote identity verification under French law. Valid until 24 July 2027.
IDnow SAS electronic seal service (Cachet / SmartStamp) under the French national RGS security framework.
VideoIdent identification procedure — Step 2. Eight control objectives over the full calendar year. Call centers in DE, HR, RO, GR, PL, PT, BG, BA.

DORA
IDnow as a critical ICT third-party service provider under the EU Digital Operational Resilience Act.

GDPR
Data-processor role under Art. 28 GDPR across all IDnow SaaS services.
Information security assessment against automotive industry partner requirements. Achieved Level 3 — highest protection level — for availability and confidentiality, including special-category personal data.
Security controls
How we protect your data.
Four operating pillars backed by 30 versioned policies, continuously monitored through our compliance tooling, not just at audit time. Our ISMS incorporates ISO 27001:2022, DORA, ETSI EN 319 401, PVID, TISAX and GDPR Art. 32.
Organizational & People
The right people, in the right roles, properly vetted.
- Access is granted on a need-to-know basis, scoped to organizational profiles, and reviewed regularly.
- Privileged access requires a "Trusted Role" as defined under ETSI EN 319 401, which needs CISO approval and thorough personnel background checks.
- MFA is enforced on all critical applications; access to production systems additionally requires a strong VPN connection.
- All staff complete recurring security awareness training, department-specific training and regular phishing simulations.
- Strict segregation of duties is enforced: critical roles such as fraud operators and system administrators require dual approval for sensitive actions.
Physical Security
Ident centers, data centers and hardware, controlled down to the rack.
- Ident centers are high-security zones: agent entry requires a hardware token and all personal devices are seized at the door.
- Each agent works in isolation, one customer at a time, with no access to local storage or the public internet.
- All entry events are logged, cameras run 24/7 with 30-day retention, and alarms detect unauthorized access outside working hours.
- On-premise data centers host servers in dedicated physical cages with door access control, continuous monitoring and independent access management per cage.
- All laptops and mobile devices run MDM with full-disk encryption, USB block and remote wipe enforced.
Secure Development
Security built into the product, not added afterwards.
- Every code change requires peer review; security-relevant changes may additionally receive Security Team assessment and threat modelling.
- Static code analysis and SBOM generation run in every CI/CD pipeline; all components are tracked in a centralised inventory that gives full visibility into libraries and known vulnerabilities.
- Production and test environments are strictly separated; production data is never used in testing and access to production systems requires an additional hardware token as a second factor.
- All customer-facing services undergo thorough penetration testing at least annually or after significant changes, conducted by independent external providers.
- Third-party libraries and dependencies are continuously monitored for newly disclosed vulnerabilities; updates are assessed and applied following risk-based prioritisation.
Infrastructure & Resilience
Monitored infrastructure, tested continuity.
- All data is encrypted in transit and at rest; master encryption keys are held in on-premise HSMs and are inaccessible to cloud providers.
- All networks and systems are continuously scanned for vulnerabilities; findings are tracked and assigned to responsible teams with risk-based remediation timelines.
- Security-relevant logs are centralised into a SOAR pipeline accessible exclusively to our internal SOC team, enabling automated detection and response to threat patterns.
- ICT security incidents are classified, contained, and notified to relevant authorities in line with DORA Art. 19 obligations; every incident closes with a mandatory post-mortem linked to the risk register.
- Business continuity plans — covering BIA, defined RPO and RTO targets, and geo-redundant backups — are tested against realistic disaster scenarios in line with DORA Art. 11 requirements.
Data residency
Where your data lives.
100 % European hosting across several independent EU operators, for data sovereignty, resilience and predictable regulatory exposure.
Data center locations, EU only
Platform status
Real-time and historical uptime, planned maintenance and incident reports.
View status pageProduction data centres
Depending on the product used, data is processed at one or more of the locations below.
- Noris Network AG — Nuremberg (eu-de-nbg6) & Aschheim (eu-de-muc5), GermanyVideoIdentAutoIdentGerman eIDInstantSignSIGNIUSQSeals
- BLUE SAS — Châteaubourg & Cesson-Sévigné (eu-fr-cha), France (primary + backup)IDCheckIDCheck PVIDSmartStamp
- Telekom Deutschland / q.beyond AG — Ulm (eu-de-ulm), Germany (redundant backup location)identity.TMPOS Self-Service
- Amazon Web Services (AWS) — Frankfurt (eu-central-1) & Paris (eu-west-3), EU (primary (Frankfurt, 3 AZs) + secondary (Paris, 3 AZs))Trust Platform
Data handling
- RetentionPersonal data is retained only for as long as required under the customer agreement or applicable law, and deleted immediately on customer or end-user request or at contract end. Deletion certificates are available on request.
- EncryptionAES-256 at rest and TLS 1.2+ in transit across all environments. Master encryption keys are managed exclusively on-premise via dedicated HSMs — cloud infrastructure providers cannot access key material.
- BackupsGeo-redundant backups stored at a dedicated offsite location, fully isolated from the production environment. Restore and DR tests are conducted regularly; customers have a contractual right to audit backup procedures.
Documents & Reports
Documents & Reports.
Public documents can be downloaded directly. Restricted documents are available to IDnow customers. Customer access via Salesforce SSO is coming soon. Please contact your IDnow Customer Success Manager in the meantime.
Certifications & Audit Reports
ISO 27001:2022 Group Certificate
eIDAS 2.0 QES Component Certificate — AutoIdent
eIDAS 2.0 QES Component Certificate — VideoIdent
eIDAS 2.0 QES Component Certificate — IdentityTM
RGS Qualification — IDnow SAS
ANSSI PVID Certificate — IDcheck.io
ETSI TS 119 461 Certificate — IDCheck PVID
TISAX AL3 Assessment Label — IDnow GmbH
ISAE 3402 Type 2 Report — VideoIdent
Penetration Test Reports
Penetration Test — AutoIdent & VideoIdent Web/Mobile
Penetration Test — IDCheck
Penetration Test — IdentityTM External Infrastructure
Penetration Test — Trust Platform
Penetration Test — IDnow Verify Android
Penetration Test — IDnow Verify iOS
Policies
Business Continuity Plan — AutoIdent & VideoIdent
Business Continuity Plan — IDCheck
Business Continuity Plan — IdentityTM & PoS
Vulnerability Disclosure Policy
Legal Documents
Data Processing Agreement + Security Controls Annex
Group Code of Conduct
Privacy Policy
Annex: DORA Addendum
Security Questionnaires
SIG Questionnaire
CAI-Q Questionnaire
Certification policies (eIDAS)
Practice Statements, CPS & GTU.
These Certificate Policies, Certificate Practice Statements and General Terms of Use govern the qualified certificates and trust services issued by IDnow GmbH, IDnow Trust Services AB and their predecessors Ariadnext and identity.tm, pursuant to ETSI EN 319 411-2 and the eIDAS 2.0 framework.
Certificate Practice Statement
Identity Proofing Service Practice Statement (ETSI TS 119 461)
11 previous versions
- VideoIdent CPS v1.6 (superseded)
- VideoIdent CPS v1.4 (superseded)
- VideoIdent CPS v1.3 (superseded)
- VideoIdent CP v1.7 (superseded)
- VideoIdent CP v1.6 (superseded)
- VideoIdent CP v1.4 (superseded)
- VideoIdent CP v1.3 (superseded)
- AutoIdent CPS v1.3 (superseded)
- AutoIdent CPS v1.1 (superseded)
- AutoIdent CP v1.3 (superseded)
- AutoIdent CP v1.1 (superseded)
Politique de Vérification d'Identité à Distance — IDCheck.io IPS
4 previous versions
- FR v1.4 (Apr 2025) — IDnow SAS
- FR v1.3 (Jun 2023) — IDnow France
- FR v1.1 (Oct 2022) — Ariadnext
- FR v1.0 (Mar 2021) — Ariadnext
General Terms of Use
IDnow General Terms of Use
3 previous versions
- 2019-12-10
- 2018-06-20
- 2017-05-29
IDnow SAS (formerly Ariadnext) certificates
Ariadnext Certificate Repository
IDnow Trust Services AB
IDnow Trust Services AB — Documentation & Certifications
IdentityTM by IDnow certificates
IdentityTM Certification Practice Statement
11 previous versions
- 2.0
- 1.9
- 1.8
- 1.7
- 1.6
- 1.5
- 1.4
- 1.3
- 1.2
- 1.1
- 1.0
Sub-processors
Who processes your data.
Depending on the product used, IDnow may engage some or all of the sub-processors below. All are bound by data-processing agreements that impose GDPR-equivalent obligations. This list reflects the current Annex: Service Providers attached to the DPA.
IDnow Group
| Name | Location | Purpose |
|---|---|---|
| IDnow GmbH | Munich, Germany | HQ — IT Service Provider |
| IDnow SAS | Cesson-Sévigné, France | IT Service Provider (formerly Ariadnext) |
| IDnow UK Limited | London, United Kingdom | Distribution company (UK) |
| IDnow Romania S.R.L. | Iași, Romania | Execution of identifications and reviews with Ident Specialists |
Hosting
| Name | Location | Products |
|---|---|---|
| Noris Network AG | Nuremberg, Germany | VideoIdentAutoIdentGerman eIDInstantSignSIGNIUSQSeals |
| BLUE SAS | Châteaubourg & Cesson-Sévigné, France | IDCheckIDCheck PVIDSmartStamp |
| Telekom Deutschland GmbH / q.beyond AG | Ulm, Germany | identity.TMPOS Self-Service |
| Amazon Web Services EMEA SARL | Frankfurt & Paris, EU | Trust Platform |
Technical Services
| Name | Location | Purpose | Products |
|---|---|---|---|
| Tink Germany GmbH | Munich, Germany | optional: GwG module — BaFin-regulated banking service provider (AIS/PIS) | AutoIdent |
| Signicat B.V. | Enschede, Netherlands | optional: NFC module — NFC chip readout of ICAO 9303 compliant documents | AutoIdent |
| AUTHADA GmbH | Darmstadt, Germany | eID service provider with authorisation certificate | German eID |
| Governikus GmbH & Co. KG | Bremen, Germany | eID Server Access Provider | German eID |
| nCINO, Inc. | London, United Kingdom | AML screening and monitoring services | IDCheck |
| Esysco Sp.z o.o. | Poznań, Poland | IT Service Provider for IDnow Trust Services AB | InstantSign |
| Microblink LLC | Zagreb, Croatia | OCR provider for ID document recognition | identity.TM |
Trust Services
| Name | Location | Purpose | Products |
|---|---|---|---|
| IDnow Trust Services AB | Stockholm, Sweden | eIDAS Qualified Trust Service Provider (QTSP) — QES, QSeals, Qualified Timestamps, QEAA | Trust PlatformSmartStampGerman eIDInstantSignAutoIdentSIGNIUSQSeals |
| Namirial S.p.A. | Senigallia, Italy | eIDAS Qualified Trust Service Provider (QTSP) | German eIDInstantSign |
| DocuSign France SAS | Issy-les-Moulineaux, France | eIDAS Qualified Trust Service Provider (QTSP) | InstantSign |
Ident Centers
IDnow customers choose which ident centers are used for their service. The following providers are authorised for execution of remote identifications with ident specialists.
| Name | Location | Products |
|---|---|---|
| IDnow Romania S.R.L. | Iași, Romania | VideoIdentInstantSignAutoIdentidentity.TM |
| Coordinatio d.o.o. | Split, Croatia | VideoIdentInstantSignAutoIdentidentity.TM |
| M.S.S. Vertriebsgesellschaft mbH u.Co.KG | Zagreb, Osijek, Metković — Croatia | VideoIdentInstantSignAutoIdentidentity.TM |
| Online Office Service S.R.L. | Brașov, Simeria — Romania | AutoIdentInstantSignVideoIdentidentity.TM |
| ASM d.o.o. | Sarajevo, Bosnia and Herzegovina | IDCheckAutoIdentVideoIdent |
| IDmission LLC | Pune, India | AutoIdentIDCheck |
| ENYA-CALL SINGLE MEMBER P.C. | Athens, Greece | — |
What's new
Change log.
Recent changes to certifications, policies and the security & compliance hub itself.
- IDnow Trust Services AB: QEAA certification under eIDAS 2.0
IDnow Trust Services AB receives certification to issue Qualified Electronic Attestations of Attributes (QEAAs) under eIDAS 2.0, enabling legally recognized verification of customer credentials such as address, tax ID and professional qualifications.
- ETSI TS 119 461 v2.1.1 certification for AutoIdent, VideoIdent and IdentityTM
IDnow becomes one of the first providers in Europe to achieve ETSI TS 119 461 v2.1.1 certification for AutoIdent, VideoIdent and IdentityTM, meeting the eIDAS 2.0 compliance standard for remote identity proofing.
Group-wide ISO 27001:2022 certificate
IDnow harmonises its group-wide ISMS under a single ISO/IEC 27001:2022 certificate, covering all four entities — IDnow GmbH, IDnow SAS, IDnow Romania and IDnow UK.
DORA (Digital Operational Resilience Act) applies
DORA entered into force across the EU. IDnow complies with DORA requirements as a critical ICT third-party service provider for regulated financial institutions.
Get in touch
Working on a vendor review or RFP?
Our security team can provide certificates, audit reports and questionnaire responses. Pre-filled SIG-Lite and CAIQ-Lite questionnaires are available on request in the Documents section.




