Who Ondato is
Ondato is a KYC and AML company founded in 2018, headquartered in London since 2021, with research and development in Vilnius, Lithuania. It verifies identities with documents, selfies, NFC chip reading and video calls, onboards businesses, screens customers against sanctions lists and monitors transactions.
Its SDKs cover the web, native iOS and Android, Flutter and React Native. Neobanks, payment service providers, crypto and gaming companies are among the businesses it serves, which is why it is one of the providers our KYC / AML module connects to.
What it does in your platform
KYC / AML
Verifies customers at sign-up through the Ondato setup you choose: the document, a liveness selfie and any extra step it includes, such as NFC chip reading. Ondato's result lands in the module's review queue, next to the checks of any other provider you use.
How the connection works
The KYC / AML module talks to Ondato's REST APIs, and Ondato's SDKs handle the capture in your apps. Ondato's credentials stay in your platform's secrets; your app only receives the ID of one verification.
A verification is created
When a customer signs up, the module creates an identity verification in Ondato for the setup you agreed, and gets back its ID. Each ID serves one session and is never reused.
The SDK opens
Your app passes that ID to Ondato's SDK: the web SDK in the browser, the native SDKs on iOS and Android, and Ondato's Flutter SDK in our Flutter apps.
Document and selfie
The customer captures the document and takes a selfie, and reads the document's chip with NFC where the setup includes it.
Signed webhooks
Ondato sends webhooks as the verification moves on, signed with HMAC so the module can check that each one comes from Ondato.
The decision
The module reads the verification and the KYC result through the API and applies your rules. Approved customers go ahead; the rest go to your team's review queue.
Next to other providers
Ondato can run next to other verification providers in the module. Routing by country or risk decides who verifies which customers, and another provider can take over if one is unavailable.
The onboarding screens, the review queue and the audit trail belong to the module, whichever provider runs the check. Adding Ondato, or moving away from it later, does not change your apps, and past checks stay in your records.
When Ondato fits best
A strong fit when
- You want SDKs for the web, native apps, Flutter and React Native from the same provider.
- You want passports and ID cards read over NFC in your mobile apps.
- You run a neobank, a payment service or a crypto business, industries Ondato serves.
Also worth a look
- A provider with deeper coverage in a market that matters to you, routed next to Ondato for those customers.
- A dedicated screening provider, if your compliance team wants a separate source of sanctions and PEP data.
How we get you live
The contract
We help you get your Ondato account and contract in place, set up for your markets and your licence.
The setups
We agree the verification setups with you and Ondato: which documents, which checks and which steps apply to which customers.
The keys
The API credentials and the webhook secret go into your platform's secrets and nowhere else, so every webhook is proven to come from Ondato.
A full test run
The whole flow runs in Ondato's test environment, with credentials kept apart from production, before your first real customer.
