Launch HN: Didit (YC W26) – Stripe for Identity Verification
31–40 of 76 posts
Re: Launch HN: Didit (YC W26) – Stripe for Identity Verification
#32Earlier quoted context omitted.
There is many direct competitors in the space, the main ones are Persona, Jumio, Incode, Sumsub, and even orchestrators like Alloy. In general I believe we just built a better product: - Fastest verification on the market (inference time 30 s, ours is less - Optimized onboarding rate worldwide, global coverage, any country, low connectivity and every device accepted, and optimized (different models loading in the cli…
Seon, Comply Advantage. There's lots of competition here.
They provide one signal, identity verification is more than that.
Re: Launch HN: Didit (YC W26) – Stripe for Identity Verification
#33There are a bunch of competing companies in that space but it's true that transparent pricing and self-service is rare. Good idea to focus on that.
Re: Launch HN: Didit (YC W26) – Stripe for Identity Verification
#34Great to see innovation in this space! If I could make one giant request, it's around giving (properly authorized) humans the ability to override the system when needed. When you make a simple API, it's all too common for a company integrating the solution to rely entirely on the identity service's yes-no outcome. But all too commonly, there's no way to override a decision, or bypass the need for identification. In t…
Instead, this should be handled not by fudging identity verification but by skipping it and maybe tagging the skip event with some verified identities of the people authorizing the skip.
Re: Launch HN: Didit (YC W26) – Stripe for Identity Verification
#35A couple questions:
1. Given that one of your offerings is a wallet for identity, how do you handle storing user biometric data and documents
2. I’m surprised AI age detection based on faces is accurate enough to be used for account decisions. Is there any specific standard your models are held too and why would someone prefer it over an ID document proving age?
Re: Launch HN: Didit (YC W26) – Stripe for Identity Verification
#36with all this talk about persona/discord sending identities to the dhs and everything, what steps do you guys take to keep identity information private?
I don't have the full context on the Persona/Discord story yet, but our philosophy is that identity providers should be a shield, not a source of risk. We address this by building privacy-preserving architectures that minimize the data footprint. First, we offer secure, long-term retention so companies don't have to store sensitive PII on their own servers—which are often managed by teams who aren't cybersecurity spe…
IMO, you should spend a lot of time working on your privacy policy. I have identified a few points of concern that you should work on:
1. Your policy is immensely vague. "legally stipulated periods of conservation" means nothing. There are no references to which laws are being referenced, and there are no references to specific timeframes. Concrete detail is most needed here.
2. Under section 4, there is no mention of response timeframes (GDPR mandates 30 days), no indication of what to include in a request, and no acknowledgement of the right to escalate if Didit fails to respond.
3. You mention processing biometric data in passing and note consent as the legal basis. For special category data under GDPR Article 9, this deserves substantially more transparency -- what biometric data, how it is stored, whether it is retained after identity verification, and what happens if consent is withdrawn. One sentence is not adequate.
4. "Didit will have adopted appropriate data protection safeguards in advance" is very vague. You should specify the transfer mechanism and actually identify which third countries are involved.
5. Your legitimate interest claim for contact persons (section 2b) is asserted without any balancing test explanation, which is technically required under the GDPR.
Your information security policy is purely a mission statement. It is only a list of things you intend to do, without any explanation about how you either currently or will implement these things.
For example, "align with the highest standards of security" -- which standards? ISO 27001? SOC 2? NIST? "achieve the fully satisfactory resolution of incidents" -- what constitutes "satisfactory"? What is your incident response process?
If you intend to take data security and privacy seriously, both documents must be improved greatly before I as a consumer would consider handing my data over to this service.
Re: Launch HN: Didit (YC W26) – Stripe for Identity Verification
#37Re: Launch HN: Didit (YC W26) – Stripe for Identity Verification
#38Congrats on the launch! Hard to judge from just demo videos but the flow seems much nicer than those I’ve encountered in many apps. A couple questions: 1. Given that one of your offerings is a wallet for identity, how do you handle storing user biometric data and documents 2. I’m surprised AI age detection based on faces is accurate enough to be used for account decisions. Is there any specific standard your models a…
The idea is that users control their identity. They create a Didit account where they can verify themselves, add credentials, revoke connections, or delete everything at any time. We don’t store raw biometrics or documents in the wallet layer — only derived attributes like estimated_age, is_human, is_unique, or a face embedding used for matching.
Services request specific scopes (similar to “Sign in with X”), like is_over_18 or is_human, and the user explicitly approves what gets shared.
On age detection: it’s mainly for low-risk age-gating (social, gaming, adult content, etc.), where asking every user for an ID kills conversion. For higher-risk cases you’d still use full ID verification.
Re: Launch HN: Didit (YC W26) – Stripe for Identity Verification
#39Any plans for B2B verification?
Re: Launch HN: Didit (YC W26) – Stripe for Identity Verification
#40Earlier quoted context omitted.
Seon, Comply Advantage. There's lots of competition here.
Comply Advantage specializes in AML, Seon as well. They provide one signal, identity verification is more than that.