top of page
Built the identity verification layer that Coursera, Square, LinkedIn, and even OpenAI rely on to know who's really behind an account, reaching a $2B valuation by treating identity as continuous infrastructure rather than a one-time signup check — while a February 2026 code-exposure controversy revealed just how much surveillance capability sits underneath that convenience.
1
MODEL
BUSINESS MODEL
API Platform, Infrastructure Platform
model bm
HOW THEY BUILT IT
Provides a customizable identity verification and orchestration platform combining document scans, biometric liveness checks, and database/watchlist checks into modular flows businesses compose for their specific KYC, AML, or age-verification needs across 200+ countries. Founded in 2018 by former Dropbox and Square engineers Charles Yeh and Rick Song.
HOW TO ARCHITECT IT
1) Build a horizontally applicable identity layer (not industry-specific) so the same infrastructure serves fintech KYC compliance, social platform age verification, and AI platform bot-prevention from one modular product. 2) Create reusable identity credentials (Reusable Personas via Passkey) so a user verified once with any Persona customer can reverify faster elsewhere — a network effect that benefits every customer as more of them join. 3) Continuously widen the addressable use case (from fraud prevention to full identity lifecycle management) as your core customers' compliance and trust needs evolve, rather than staying fixed on the original narrow use case.
DISTRIBUTION MODEL
API Distribution, Enterprise Sales
dm
HOW THEY OPERATIONALIZED
Distributes primarily via API integration that developers embed directly into signup and compliance workflows, with enterprise sales driving large accounts (LinkedIn, Block/Square, Reddit) needing custom verification flows across many countries and use cases simultaneously.
HOW TO REPLICATE WHAT WORKED
Worked: building reusable, cross-customer identity credentials creates a genuine network effect — verifying once with Coursera makes reverifying with Square faster, which no single-customer verification tool could offer. Caution: a February 2026 security researcher discovery exposed Persona's underlying verification pipeline, revealing up to 269 individual identity checks that could be run — sparking public criticism (including from Discord users and the security press) that 'age verification' infrastructure can quietly function as a far broader surveillance capability than users realize, a serious reputational and regulatory risk for any identity infrastructure company operating at this scale.
| PATTERNS OF THIS MODEL
PATTERNS IN MODULAR IDENTITY AND TRUST INFRASTRUCTURE:
1. BUILD A HORIZONTAL TRUST LAYER RATHER THAN AN INDUSTRY-SPECIFIC ONE, so the same modular infrastructure serves compliance, age verification and fraud prevention from one product.
2. CREATE REUSABLE CREDENTIALS SO A USER VERIFIED ONCE ANYWHERE IN YOUR NETWORK VERIFIES FASTER EVERYWHERE. That network effect benefits every customer as more join.
3. WIDEN THE USE CASE CONTINUOUSLY AS CUSTOMERS' TRUST REQUIREMENTS EVOLVE rather than remaining fixed on the original narrow application.
4. IDENTITY INFRASTRUCTURE CARRIES CONCENTRATED PRIVACY AND REGULATORY EXPOSURE. Data minimisation is a product architecture decision, not a policy statement.
What companies with this model reveal
| OPPORTUNITY INTELLIGENCE
GOLDMINE 1 — BUILD IDENTITY HORIZONTALLY, NOT PER INDUSTRY.
Standard: the same modular infrastructure serves fintech KYC, social platform age verification and AI bot prevention. Where the underlying primitive is identical across regulated industries, one product can serve all of them.
GOLDMINE 2 — MAKE VERIFICATION REUSABLE ACROSS CUSTOMERS.
Standard: a Reusable Persona means a user verified once with any customer reverifies faster elsewhere — a network effect that improves for every customer as more of them join.
GOLDMINE 3 — WIDEN THE USE CASE AS COMPLIANCE NEEDS EVOLVE.
Standard: from fraud prevention to full identity lifecycle management, following the customer rather than defending the original narrow wedge.
THE PIT — IDENTITY INFRASTRUCTURE CARRIES THE HIGHEST-CONSEQUENCE DATA IN SOFTWARE.
Biometric and document data across 200+ countries means a single breach is existential and permanently reputational, and biometric privacy statutes create per-record liability.
THE SECOND PIT — REGULATION IS YOUR TAILWIND AND YOUR COMPLIANCE BURDEN SIMULTANEOUSLY.
Every new age-verification law expands demand and adds jurisdiction-specific engineering.
MOVE WITH CAUTION — REUSABLE CREDENTIALS DEPEND ON CUSTOMERS ACCEPTING ANOTHER FIRM'S VERIFICATION.
Untapped Business Model / Gaps / Goldmines / Pits
Patterns & Insights
2
MARKET
mkt mt es
MARKET TYPE
Fragmented Market
WHY THEY WON
Identity verification was historically split between legacy credit-bureau-based checks (Experian) and narrower point solutions (Onfido, Jumio) built for one specific use case like document scanning. Persona won by building a horizontally composable platform that any business — fintech, social platform, marketplace — could configure for its own specific identity questions, rather than a single fixed verification flow.
ENTRY STRATEGY
Greenfield Entry
EXECUTION
Built from scratch in 2018 by founders who had led identity teams at Dropbox and Square respectively — direct, first-hand experience with the exact problem (verifying who's real online) rather than acquiring into an existing identity vendor's fixed architecture.
FOOTHOLD STRATEGY
fs
Beachhead Strategy
Started with fraud-prevention-focused customers in regulated industries (fintech, marketplaces) needing KYC/AML compliance, a beachhead with clear, legally-mandated urgency, before expanding into broader trust-and-safety use cases (social platform age verification, AI platform bot prevention) as those needs became equally pressing industry-wide.
GROWTH CAMPAIGN
CAMPAIGNS THAT WORKED
Processing over 300 million verifications in 2024 while doubling revenue and customer count year-over-year reflects compounding demand from existing enterprise customers expanding usage across new identity use cases (KYC, then age verification, then AI-agent authentication) rather than one-time customer acquisition alone.
KEY LEARNING
When your core infrastructure applies to a new regulatory or trust requirement (like AI-agent identity or age verification laws), position quickly to serve that use case with your existing customer base before a new specialized competitor can — the same underlying verification technology often applies across many mandates, but customers won't realize that unless you tell them.
gc
Market Context
| MARKET INTELLIGENCE
THE STANDARD: Where incumbents ship a fixed verification flow, a horizontally composable platform lets any business configure its own identity questions.
RULE 1 — CONFIGURABILITY IS THE PRODUCT WHEN RISK TOLERANCE VARIES BY CUSTOMER. A marketplace, a bank and a social platform need different evidence for the same person.
RULE 2 — ORCHESTRATING MULTIPLE DATA SOURCES BEATS OWNING ONE. Routing across providers gives coverage and cost flexibility a single-method vendor cannot.
RULE 3 — IDENTITY IS REGULATED AND JURISDICTIONAL, WHICH IS THE MOAT. Compliance coverage across markets is slow, expensive and excludes fast followers.
RULE 4 — GENERATIVE FORGERY RAISES THE BAR CONTINUOUSLY. Document verification alone is degrading; liveness and signal aggregation are where the category is moving.
MARKET TYPE: Fragmented Market (identity verification).
| MARKET ENTRY PLAYBOOK
THE STANDARD: FOUNDERS WHO RAN THE FUNCTION AT SCALE KNOW WHICH ARCHITECTURAL RIGIDITY TO ATTACK.
RULE 1 — CONFIGURABILITY IS THE WEDGE AGAINST FIXED VERIFICATION FLOWS.
Every business has a different risk tolerance; incumbents force one flow. A configurable orchestration layer is a structural difference.
RULE 2 — IDENTITY IS BOUGHT WHEN FRAUD OR REGULATION FORCES IT.
Enter through the compliance trigger, not through efficiency.
RULE 3 — HOLDING IDENTITY DOCUMENTS IS A PRIVACY OBLIGATION ABOVE THE PRODUCT.
Data handling posture determines which markets and customers are even available.
How to enter
| FOOTHOLD STRATEGY PLAYBOOK
THE STANDARD: Start where the requirement is legally mandated, then follow the same capability into markets where it is merely urgent.
RULE 1 — ENTER WHERE NON-COMPLIANCE IS ILLEGAL, NOT MERELY RISKY. Regulated fintech and marketplaces must verify identity — the question is which vendor, never whether.
RULE 2 — CONFIGURABILITY IS THE DIFFERENTIATOR WHEN RISK APPETITES DIFFER. Every customer wants a different balance of friction and fraud tolerance; a fixed flow serves none of them well.
RULE 3 — THE SAME INFRASTRUCTURE SERVES ADJACENT PROBLEMS AS THEY BECOME URGENT. Age verification, bot prevention and platform trust reuse the identical capability.
RULE 4 — IDENTITY INFRASTRUCTURE CARRIES PRIVACY OBLIGATIONS THAT SCALE WITH ADOPTION. Data handling is a product requirement and a permanent regulatory exposure.
How to get the first strong position
MARKET PATTERNS & PLAYBOOK
3
MONEY
money rev pri
REVENUE MODEL
Usage-Based
PRICING MODEL
Usage-Based Pricing, Tiered Pricing
WHY THEY WON
Analyst estimates point to roughly 100% year-over-year revenue growth driven by modular product uptake, with net revenue retention reportedly above 120% — reflecting existing enterprise customers expanding usage across additional identity verification and compliance modules rather than growth being driven mainly by new customer acquisition.
Prices based on verification volume and the specific mix of identity checks selected (document scan, biometric liveness, database check), with pricing tiers scaling by both volume and the compliance/risk tooling required — a fintech doing heavy KYC pays differently than a social platform doing lightweight age checks.
TARGET AUDIENCE
CUSTOMER BUYING BEHAVIOUR
tg cb
Regulated fintech and marketplace companies needing KYC/AML compliance, social and gaming platforms needing age verification (Discord, Reddit), and increasingly AI platforms needing to verify human users and organizations interacting with agentic systems.
Enterprise, compliance-driven procurement for regulated industries where identity verification is legally mandated, alongside increasingly urgent trust-and-safety-driven adoption from consumer platforms responding to new age-verification regulations.
| PRICING INTELLIGENCE
What makes this model effective & make customers pay
Identity verification is priced per check, and the buyer's willingness to pay is set by fraud losses and regulatory exposure.
RULE 1 — PER-VERIFICATION PRICING IS COMPARED TO THE COST OF ONE FRAUDULENT ACCOUNT.
In financial services and marketplaces, that number is large and already measured.
RULE 2 — CONFIGURABILITY IS THE DIFFERENTIATOR BECAUSE RISK TOLERANCE VARIES BY CUSTOMER.
Letting the buyer set their own verification steps serves populations a fixed product cannot.
RULE 3 — COMPLIANCE MANDATES CREATE NON-DISCRETIONARY DEMAND.
KYC and AML obligations mean the purchase is required, not optimised.
RULE 4 — VERIFICATION FRICTION COSTS YOUR CUSTOMER CONVERSIONS.
Every additional step loses genuine users. The product must be priced against fraud prevented net of customers lost — a balance the buyer feels acutely.
A risk leader is buying the ability to onboard customers quickly without admitting fraudsters. Where two opposing costs meet, the vendor who moves both numbers commands pricing that neither alone would support.
PRICE & REVENUE
| Revenue Risk - The biggest threat to revenue stability
Net revenue retention above 120% driven by module expansion is the healthy shape: existing customers buying more, rather than growth resting on new logos.
Identity verification revenue tracks customer signup volume, which falls in a downturn with no churn event.
Compliance-driven demand is real and regulation-dependent — KYC and AML rule changes create and remove budget.
Generative AI is simultaneously a demand driver (deepfake fraud) and a threat (synthetic identities defeating verification). The arms race is a permanent cost line.
Roughly 100% year-on-year growth per analyst estimates; no company-disclosed ARR.
Where the model can break
4
MOTION
GROWTH EXPANSION MODEL
COMPETITIVE STRATEGY
motion ge cs
Market Development (New Customer Segments)
HOW THEY EXPAND
Expanded from its original fraud-prevention and KYC customer base into age-verification for social/gaming platforms and, most recently, identity verification for AI platforms and agentic systems (screening announced for OpenAI in 2025) — each new segment driven by a distinct new regulatory or trust pressure rather than the original fintech use case.
Differentiation
HOW THEY COMPETE
Differentiates from narrower point-solution competitors (Onfido, Jumio) through full customizability and modularity — letting a single customer combine exactly the checks they need rather than adopting a fixed verification flow built for a different industry's requirements.
GROWTH ENGINE
GTM
ge n gtm
Network Effects, API Ecosystem Growth
Reusable Personas (identity verified once, reusable across any Persona customer via Passkey) create a genuine cross-customer network effect — the platform gets more valuable to every business as more users have already been verified elsewhere in the Persona network, reducing friction for both the user and each new customer.
Enterprise and developer-led API adoption, with a growing focus on becoming the identity infrastructure specifically for the emerging agentic AI economy — positioning around 'the verified identity layer for an agentic AI world' in its most recent funding announcement.
SUSTAINING MOATS
Switching Costs, High Customer Lock-In, Brand Power, Technology Advantage (complex enterprise scenarios)
moat
The moat compounds two ways: the reusable identity network gets stronger as more customers join (each new customer benefits from users already verified by others), and deep, accumulated expertise navigating fragmented global compliance requirements (GDPR, KYC/AML, regional age-verification laws) is slow for a new entrant to replicate — though the February 2026 surveillance controversy shows that same regulatory-adjacent capability carries real reputational risk if trust in how it's used erodes.
| MOAT INTELLIGENCE
THE STANDARD: Identity verification is a network business where every fraud pattern seen for one customer protects all the others.
RULE 1 — CROSS-CUSTOMER SIGNAL IS THE COMPOUNDING ASSET. Recognising a fraudulent identity attempted at one company and blocked at another is intelligence no single customer could assemble, and it improves with every verification.
RULE 2 — REGULATED ONBOARDING MAKES YOU A COMPLIANCE VENDOR, NOT A SOFTWARE ONE. Know-your-customer obligations mean the buyer is transferring regulatory risk, which is why these relationships survive price competition.
RULE 3 — CONFIGURABLE VERIFICATION FLOWS BECOME EMBEDDED IN THE SIGNUP FUNNEL, and nobody rebuilds the highest-conversion path in their business to change vendor.
THE SIGNAL: generated identity documents and synthetic media are eroding document-based verification faster than most buyers realise. The defensible position is behavioural and cross-network signal, because the document itself is no longer trustworthy evidence.
Why this company remains defensible
ARR & TAKEAWAY
ARR Journey - what to do at each stage
PRE-$1M ARR — MAKE IDENTITY VERIFICATION CONFIGURABLE, NOT PRESCRIPTIVE
Every company has a different risk tolerance, geography and regulatory obligation. Selling a building-block platform rather than a fixed flow is the differentiation against rigid incumbents.
Land with fintechs and marketplaces facing onboarding fraud.
$1–5M ARR — PRICE PER VERIFICATION
Usage pricing scales with the customer's own onboarding volume and requires no renegotiation.
WATCH: verifications per customer per month and pass rates by segment.
$5–10M ARR — ORCHESTRATION ACROSS VENDORS IS THE MOAT
Routing between document checks, database checks, biometrics and watchlists — and switching providers without code — is what customers cannot rebuild.
$10–50M ARR — REGULATION IS THE PIPELINE
KYC, age verification and anti-fraud rules create mandatory demand. New legislation is a revenue calendar.
$50–100M ARR — AI-GENERATED FRAUD EXPANDS THE MARKET
Deepfakes and synthetic identities make verification harder and more valuable simultaneously. This is a category where the threat funds the product.
Reported rounds through 2025 at multi-billion valuations; figures are press-reported, not audited.
$100M+ ARR — NOT CONFIRMED
Rule: orchestration layers over commoditising vendors are defensible as long as switching between vendors stays hard for the customer and easy inside your product.
COPY PLAYBOOK : What Worked → What Failed → What to Replicate → What to Avoid
THE STANDARD: Reusable cross-customer credentials create a genuine network effect no single-customer tool can offer. Identity infrastructure at scale is one disclosure away from being reframed as surveillance.
SEQUENCE:
1. Make a verification reusable across your customer base.
2. Let each verification reduce friction at the next customer, compounding value.
3. Constrain and disclose exactly what the pipeline can check.
WORKED: Reusable credentials making reverification faster at each subsequent customer — a network effect single-customer verification cannot replicate.
CAUTION:
1. A FEBRUARY 2026 SECURITY RESEARCHER DISCLOSURE EXPOSED THE VERIFICATION PIPELINE, revealing up to 269 individual identity checks that could be run, and drew public criticism that age verification can quietly function as far broader surveillance. Assume your capability surface will be reverse-engineered and published.
2. IDENTITY INFRASTRUCTURE CARRIES REGULATORY AND REPUTATIONAL EXPOSURE disproportionate to its revenue.
bottom of page