deepidv
Vibe CodingSeptember 29, 202613 min read
N° 278

Securing a Vibe-Coded Fintech App: KYC, AML and the Code

What US and EU rules require of a fintech app, what the BaaS enforcement wave taught, and how to add KYC and AML with the deepidv MCP server and API.

If your vibe-coded app moves money, holds balances, lends, or opens accounts, it inherits the compliance obligations of the bank or licensed partner behind it. In the US that means a customer identification program: name, date of birth, address and an identification number, verified within a reasonable time, records kept five years, and a screen against government lists. In the EU the new AML regulation applies from July 2027 and the authority policing it is already operating. The 2024 to 2026 banking-as-a-service enforcement wave showed what happens when a fintech treats verification as a feature to be added later. This guide gives the rules, the build order, and the exact deepidv calls that satisfy them.

It assumes you have already run the vibe coding security checklist. Verification sits on top of a secure app, not instead of one.

What does the law require a fintech app to verify?

United States. The customer identification program rule for banks, 31 CFR 1020.220, requires collecting name, date of birth, address and an identification number before an account is opened, verifying identity within a reasonable time using documentary or non-documentary methods, forming a reasonable belief that the bank knows the true identity of each customer, keeping records for five years after the account closes, and checking government terrorist lists. If you build on a sponsor bank or a banking-as-a-service platform, that bank's program becomes your program by contract.

Money transmission, remittances and currency exchange are separately licensed and treated as restricted by payment processors; Stripe applies extra due diligence to money services businesses and limits availability for crypto exchanges and wallets.

European Union. The AML Regulation (2024/1624) applies from 10 July 2027, with the sixth directive transposed on the same date; the new Anti-Money Laundering Authority became operational in Frankfurt on 1 July 2025; the beneficial ownership threshold is 25 percent or more; and scope now covers crypto-asset service providers, crowdfunding platforms and consumer credit providers.

What did the BaaS enforcement wave teach?

That "the bank handles compliance" is not a plan. Synapse, the middleware between dozens of fintech apps and their sponsor banks, filed for bankruptcy in April 2024; the trustee estimated a shortfall of $65 million to $95 million and about $200 million of customer funds were frozen. Two months later the Federal Reserve ordered Evolve Bank to fix its anti-money-laundering program and its oversight of fintech partnerships, citing unsafe and unsound practices.

The fintechs on top of that stack did not choose those failures, but their customers lived with them. A fintech that owns its verification records, can prove every check, and screens continuously is a fintech a sponsor bank keeps.

What does a fintech verification flow need?

Six components, in the order a user meets them:

  1. Identity. Government ID captured and checked for authenticity, a face liveness check, and a match between the two.
  2. Screening. PEP and sanctions at onboarding, adverse media for higher-risk customers, both re-run on a schedule.
  3. Contact integrity. Phone ownership and carrier signals, so the number on the account belongs to the person.
  4. Risk signals. IP jurisdiction, VPN detection, injection detection on the capture.
  5. Monitoring. Transaction and behavior monitoring after onboarding, with filings when required.
  6. Proof. A tamper-evident record of every check for the bank, the auditor and the regulator.

deepidv covers all six behind one API. Workflow steps available today include ID_VERIFICATION, FACE_LIVENESS, AGE_ESTIMATION, PEP_SANCTIONS, ADVERSE_MEDIA, IP_JURISDICTION, VPN_DETECTION and INJECTION_DETECTION (create workflow); monitoring and filings are Arbiter, the compliance module; proofs are the chain layer.

How do you add it from Cursor or Claude Code?

Add the deepidv MCP server, then let the assistant build against real objects.

{
  "mcpServers": {
    "deepidv": {
      "url": "https://mcp.deepidv.com/v1/mcp",
      "transport": "http"
    }
  }
}

Sign in with your deepidv account (OAuth, no key in the file). The server exposes create_workflow, create_verification_session, run_pep_sanctions_check, run_adverse_media_check, run_phone_ownership_check, run_phone_trust_check and session tools (docs).

Prompt: "Using the deepidv MCP server, create a workflow named 'account-opening' with steps ID_VERIFICATION, FACE_LIVENESS, PEP_SANCTIONS and IP_JURISDICTION. Then add a server function that creates a verification session for a new user with that workflow, redirects them to the session_url, and handles the session.status.verified and session.status.rejected webhooks."

Ready to get started?

Start verifying identities in minutes. No sandbox, no waiting.

Get Started Free

The code

Workflow, once, from your backend or the console (reference):

curl -X POST https://api.deepidv.com/v1/workflows \
  -H "Content-Type: application/json" \
  -H "x-api-key: $DEEPIDV_API_KEY" \
  -d '{
    "name": "account-opening",
    "steps": [
      {"id": "ID_VERIFICATION", "config": {"minimum_age": 18}},
      {"id": "FACE_LIVENESS"},
      {"id": "PEP_SANCTIONS"},
      {"id": "IP_JURISDICTION"}
    ]
  }'

Session per user, server side, with the Node SDK (quickstart):

import { DeepIDV } from "@deepidv/server";
const client = new DeepIDV({ apiKey: process.env.DEEPIDV_API_KEY! });

export async function openAccountVerification(u: {
  id: string; firstName: string; lastName: string; email: string; phone: string;
}) {
  const s = await client.sessions.create({
    firstName: u.firstName,
    lastName: u.lastName,
    email: u.email,
    phone: u.phone,                       // E.164
    externalId: u.id,
    workflowId: process.env.DEEPIDV_ACCOUNT_OPENING_WORKFLOW!,
    redirectUrl: "https://yourapp.com/onboarding/complete",
  });
  return s.sessionUrl;
}

Direct screening when you need it outside a session (reference):

curl -X POST https://api.deepidv.com/v1/screening/pep-sanctions \
  -H "Content-Type: application/json" \
  -H "x-api-key: $DEEPIDV_API_KEY" \
  -d '{"firstName":"Jane","lastName":"Smith","email":"jane@example.com","dateOfBirth":"1990-04-12"}'

The response returns totalMatches, peps, sanctions and searchedSources, with per-match confidence and the dataset (for example us_ofac_sdn).

Webhook: register in the admin console, keep the whsec_ secret server side, act on session.status.verified, session.status.rejected, session.status.failed (webhooks). Do not let a user fund an account until verified has arrived.

Testing: the sandbox key returns canned sessions at GET /v1/sessions/test_verified and test_rejected (sandbox), so your state machine can be tested before a real document is captured.

What does it cost, and what does the bank want to see?

At the time of writing, deepidv's public list prices are $0.50 for identity verification with face liveness, $0.40 for PEP and sanctions, $0.25 for AML status, $0.15 for phone verification and $0.70 for a KYB check, with volume and term discounts. A sponsor bank will ask for your program document, your vendor's certifications (deepidv holds SOC 2, ISO 27001 and PCI DSS), your screening cadence, and evidence that checks happened. The evidence is the part most fintechs cannot produce; with deepidv it is a proof per check at proof.deepidv.com, verifiable without a login and with no personal data on chain.

Qualifying startups can apply to the deepidv Startup Program, which the site describes as free for 6 to 12 months with no usage caps for companies from idea stage to Series A, with fintech as a priority vertical.

Frequently asked questions

Does a small fintech app need KYC?

If it opens accounts, holds balances or moves money, yes, through the rules that bind its bank or licensed partner. The customer identification program requires name, date of birth, address and an identification number, verified, with records kept five years.

Can I use a vibe-coding tool to build a fintech app?

Yes, for the product. The verification layer must be a service built for it: liveness, document forensics, sanctions screening and audit trails are not things a generated function does. Add it through an API and an MCP server.

What is the difference between KYC and AML?

KYC verifies who a customer is at onboarding. AML is the ongoing program: screening against sanctions and PEP lists, monitoring transactions, and filing reports when required.

What happened with Synapse and Evolve?

Synapse, a banking-as-a-service middleware, filed for bankruptcy in April 2024 with a shortfall estimated at $65 million to $95 million and about $200 million of customer funds frozen. The Federal Reserve then ordered its partner bank to fix its AML program and fintech oversight.

When do the new EU AML rules apply?

The AML Regulation applies from 10 July 2027. The EU's new AML authority began operating on 1 July 2025.

How do I prove to a bank or auditor that I verified a user?

Keep a tamper-evident record per check. deepidv seals every verification into a signed, timestamped, chain-anchored proof that anyone can verify at proof.deepidv.com.

Start verifying identities today

Go live in minutes. No sandbox required, no hidden fees.

Related Articles

All articles

Vibe Coding in 2026: Tools, Numbers, Failures, and Fixes

What vibe coding is, who uses it, what it costs, what has broken, and how to ship a vibe-coded app safely with the verification layer done right.

Sep 29, 202614 min
Read more

The Vibe Coding Security Checklist: 14 Checks Before Launch

RLS, secrets, environments, dependencies, MCP configs, personal data, identity verification and app store rules. A pre-launch checklist with a prompt per fix.

Sep 29, 202611 min
Read more

Vibe-Coded Casino or Sweepstakes App: The 2026 Legal Reality

State bans, vendor liability, app store rules, processor bans, and the age and identity verification a real-money or sweepstakes app must have.

Sep 29, 202613 min
Read more