Vendor comparison
Veriff vs Incode vs deepidv: The Highly Effective Age Bar
Veriff, Incode, and deepidv compared against Ofcom's highly effective age assurance bar: present-user proof, tested accuracy, and regulator-ready evidence.
An operational engineering analysis evaluating deepidv, Veriff, and Incode against the standard Ofcom is now enforcing by investigation: highly effective age assurance, with due diligence and testing a platform can produce when the regulator asks.
Ofcom's probe into Aylo's device-signal age checks changed the vendor conversation. The question stopped being which estimator quotes the best mean absolute error and became which stack proves the present user, degrades gracefully across methods, and arrives at the examination with its testing already documented. Veriff, Incode, and deepidv all sell age assurance; they distribute their strength across that new job differently.
The highly-effective scorecard
| Capability | deepidv | Veriff | Incode |
|---|---|---|---|
| Facial age estimation | Buffer-policy estimation on structural liveness | Estimation integrated with IDV flows | Estimation, strong published benchmark focus |
| Present-user proof (family-device gap) | Session-level liveness-anchored checks, native | Selfie-based flows with liveness | Liveness within its platform flows |
| Method layering (signals, estimation, credentials) | One decision plane, per-action policy | Estimation plus document verification routes | Estimation plus document and database routes |
| Injection and deepfake defense at capture | deepeye structural liveness plus injection detection | Vendor liveness stack | Vendor liveness stack, NIST-benchmarked components |
| Regulator-ready testing evidence | Measured accuracy, circumvention stats, exportable per decision | Reports available on engagement | Benchmark results, platform reporting |
| Anonymous age-only mode | Estimate-and-discard supported | IDV-centric heritage | Supported in age products |
Three stacks meet one bar
deepidv: assume the examination
deepidv's design premise matches the moment: every age decision will eventually be examined, so the stack is built backward from the evidence. Estimation runs only on deepeye's structural liveness, which closes the gap Ofcom is investigating, proof that the face being measured belongs to the human present, not to a photo, a replay, or the device owner's enrollment. Signals, including OS age brackets, enter the decision plane as inputs with policy weight rather than verdicts; contested and boundary cases escalate to credentials; and the system assembles per-decision records with measured accuracy and circumvention statistics. The layered method logic is the product, not a configuration.
Veriff: age assurance inside an IDV engine
Veriff comes at age from identity verification: document authentication, biometric matching, and liveness at high volume, with age estimation as a route inside those flows. That heritage is a real advantage wherever age assurance and identity verification are the same purchase, gambling and fintech onboarding above all. The trade-off runs the other way on anonymous age checks: an IDV-centric stack is heavier than the age-only question needs for content gating, where regulators and privacy authorities increasingly prefer estimate-and-discard. Platforms choosing Veriff for age-only use cases should scope the data minimization story explicitly.
Incode: the benchmark competitor
Incode has invested visibly in measured performance, with NIST-benchmarked components and published accuracy positioning, and its age estimation sits inside a broad identity platform. For buyers who anchor procurement on public benchmarks, that legibility is genuinely useful. The bar's remaining questions are the operational ones benchmarks do not settle: how the stack behaves on the deployed population rather than the test set, how boundary and contested cases route across methods, and what evidence exports look like when a regulator wants this platform's numbers, not the lab's. Strong benchmark performance plus documented in-production testing is the complete answer; either alone is half of one.
The test that decides it: the inherited device
Run the Aylo scenario against any candidate stack. A 14-year-old opens the platform on a parent's phone: the OS signal says adult, a saved card says adult, and every inference the device can offer is wrong about the human holding it. A stack that trusts the signal admits the child, and a stack that answers with an estimation check must then survive the second layer of the same attack, the child pointing the camera at a photo of the parent, which is where structural liveness and injection detection decide the outcome, not the estimator's headline accuracy. The passing stack catches the present user at the session, routes the boundary case by buffer policy, and writes the whole event into the record the investigation will read.
Frequently asked questions
What counts as highly effective age assurance under the UK Online Safety Act?
Methods that reliably establish whether a user is a child, tested and documented for the deployed context. Ofcom's Aylo investigation signals that device-owner signals alone may not clear the bar, and that platforms must show due diligence and testing, not just a method choice.
How do Veriff, Incode, and deepidv differ on age verification?
Veriff embeds age estimation in a high-volume IDV engine, strongest where identity and age are one purchase; Incode leads with benchmarked accuracy inside a broad platform; deepidv builds age decisions on structural liveness with layered methods and per-decision evidence designed for regulatory examination.
Why does liveness matter for facial age estimation?
Because the estimator measures whatever image it receives: without liveness and injection detection, a child presents a photo of an adult and the system confidently ages the photograph. Structural liveness proves the measured face is the present human.
What evidence should platforms keep for age assurance audits?
Per-decision records naming the method, signal inputs, estimation confidence, escalations, and outcome, plus program-level measured accuracy on the deployed population and circumvention statistics.
Can platforms rely on Apple or Google device age signals?
As one input, yes; as the whole program, that is exactly what Ofcom is investigating. Device signals attest the owner's age, not the present user's, so highly effective stacks corroborate them with session-level checks where the risk warrants.
Ship this with one API
Everything above runs on the deepidv verification engine: one modular API, drop-in SDKs, and an MCP server your coding assistant can build against. Read the docs or see it live on your use case.
Start verifying identities today
Go live in minutes. No sandbox required, no hidden fees.