Hey Ed, thanks for doing this! I’m always heartened to see a new addition in the Privacy Tech space
I’d like to ask about your KYC provider:
Can you speak a bit towards the vetting & selection process you used when choosing this provider?
I’m under no illusions: KYC is an inherently de-anonymizing & non-private process, by definition
Regardless, I see some elements in their Privacy Policy that do give me pause as a KYC compliance layman:
…we may process some Personal data to develop and improve existing Services to prevent and detect fraud and other illicit activities, including by means of artificial intelligence…
…Sumsub may process biometrics to verify whether the facial images submitted to it are likely to belong to the same person… for this purpose, extracting facial features from uploaded or recorded facial images…
we use our Liveness check to determine if the User isn’t holding a mobile phone, showing any signs of constraint, or attempting to defraud the system using emulators, static images, or ‘deep fakes’. As a rule, Users are prompted to blink, smile, or move their device while passing Liveness
This sounds as though Sumsub may collect user biometrics & feed it into some undisclosed AI processing system… or am I reading too far into this?