Identity Impersonation Detection White Paper Read Now
Both can check a US driver's license against DMV records. The difference is what each platform asks the person to do, and what it keeps when the check is done.
Incode is an AI identity platform that verifies people with a government ID and a live selfie. Trusona ATO Protect verifies the ID itself against the agency that issued it, with no selfie and no stored personal data.
To be fair to both: if the job is onboarding customers at scale with KYC checks, Incode built a platform for that job. If the job is stopping an impersonator on tomorrow morning's help desk call, that is the only job ATO Protect does, and the two products go about it very differently.
ATO Protect verifies callers during password resets, MFA changes, and other high-risk requests. The caller scans a government ID, and Trusona checks it against the issuing DMV through AAMVA in real time.
There is no selfie and no enrollment step, so it works the first time an employee or customer ever calls. Trusona stores no PII, flags SIM swaps and recently ported numbers, and detects man-in-the-middle and replay attacks (US Pat. 10,601,859).
With Agent Verify, the check runs in both directions: the caller can confirm the agent is real before sharing anything.
Incode verifies identity for customer onboarding, KYC and AML compliance, business verification, age checks, and workforce security. The standard flow pairs document verification with a live selfie, screened by Incode's liveness and deepfake detection.
That first check builds a verified profile. From then on, the person authenticates with a new selfie that Incode matches against it, including at help desk and MFA reset moments through its Workforce product.
The platform integrates with IAM and ITSM tools including Okta, Microsoft, Ping Identity, ServiceNow, Zendesk, and Jira, and holds a SOC 2 Type II attestation.
Incode's answer to deepfakes is to inspect the face. Its liveness models analyze micro-expressions, lighting, and motion, and its device integrity checks look for injected or replayed camera streams. That is detection, and detection is a race: every new generation of synthetic video has to be caught by a new generation of models.
Trusona's answer is to take the face out of the equation. If no selfie is collected, there is no selfie to fake, so there is no race to run. Trusona verifies the document against the source that issued it, and phone-channel signals like SIM swaps and port-outs catch the attacker's infrastructure rather than their face.
The same logic applies to the data. You cannot breach a face database that was never built.
A selfie match needs something to match against. In Incode's Workforce flow, an employee first enrolls with a government ID and a live selfie; from then on, a new selfie is compared to that stored profile. Anyone who has not enrolled yet cannot be verified that way: the new hire on day one, the contractor who was never onboarded, the employee who skipped the rollout email. Those are exactly the accounts an attacker calls about.
Trusona has no enrollment step to skip. The very first call someone ever makes to your help desk can be verified against the DMV, which closes the window between "hired" and "protected."
| Capability | Trusona ATO Protect | Incode |
|---|---|---|
| DMV verification (AAMVA) | Yes | Yes (AAMVA data verification) |
| Requires a live selfie | No selfie | Yes, in the standard ID + selfie flow |
| Stores PII or biometric profiles | No stored PII (SOC 2) | Yes. Verification builds a profile that later selfies are matched against |
| Works with no prior enrollment | Yes, including first-time callers | Enrollment first, then selfie authentication |
| Focus | Help desk impersonation detection | Onboarding, KYC/AML, KYB, age checks, workforce |
| SIM-swap and port-out detection | Yes | Not published |
| Man-in-the-middle and anti-replay detection | Yes (US Pat. 10,601,859) | Injection and replay detection on selfie capture |
| Reverse check: caller verifies the agent | Yes (Agent Verify) | Not published |
| Help desk tooling | Real-time result in ServiceNow | ServiceNow, Zendesk, and Jira integrations |
| SOC 2 | Yes | Yes (Type II) |
"Not published" means the capability does not appear in Incode's public product materials or developer documentation as of August 2026. Incode capabilities are described from incode.com and developer.incode.com.
Yes. Both check US driver's license data through AAMVA. The difference is everything around that check: Incode pairs it with a selfie and builds a stored profile, while Trusona verifies the document alone and keeps nothing.
Incode verifies a person by matching a live selfie to an ID, and later to a stored profile. Trusona verifies the ID itself against the agency that issued it. One approach depends on facial recognition and retained biometric data. The other collects no face and stores no PII.
Yes. Incode Workforce prompts the employee to take a live selfie, which it matches to the profile created when they enrolled with an ID and selfie. That enrollment has to exist first. Trusona needs no enrollment at all, so it also covers the first call an employee or customer ever makes.
With Trusona, nothing remains. No selfie is taken and no PII is stored, so there is nothing to retain, subpoena, or breach. A selfie-match platform works differently by design: it must retain a verified profile to match against, which makes data storage, biometric privacy law (BIPA, GDPR), and breach exposure part of the evaluation. Ask any selfie-based vendor where profiles live, how long they persist, and what happens to them at offboarding.
No. Trusona never captures a selfie or a biometric. It verifies the government ID against the issuing DMV and checks the phone channel for signals like SIM swaps and recent port-outs.
Every comparison lives in the Product Comparisons library.
Watch ATO Protect check an ID against the DMV during a live help desk call, including a caller you have never seen before. No selfie, no enrollment, nothing stored.