Jumio
United States · www.jumio.com · 22 vendors
Jumio provides AI-driven identity verification, risk assessment, and AML compliance solutions. The company leverages biometrics, machine learning, and liveness detection to help businesses fight fraud, onboard customers faster, and meet regulatory requirements.
Resilience scores
- Digital Sovereignty: 64
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Demandware — Technology — United States
- InstaID — Australia
- Stripe, Inc. — Financial Services — United States
- and 25 more
Services catalogue
5 services in catalogue across 4 categories; runs on 22 sub-vendors.
- Machine Learning
- Jumio
- Personal Data Processing
Insights
Last updated 2026-08-15 · revision 1
22 direct vendors, 271 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- Canada: 1
- United States: 14
Subvendors by controlling owner country (sample)
- India: 2
- Romania: 1
- Singapore: 2
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Jumio exhibits a high level of migration readiness, scoring 85. This is primarily driven by its extremely modern and cloud-native internal tech stack. The company is built on Amazon Web Services (AWS) and extensively uses Kubernetes and Docker for containerization, indicating a highly portable and flexible architecture. The adoption of Terraform for infrastructure as code significantly streamlines infrastructure provisioning and management, making migrations more efficient and less error-prone. The reliance on REST APIs and the modular nature of their products suggest an architectural style conducive to microservices, facilitating independent deployment and migration of components. Additionally, the geographic diversity of vendor HQs across eight unique countries suggests that Jumio is not overly reliant on a single regional vendor ecosystem, which could simplify vendor transitions during a migration. Key data gaps that prevent an even higher score include the lack of specific information on regulatory compliance requirements and data residency constraints, which can significantly impact migration complexity for a cybersecurity company. Information on financial stability, crucial for funding large-scale migrations, is also missing. While vendor geographic diversity is a strength, the specific number of distinct vendors and the complexity of contracts (which contribute to lock-in) are not detailed, though the modern tech stack generally mitigates these concerns.
Compliance
14 in-scope frameworks identified; showing 3.
FINTRAC PCMLTFA — Compliant
Jumio explicitly maintains a FINTRAC PCMLTFA compliance page, demonstrating active engagement with Canadian AML regulatory requirements. As a technology provider to Canadian financial institutions and reporting entities, Jumio's platform must meet FINTRAC's identity verification requirements under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act. The risk is Low because Jumio's role is as a compliance enabler.
Evidence: https://www.jumio.com/compliance-regulations/fintrac-compliance/, https://www.jumio.com/compliance-regulations/
Washington State My Health MY Data Act — Compliant
Jumio has proactively published a Washington State Consumer Health Privacy Notice, demonstrating active compliance with the Washington My Health MY Data Act. This is a positive compliance indicator. The risk is Low because Jumio has already taken the required disclosure steps.
Evidence: https://www.jumio.com/privacy-center/privacy-notices/mhmd-notice/, https://www.jumio.com/privacy-center/
SOC 2 (source) — Compliant
Jumio is a cloud-based SaaS identity verification platform that processes sensitive personal and biometric data for thousands of enterprise clients globally. SOC 2 compliance is a standard market expectation for such providers, and Jumio's trust center (trust.jumio.com) — dedicated to security and compliance — strongly indicates active SOC 2 compliance. The risk is Low because: (1) Jumio's business model as a B2B SaaS provider makes SOC 2 a commercial necessity (enterprise clients require it); (2) the existence of a dedicated trust center signals mature security compliance practices; (3) SOC 2 Type II reports are typically renewed annually, reducing the risk of lapsed compliance. The primary residual risk is that the specific SOC 2 report scope and any exceptions are not publicly disclosed.
Evidence: https://trust.jumio.com/, https://www.jumio.com/privacy-center/, https://www.jumio.com/about/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Jumio is a privately held, PE-backed identity verification company that does not disclose audited financials. The last hard revenue reference point is the company's own March 2021 disclosure of '$100M+ ARR' at the time of Great Hill Partners' $150M growth investment. Since then, no revenue, EBIT, or equity figures have been made public, making independent assessment of profitability, cash burn, or leverage impossible. However, the company benefits from three well-capitalized growth-equity sponsors (Centana, Great Hill, Millennium), significant scale (>1 billion transactions processed, 200+ countries, 5,000+ ID types, 300+ patents), and an enterprise customer base in regulated verticals (banking, iGaming, crypto, travel) which typically produces sticky, multi-year, usage-based SaaS revenue. On the risk side, the identity verification market is highly competitive (Onfido/Entrust, Persona, Socure, Sumsub, iProov, Trulioo, Veriff, IDnow) with recent evidence of valuation compression across the peer group. Jumio has also had two CEO changes in four months during 2026 (Bala Kumar as interim in January, Mark Lorion as permanent in April), which may signal strategic recalibration. Exposure to cyclical crypto and gaming verticals, biometric/privacy regulatory risk (BIPA, GDPR, AI regulation), and a maturing sponsor investment (now ~5 years old) that will eventually require a liquidity event add further uncertainty. On balance, resilience appears moderate: strong sponsor backing and product moat are offset by opacity, leadership turnover, and competitive pressure.
Key strengths: Well-capitalized PE ownership by Centana, Great Hill Partners, and Millennium Technology Value Partners, $150M growth financing led by Great Hill Partners in March 2021, Disclosed $100M+ ARR as of March 2021 (last public revenue reference), Scale: >1 billion transactions processed across 200+ countries, 5,000+ ID types supported and 300+ patents/applications, Enterprise customer base in regulated verticals (Alaska Airlines, United Airlines, Webull, BoyleSports, Stanleybet, Fortune 500 financial services firm), Recurring/usage-based SaaS model with high gross margins, Product breadth expansion into continuous identity intelligence (Jumio Watch, Jumio Smart, selfie.DONE)
Risk factors: No published financials; opacity around profitability, cash burn, and leverage, Highly competitive market with peers Onfido, Persona, Socure, Sumsub, iProov, Trulioo, Veriff, IDnow, Two CEO changes within four months in 2026 (Bala Kumar interim in January, Mark Lorion permanent in April), Cyclical exposure to crypto and iGaming end-markets, Regulatory and privacy risk from biometric products (BIPA, GDPR, AI regulation), PE sponsor exit horizon approaching (~5 years since 2021 investment), Peer valuation compression (e.g., Socure reset from ~$4.5B)
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.