The typical implementation of Ondato is designed to be seamless and flexible, adapting to your organization’s needs. Here's a step-by-step guide along with estimated timelines:
Initial Assessment & Requirements Gathering
Your team works with Ondato’s sales and solution engineers to define verification needs, risk thresholds, and regulatory coverage. Together, you establish which modules you require (e.g., KYC, KYB, AML screening) and set integration goals.
Estimated duration: 1–2 weeks.
Account Setup & Environment Configuration
Ondato provisions a secure, cloud-hosted environment (test and production), configures role-based access, and sets up necessary credentials.
Estimated duration: 1–3 days.
Integration & API/SDK Development
Developers integrate either the Ondato Web/Mobile SDK or API endpoints. Ondato provides comprehensive guides for both UI‑based and headless integrations, covering KYC, KYB, face verification, and webhooks for onboarding events.
Estimated duration: 2–4 weeks, depending on integration complexity and platform scope.
Workflow Configuration & Customization
Compliance teams customize onboarding flows using Ondato’s no-code workflow builder. This includes setting triggers for supplemental checks, languages, document types, and UI text.
Estimated duration: 1–2 weeks.
Pilot Testing & QA
A small-scale pilot is launched to validate document capture, biometric checks, screening accuracy, notifications, and case assignment. Feedback loops enable refining UI, webhook logic, and escalations.
Estimated duration: 1–2 weeks.
Training & Documentation
Ondato provides onboarding resources, API documentation, user guides, and training sessions for both technical and compliance stakeholders.
Estimated duration: 1 week (concurrently with testing).
Go-Live & Post-Deployment Support
Once validated, the solution moves to production. Ondato ensures monitoring, SLA-backed support, and iterative updates. Client teams transition to continuous risk monitoring, case management, and audit reporting.
Estimated duration: Production cutover takes 1–2 days; monitoring and support are ongoing.
Total estimated implementation timeline: 5–10 weeks, varying with integration depth and workflow complexity.
Ondato is designed to be highly adaptable, allowing organizations to tailor the platform to fit unique business needs and compliance requirements. Here are key customization options:
Compliance teams can define multi-step onboarding flows tailored to segments or risk levels—e.g., requiring video verification or supplemental documents for high-risk profiles—without writing code.
The platform supports fully customizable forms for both individual (KYC) and business (KYB) onboarding. You can include branded fields, custom questions, and dynamic requirements such as UBO disclosures, proof-of-address uploads, or conditional questions.
Ondato operates on a modular basis—KYC, KYB, AML, CDP, case management, e-signature, age verification, etc.—that can be selected à la carte. Organizations select and pay only for the modules they need, reducing unnecessary bloat.
Clients can fetch official business registry data via API and integrate their own third-party or in-house data sources for enrichment or screening. This enables customized risk scoring and checks beyond standard sanctions or PEP lists.
Web or mobile SDKs are fully white-labeled, allowing control over UI flow, branding, languages, layout screens (start, loading, success), and inclusion of advanced modules like NFC or screen recording.
Developers can tailor device-level settings, quality gates, and asset capture flows directly in the SDK configuration.
Ondato supports granular webhook events during onboarding—such as “KYC started”, “ID approved/rejected”, “KYB filing done”, “e-signature completed”—enabling seamless automation, CRM-triggered tasks, and downstream orchestration via your existing systems.
The interface is multilingual—supporting Arabic, German, and non-Latin scripts—and can be configured per flow or user segment.
Form texts, instructions, and risk rules can adjust for regional regulatory needs, such as age-restricted industries or locale-specific document types.
Organizations can configure access roles and permissions, establish audit trails, and enable encryption/sandboxing tuned to internal policies and compliance standards (e.g., GDPR, ISO 27001).
These rich customization options enable Ondato to serve businesses across fintech, telecoms, marketplaces, gambling, insurance, and beyond—tailoring identity and risk workflows to match each organization’s compliance frameworks, user journeys, and technology stacks.
Ondato uses a custom pricing model, so exact figures vary by client size and modules selected. However, typical cost components include:
Ondato offers comprehensive onboarding and support:
Ondato implements enterprise-grade security controls:
Ondato follows a continuous improvement cycle, releasing updates regularly to address compliance changes, security enhancements, and feature upgrades. Minor updates and bug fixes are typically rolled out monthly or bi-weekly, while major feature releases occur quarterly. Updates are managed through cloud deployment, meaning clients automatically receive the latest version without manual intervention. For on-premise or custom environments, Ondato provides scheduled update windows and advanced notifications. Release notes and documentation accompany each update, ensuring compliance teams and developers understand new features and changes.
Ondato operates under GDPR-compliant principles, meaning clients retain full ownership of their data. The platform acts as a processor, not a controller, and does not use client data for any purpose beyond agreed compliance workflows. Data portability is supported through export options in standard formats (CSV, JSON, or via API), enabling organizations to migrate or back up data easily. Clients can request full data extraction at any time, and Ondato ensures secure transfer protocols during such processes. Additionally, data deletion requests are honored promptly to meet regulatory requirements.
Ondato offers flexible, modular pricing and deployment, allowing businesses to scale up or down based on transaction volumes and compliance needs. Scaling up typically involves adding more verification credits, enabling additional modules (e.g., KYB, AML screening), or expanding API capacity. Scaling down is possible by reducing active modules or lowering verification limits, subject to contract terms. Most agreements include usage-based billing, so costs align with actual consumption. Ondato also supports enterprise SLAs for rapid scaling during peak onboarding periods, ensuring performance and uptime remain unaffected.
These terms and standards position Ondato as a robust, compliant solution for regulated industries requiring high data security, legal alignment, and operational flexibility.