{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "complycube",
    "name": "ComplyCube",
    "vendor": "ComplyCube (Teemo Technology Ltd)",
    "vendorUrl": "https://www.complycube.com",
    "kind": "http-api",
    "category": "identity-verification",
    "summary": "ComplyCube verifies people from identity documents and a liveness check, screens people and companies against sanctions, PEP and adverse media lists, and runs address and bureau checks. Agents reach it through a REST API with separate test and live keys.",
    "url": "https://www.anchorterminal.com/tools/complycube",
    "markdownUrl": "https://www.anchorterminal.com/tools/complycube.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/complycube.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/complycube.json",
    "repo": "https://github.com/complycube/complycube-php",
    "license": "Proprietary service under ComplyCube's terms of service. The PHP library and the web, iOS and Android SDK repositories are MIT, and `@complycube/api` on npm is MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.complycube.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@complycube/api"
      },
      {
        "registry": "pypi",
        "name": "complycube"
      }
    ],
    "auth": "api-key",
    "authNotes": "Every request carries an API key in the `Authorization` header, with no Bearer prefix. Each account has a test key (prefix `test_`) and a live key (prefix `live_`), created and rotated on the API keys page of the Web Portal by a signed-in Owner, Administrator or Developer. Keys have no scopes, and the docs say they carry many privileges. The live key opens when the account is activated from Test to Live in the portal. Client-side SDKs use short-lived tokens from `POST /v1/tokens` (https://docs.complycube.com/documentation/api-reference/authentication).",
    "pricing": "usage",
    "pricingNotes": "Starter is $99 a month and Core $299, each converted to credits spent per check, with further checks billed at plan rates. On Starter a document check is $1.05, standard AML screening $0.50 and a photo liveness check $0.35. Growth and Enterprise are quoted by sales. Only completed verifications are charged. The sandbox is free with a test key, and a 14-day trial of 50 checks starts on activation to Live (https://www.complycube.com/en/pricing/, checked 2026-10-08).",
    "priceSummary": "$99 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API reference, the OpenAPI spec or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 6182,
      "pypiWeekly": 292,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.complycube.com/documentation",
    "llmsTxt": "https://docs.complycube.com/documentation/llms.txt",
    "openapi": "https://2245032618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkAhgmUKSf8CFUFVL3GEe%2Fuploads%2FcpxxltxmYAxOotxgEkmP%2Fcomplycube-openapi.yaml?alt=media\u0026token=aa988fe0-8ce8-431c-a69a-6657f5eacf28",
    "capabilities": [
      "kyc.identity",
      "kyc.documents",
      "kyc.screening",
      "kyc.business"
    ],
    "tags": [
      "hosted",
      "usage-based",
      "sandbox",
      "api-key",
      "openapi",
      "llms-txt",
      "webhooks",
      "status-page",
      "python",
      "typescript",
      "php",
      "dotnet",
      "iso27001",
      "soc2"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 63.7,
      "grade": "B",
      "agentReady": false,
      "rank": 299,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 60,
        "maintenance": 74,
        "payments": 27,
        "reliability": 84,
        "schema": 78,
        "security": 52,
        "transparency": 63
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 84,
          "points": 16.8,
          "reason": "Graded on the REST API, hosted lines. Statuspage at status.complycube.com with API, Web Portal, Hosted Solution and each check type as components for Europe, US, Asia-Pacific and Middle East (20). The incident feed shows nothing in the 90 days to 8 October 2026, and its newest entry is a 21-minute minor Document Check incident on 8 August 2022 (30). Limits published as 10 requests a second live and 5 in the sandbox (15). 429 is documented with exponential backoff and jitter starting at 30 seconds, but no Retry-After header and no idempotency keys for writes were found (9). The pricing table lists an SLA as a plan feature and Enterprise advertises SLA-backed uptime, but no SLA text or figure is published (0). The API is generally available at v1 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "Public OpenAPI 3.0.0 spec, version 1.7.3, with 52 operations on 35 paths, linked from the integration page. Company search, address search and redaction are in the reference but not in the spec (22). `llms.txt` on the docs host and every page as Markdown (10). All 52 operations have a summary and 14 a description. Reference pages describe each attribute, and when not to use a method is rarely stated (12). Bodies are typed inline with 28 enums and 53 required lists, and the spec has no reusable component schemas (10). Reference pages carry request examples in cURL and four SDK languages, response examples and a table of 29 processing errors, while the spec has no examples and only a default error response (12). The path carries v1 and a versioning policy lists releases to 1.7.3 without dates. The product changelog is dated (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 60,
          "points": 9.75,
          "reason": "`pageSize` from 1 to 1,000 (default 100) and omitted null properties size responses. No field selection (12). `page` and `pageSize` plus created and updated date filters on every list, and attribute filters per endpoint. A badly formed filter returns 200 with no results (17). Errors return `type`, `message` and `param`, with 29 named processing errors on 422, several telling the end user what to retake (15). No idempotency keys or safe-retry guidance for creates. Duplicate handling is documented for webhooks only (3). Official client libraries for Node.js, Python, PHP and .NET. A document check takes at least four calls (client, document, image upload, check) (13)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 52,
          "points": 9.1,
          "reason": "One test key and one live key per account, sent in the `Authorization` header, rotated from the Web Portal. No scopes, and the docs say keys carry many privileges. The pricing table lists IP whitelisting (15). Test and live are separate, short-lived SDK tokens keep keys out of client code, and five portal roles limit who can manage keys. Keys have no read-only mode and deletes need no confirmation (8). Responses carry document data supplied by end users and adverse media text. No injection guidance was found (3). Audit log API with team member, trigger, action and field-level diff, covering API keys and allowed IPs among 17 resource types (14). ISO 27001:2022, SOC 2 Type II, Cyber Essentials and regular penetration testing are stated. No `security.txt` (404), disclosure policy or bug bounty was found, and the trust centre couldn't be read (12)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 27,
          "points": 3.38,
          "reason": "No x402, MPP or L402 (0). Starter is $99 a month and Core $299, each converted to usage credits, with per-check prices public (a document check is $1.05 on Starter and $0.75 on Core). Growth and Enterprise are quoted by sales, and several services show no price (17). The sandbox is free and returns dummy results. The 14-day trial of 50 checks starts when the account is activated from Test to Live, and whether that asks for a card wasn't established (10). Signup and key creation need a person in the Web Portal (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 74,
          "points": 6.48,
          "reason": "The changelog's latest entry is dated 6 October 2026 (30). Three dated entries in the last 90 days, on 14 July, 27 August and 6 October 2026 (20). Closed service with a dated changelog and a support site. The public SDK repositories show three open issues between them. Response times weren't measurable (10). `@complycube/api` 1.1.14 was published on 15 April 2026 and `complycube` 1.1.8 on PyPI on 8 December 2025. The PHP library was last pushed in June 2026. No entry in the official MCP registry (10). The Node.js and Python libraries have no public source repository, so tests and CI couldn't be seen. The Node.js package depends on axios ^1.15.0 (4)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 63,
          "points": 5.51,
          "note": "editorial 43, provenance 82",
          "reason": "Closed service. The terms of service carry no date, name ComplyCube without the legal entity, and are written around website use, Goods and Paid Content. The mobile and web SDK repositories and the PHP library are MIT (9). The privacy policy names Teemo Technology Ltd, says ComplyCube is a processor, uses client data for improvement only in anonymised or aggregated form, and answers a client's deletion request within 30 days. The pricing table gives 12 months of retention on Starter and indefinite above. The policy carries no date and no public DPA was found (16). A versioning policy lists changes treated as backward compatible. No deprecation notice period was found (6). Twelve data residency locations are published and AWS is named as host. The subprocessor list sits in the trust centre, which is drawn by script and wasn't read (12)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`pageSize` from 1 to 1,000 (default 100) and omitted null properties size responses. No field selection (12). `page` and `pageSize` plus created and updated date filters on every list, and attribute filters per endpoint. A badly formed filter returns 200 with no results (17). Errors return `type`, `message` and `param`, with 29 named processing errors on 422, several telling the end user what to retake (15). No idempotency keys or safe-retry guidance for creates. Duplicate handling is documented for webhooks only (3). Official client libraries for Node.js, Python, PHP and .NET. A document check takes at least four calls (client, document, image upload, check) (13).",
          "maintenance": "The changelog's latest entry is dated 6 October 2026 (30). Three dated entries in the last 90 days, on 14 July, 27 August and 6 October 2026 (20). Closed service with a dated changelog and a support site. The public SDK repositories show three open issues between them. Response times weren't measurable (10). `@complycube/api` 1.1.14 was published on 15 April 2026 and `complycube` 1.1.8 on PyPI on 8 December 2025. The PHP library was last pushed in June 2026. No entry in the official MCP registry (10). The Node.js and Python libraries have no public source repository, so tests and CI couldn't be seen. The Node.js package depends on axios ^1.15.0 (4).",
          "payments": "No x402, MPP or L402 (0). Starter is $99 a month and Core $299, each converted to usage credits, with per-check prices public (a document check is $1.05 on Starter and $0.75 on Core). Growth and Enterprise are quoted by sales, and several services show no price (17). The sandbox is free and returns dummy results. The 14-day trial of 50 checks starts when the account is activated from Test to Live, and whether that asks for a card wasn't established (10). Signup and key creation need a person in the Web Portal (0).",
          "reliability": "Graded on the REST API, hosted lines. Statuspage at status.complycube.com with API, Web Portal, Hosted Solution and each check type as components for Europe, US, Asia-Pacific and Middle East (20). The incident feed shows nothing in the 90 days to 8 October 2026, and its newest entry is a 21-minute minor Document Check incident on 8 August 2022 (30). Limits published as 10 requests a second live and 5 in the sandbox (15). 429 is documented with exponential backoff and jitter starting at 30 seconds, but no Retry-After header and no idempotency keys for writes were found (9). The pricing table lists an SLA as a plan feature and Enterprise advertises SLA-backed uptime, but no SLA text or figure is published (0). The API is generally available at v1 (10).",
          "schema": "Public OpenAPI 3.0.0 spec, version 1.7.3, with 52 operations on 35 paths, linked from the integration page. Company search, address search and redaction are in the reference but not in the spec (22). `llms.txt` on the docs host and every page as Markdown (10). All 52 operations have a summary and 14 a description. Reference pages describe each attribute, and when not to use a method is rarely stated (12). Bodies are typed inline with 28 enums and 53 required lists, and the spec has no reusable component schemas (10). Reference pages carry request examples in cURL and four SDK languages, response examples and a table of 29 processing errors, while the spec has no examples and only a default error response (12). The path carries v1 and a versioning policy lists releases to 1.7.3 without dates. The product changelog is dated (12).",
          "security": "One test key and one live key per account, sent in the `Authorization` header, rotated from the Web Portal. No scopes, and the docs say keys carry many privileges. The pricing table lists IP whitelisting (15). Test and live are separate, short-lived SDK tokens keep keys out of client code, and five portal roles limit who can manage keys. Keys have no read-only mode and deletes need no confirmation (8). Responses carry document data supplied by end users and adverse media text. No injection guidance was found (3). Audit log API with team member, trigger, action and field-level diff, covering API keys and allowed IPs among 17 resource types (14). ISO 27001:2022, SOC 2 Type II, Cyber Essentials and regular penetration testing are stated. No `security.txt` (404), disclosure policy or bug bounty was found, and the trust centre couldn't be read (12).",
          "transparency": "Closed service. The terms of service carry no date, name ComplyCube without the legal entity, and are written around website use, Goods and Paid Content. The mobile and web SDK repositories and the PHP library are MIT (9). The privacy policy names Teemo Technology Ltd, says ComplyCube is a processor, uses client data for improvement only in anonymised or aggregated form, and answers a client's deletion request within 30 days. The pricing table gives 12 months of retention on Starter and indefinite above. The policy carries no date and no public DPA was found (16). A versioning policy lists changes treated as backward compatible. No deprecation notice period was found (6). Twelve data residency locations are published and AWS is named as host. The subprocessor list sits in the trust centre, which is drawn by script and wasn't read (12)."
        },
        "sources": [
          {
            "what": "docs index for agents",
            "url": "https://docs.complycube.com/documentation/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API overview, client libraries and OpenAPI link",
            "url": "https://docs.complycube.com/documentation/api-reference/integration.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI spec",
            "url": "https://2245032618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkAhgmUKSf8CFUFVL3GEe%2Fuploads%2FcpxxltxmYAxOotxgEkmP%2Fcomplycube-openapi.yaml?alt=media\u0026token=aa988fe0-8ce8-431c-a69a-6657f5eacf28",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication",
            "url": "https://docs.complycube.com/documentation/api-reference/authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "test and live environments",
            "url": "https://docs.complycube.com/documentation/api-reference/sandbox-and-live.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits",
            "url": "https://docs.complycube.com/documentation/api-reference/rate-limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "service quota",
            "url": "https://docs.complycube.com/documentation/api-reference/service-quota.md",
            "seen": "2026-10-08"
          },
          {
            "what": "pagination",
            "url": "https://docs.complycube.com/documentation/api-reference/pagination.md",
            "seen": "2026-10-08"
          },
          {
            "what": "filtering",
            "url": "https://docs.complycube.com/documentation/api-reference/filtering.md",
            "seen": "2026-10-08"
          },
          {
            "what": "errors",
            "url": "https://docs.complycube.com/documentation/api-reference/errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "versioning policy",
            "url": "https://docs.complycube.com/documentation/api-reference/versioning.md",
            "seen": "2026-10-08"
          },
          {
            "what": "create a check",
            "url": "https://docs.complycube.com/documentation/api-reference/core-resources/checks/create-a-check.md",
            "seen": "2026-10-08"
          },
          {
            "what": "audit logs API",
            "url": "https://docs.complycube.com/documentation/api-reference/other-resources/audit-logs.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks guide",
            "url": "https://docs.complycube.com/documentation/integration-resources/webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "testing data",
            "url": "https://docs.complycube.com/documentation/integration-resources/testing-data.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server (documentation only)",
            "url": "https://docs.complycube.com/documentation/integration-resources/model-context-protocol-mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "teams and user roles",
            "url": "https://docs.complycube.com/documentation/access-management/teams-and-user-roles.md",
            "seen": "2026-10-08"
          },
          {
            "what": "compliance and certifications",
            "url": "https://docs.complycube.com/documentation/trust-and-compliance/compliance.md",
            "seen": "2026-10-08"
          },
          {
            "what": "data residency",
            "url": "https://docs.complycube.com/documentation/trust-and-compliance/data-residency.md",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog, 6 October 2026",
            "url": "https://docs.complycube.com/documentation/changelog/2026/6-oct-smarter-onboarding.md",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.complycube.com/en/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.complycube.com/en/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.complycube.com/en/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "security and compliance centre",
            "url": "https://www.complycube.com/en/company/security-compliance-center/",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.complycube.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.complycube.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://www.complycube.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Node.js library on npm",
            "url": "https://registry.npmjs.org/@complycube/api/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "Python library on PyPI",
            "url": "https://pypi.org/pypi/complycube/json",
            "seen": "2026-10-08"
          },
          {
            "what": "public repositories",
            "url": "https://api.github.com/orgs/complycube/repos?per_page=100",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search (no result)",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=complycube",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.verisign.com/com/v1/domain/complycube.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the trust centre at trust.complycube.com (drawn by script on Vanta), so the subprocessor list, the SOC 2 report status and any DPA there weren't read",
          "unchecked: whether signup or activating the 14-day trial asks for a payment card. The portal signup page is drawn by script",
          "unchecked: which plan the single-price rows of the pricing table belong to (age estimation, proof of address, fraud intelligence, continuous monitoring). The page text didn't show the column",
          "unchecked: the .NET library on NuGet and the Postman collection",
          "Whether a service agreement or DPA other than the public terms of service governs paid accounts. None was found on a public page",
          "Whether 429 responses carry a Retry-After header. None is documented",
          "The docs compliance table says SOC 2 Type II (Compliant), and whether an audit report exists wasn't established",
          "The docs `llms.txt` and each Markdown page end with GitBook's block of instructions addressed to AI agents (query the docs with an `ask` parameter). It wasn't acted on"
        ]
      },
      "negative": 0,
      "verdict": "A sandbox with its own key and scripted outcomes, a public OpenAPI spec, Markdown docs and an audit log API suit an agent running verification checks. Each environment has one unscoped key, no idempotency keys were found, and the only published terms are undated and read as website terms.",
      "bestFor": "An agent that creates clients, uploads documents, starts document, identity and AML screening checks and reads results for a regulated business, with low entry cost ($99 a month) and a scripted sandbox.",
      "strengths": [
        "Test and live environments have separate keys, and sandbox outcomes are set by test data such as a client last name of attention or failed",
        "Public OpenAPI 3.0.0 spec (version 1.7.3, 52 operations), `llms.txt`, and every docs page served as Markdown",
        "Audit log API records the team member, trigger, action and a field-level diff of old and new values",
        "Per-check prices are public for the Starter and Core plans, and failed or incomplete verifications are not charged",
        "Statuspage lists API, Web Portal and each check type for four regions, with no incident recorded since August 2022"
      ],
      "weaknesses": [
        "One API key per environment with no scopes. The docs say keys carry many privileges",
        "No idempotency keys, and no Retry-After header documented for 429 responses",
        "The only published terms are undated, read as website terms and cite the Data Protection Act 1998. No service agreement or DPA was found on a public page",
        "No `security.txt`, disclosure policy or bug bounty found, and the trust centre is drawn by script",
        "Company search, address search and redaction endpoints are in the API reference but not in the OpenAPI spec",
        "The ComplyCube MCP server serves documentation only and cannot reach account data"
      ],
      "agentNotes": [
        "Send the key bare in the `Authorization` header, with no Bearer prefix. Keys start `test_` or `live_`",
        "Create a client first, then documents or live photos for it, then `POST /v1/checks` with the client and upload IDs",
        "Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds",
        "A badly formed filter returns 200 with no results, so check filter names before trusting an empty list",
        "Checks are asynchronous. Subscribe to webhooks, verify the `ComplyCube-Signature` HMAC-SHA256 header, and expect duplicate and out-of-order events"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 63.7
        }
      ],
      "editorialScores": {
        "ergonomics": 60,
        "maintenance": 74,
        "payments": 27,
        "reliability": 84,
        "schema": 78,
        "security": 52,
        "transparency": 43
      },
      "provenanceScore": 82
    },
    "connect": {
      "install": "npm install --save @complycube/api",
      "http": "curl -X GET https://api.complycube.com/v1/clients \\\n     -H 'Authorization: \u003cYOUR_API_KEY\u003e'"
    },
    "letme": {
      "capability": "https://letme.dev/kyc.identity",
      "tool": "https://letme.dev/complycube"
    },
    "notable": [
      "The OpenAPI 3.0.0 spec (version 1.7.3) lists 52 operations on 35 paths, covering clients, addresses, documents, live photos, checks, workflow sessions, webhooks, custom lists, audit logs and SDK tokens (https://docs.complycube.com/documentation/api-reference/integration)",
      "Sixteen check types are created through `POST /v1/checks`, among them standard and extensive AML screening, document, identity, proof of address, multi-bureau, eID and age estimation checks (https://docs.complycube.com/documentation/api-reference/core-resources/checks/create-a-check)",
      "Sandbox outcomes are scripted. A client last name of attention returns an attention outcome, and failed returns not_processed (https://docs.complycube.com/documentation/integration-resources/testing-data)",
      "Rate limits are 10 requests a second live and 5 in the sandbox, with a monthly check quota of 1,000 on Starter and 8,000 on Core (https://docs.complycube.com/documentation/api-reference/rate-limits, https://www.complycube.com/en/pricing/)",
      "The ComplyCube MCP server at https://docs.complycube.com/documentation/~gitbook/mcp is read-only and serves documentation only, with no access to keys, clients or checks (https://docs.complycube.com/documentation/integration-resources/model-context-protocol-mcp)",
      "The status incident feed's newest entry is a minor Document Check incident on 8 August 2022, and the docs state 100% uptime across all regions for five years as ComplyCube's own claim (https://status.complycube.com/api/v2/incidents.json)",
      "Data residency is published for 12 locations, among them the EU, UK, US, Canada, Australia, Singapore and the UAE, defaulting to the EU elsewhere (https://docs.complycube.com/documentation/trust-and-compliance/data-residency)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "API",
        "value": "REST at https://api.complycube.com/v1 for both test and live keys. OpenAPI 3.0.0, version 1.7.3, with 52 operations on 35 paths (28 GET, 17 POST, 7 DELETE). Updates are sent as POST to the resource"
      },
      {
        "label": "Check types",
        "value": "standard_screening_check, extensive_screening_check, document_check, identity_check, enhanced_identity_check, proof_of_address_check, multi_bureau_check, eid_check, ssn_check, age_estimation_check, identity_fraud_check, driving_license_check, and device, email and mobile intelligence and face authentication checks"
      },
      {
        "label": "Credentials",
        "value": "One test key (`test_`) and one live key (`live_`) per account in the `Authorization` header, rotated in the Web Portal. No scopes. IP whitelisting is listed in the plan table. SDK tokens from `POST /v1/tokens` for client-side SDKs"
      },
      {
        "label": "Rate limits",
        "value": "10 requests a second live, 5 in the sandbox. Monthly check quota of 1,000 on Starter and 8,000 on Core, and both limits answer 429"
      },
      {
        "label": "Errors",
        "value": "JSON with `type`, `message` and `param`. 400, 401, 402 (credit plans), 403, 404, 413, 422 with 29 named processing errors, 429 and 500. No Retry-After documented"
      },
      {
        "label": "Paging and filters",
        "value": "`page` and `pageSize` (1 to 1,000, default 100) with createdAfter, createdBefore, updatedAfter and updatedBefore on every list, plus attribute filters joined by AND. A badly formed filter returns 200 with no results"
      },
      {
        "label": "Sandbox",
        "value": "Separate test key on the same host. All checks return dummy responses, with outcomes chosen by test data (last name attention or failed, middle name medium-risk or high-risk, OTP 123456). Sandbox data is deleted periodically"
      },
      {
        "label": "Webhooks",
        "value": "Created in the portal or through `/v1/webhooks`. Events are signed with HMAC-SHA256 over the request body in the `ComplyCube-Signature` header. Duplicates and out-of-order delivery are possible"
      },
      {
        "label": "Audit",
        "value": "`GET /v1/auditLogs` with team member, trigger, action and a diff of old and new values, across 17 resource types that include apiKeys and allowedIps"
      },
      {
        "label": "Client libraries",
        "value": "Node.js `@complycube/api` 1.1.14 (15 April 2026), Python `complycube` 1.1.8 (8 December 2025), PHP `complycube/complycube-php` and .NET `Complycube`. Web, iOS, Android, React Native and Flutter SDKs for capture"
      },
      {
        "label": "MCP",
        "value": "A documentation server at https://docs.complycube.com/documentation/~gitbook/mcp with no authentication. It searches and reads the docs and has no access to account data"
      },
      {
        "label": "Status",
        "value": "status.complycube.com on Statuspage, with API, Web Portal, Hosted Solution and check-type components for Europe, US, Asia-Pacific and Middle East"
      },
      {
        "label": "Certifications",
        "value": "ISO 27001:2022, SOC 2 Type II (Compliant), UK Cyber Essentials, ISO 9001:2015, UK DIATF and ISO 30107-3 testing per the docs compliance page. Evidence is in a trust centre that needs a browser"
      },
      {
        "label": "Data handling",
        "value": "ComplyCube is processor for client data. Retention is 12 months on Starter and indefinite on Core and Growth per the plan table, with custom retention on higher plans. Residency in 12 locations, EU by default, hosted on AWS"
      }
    ],
    "unitPrices": [
      {
        "item": "Starter plan",
        "unit": "month",
        "usd": 99,
        "note": "converted to usage credits; 1,000 checks a month quota"
      },
      {
        "item": "Core plan",
        "unit": "month",
        "usd": 299,
        "note": "converted to usage credits; 8,000 checks a month quota"
      },
      {
        "item": "Document verification check, Starter",
        "unit": "tx",
        "usd": 1.05,
        "note": "per completed check; $0.75 on Core"
      },
      {
        "item": "Standard AML screening, Starter",
        "unit": "tx",
        "usd": 0.5,
        "note": "per completed check; $0.35 on Core"
      },
      {
        "item": "Extensive AML screening, Starter",
        "unit": "tx",
        "usd": 1.05,
        "note": "per completed check; $0.85 on Core"
      },
      {
        "item": "Liveness and facial similarity check (photo), Starter",
        "unit": "tx",
        "usd": 0.35,
        "note": "per completed check; $0.20 on Core"
      }
    ],
    "provenance": {
      "legalEntity": "Teemo Technology Ltd",
      "domain": "complycube.com",
      "domainRegistered": "2018-05-24",
      "endpointOnVendorDomain": true,
      "terms": "https://www.complycube.com/en/terms-of-service/",
      "privacy": "https://www.complycube.com/en/privacy-policy/",
      "statusPage": "https://status.complycube.com",
      "changelog": "https://docs.complycube.com/documentation/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The privacy policy gives ComplyCube as the trading name of TEEMO TECHNOLOGY LTD, company number 12392069, Crown House, 27 Old Gloucester Street, London WC1N 3AX. The terms of service name only ComplyCube, registered in England and Wales, at that address.",
        "The terms of service are the only terms published. They define the Services to include ComplyCube's data and software services, but are written around website use, carry no date and cite the Data Protection Act 1998. No separate service agreement or DPA was found on a public page.",
        "The privacy policy covers the website and the Service and carries no date.",
        "The API answers at api.complycube.com, the Web Portal at portal.complycube.com and the docs at docs.complycube.com.",
        "www.complycube.com/.well-known/security.txt redirects to a 404 page, and api.complycube.com returns 403 for the same path.",
        "RDAP for complycube.com gives a registration date of 2018-05-24."
      ],
      "score": 82,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Teemo Technology Ltd",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "complycube.com, registered 2018-05-24 (8 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.complycube.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 4 of the 7 things a reader expects",
          "points": 7.4,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.complycube.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.complycube.com/en/terms-of-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 3430,
          "points": 7.4,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms and Conditions and the relationship between you and us shall be governed by and construed in accordance with the Laws of the United Kingdom and both we and you agree to submit to the exclusive jurisdiction of the Courts of the United Kingdom.",
              "says": "The law of the United Kingdom"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "We accept no liability for any disruption or non-availability of the Website resulting from external causes including, but not limited to, ISP equipment failure, host equipment failure, communications network failure, power failure, natural events, acts of war or legal restrictions and censorship."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Failure to comply with these rules may result in your Account being suspended or closed:"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not agree to the Agreement you must not use or access the Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Information sent through the vendor's communications system may be modified by the vendor in any way, and the sender waives the moral right to be identified as its author.",
              "quote": "You acknowledge that any information you send to Us through Our System may be modified by Us in any way and you hereby waive your moral right to be identified as the author of such information."
            },
            {
              "date": "2026-10-08",
              "text": "The vendor accepts no liability for direct or indirect loss arising from use of the Website or the information it contains, to the extent the law allows.",
              "quote": "To the maximum extent permitted by law, We accept no liability for any direct or indirect loss or damage, foreseeable or otherwise, including any indirect, consequential, special or exemplary damages arising from the use of the Website or any information contained therein."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.complycube.com/en/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 5670,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We collect different types of information from or through the Service from the following categories of data subjects:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We only retain the Personal Data collected from a User for as long as the User’s account is active or otherwise for a limited period of time as long as we need it to fulfill the purposes for which we have initially collected it, unless otherwise required by law."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "In issuing OTP Messages, we act strictly on the Client’s instructions and process any related personal data only in accordance with our role as the Client’s service provider."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "We respect your privacy rights and provide you with reasonable access to the Personal Data that you may have provided through your use of the Services."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you would like to exercise these rights please contact the relevant Client that carried out your related check or contact us at privacy@complycube.com.",
              "says": "privacy@complycube.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "In case your Personal Data is provided to service providers outside the EEA/UK, and where applicable, we will implement appropriate safeguards to protect your Personal Data, including Standard Contractual Clauses as adopted by the European Commission.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Client Data may be used to improve the service and develop new products, in anonymised or aggregated form only.",
              "quote": "Should this purpose require ComplyCube to process Client Data, then the data will only be used in anonymized or aggregated form."
            },
            {
              "date": "2026-10-08",
              "text": "After a client asks for data to be removed, the vendor may keep a copy for archiving or to defend its rights in litigation.",
              "quote": "We reserve the right to retain a copy of such data for archiving purposes, or to defend our rights in litigation."
            },
            {
              "date": "2026-10-08",
              "text": "The client may choose where personal data is processed and stored.",
              "quote": "The Client may choose the location of personal data processing (including storage) to comply with the applicable laws."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/complycube.json",
    "live": {
      "slug": "complycube",
      "probe": {
        "target": "https://api.complycube.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:08.016023639Z",
        "lastOk": true,
        "lastStatus": 403,
        "lastMs": 28,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 32,
        "p95ms24h": 67,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.complycube.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:05:57.230738482Z"
      },
      "updatedAt": "2026-10-08T21:12:08.016023639Z"
    }
  }
}
