INNOVATION DROPSUMMER
EDITION
20
26
Three product drops. Every Tuesday
1st Sep | 02:00 PM UTCRESERVE YOUR SPOT NOW
INNOVATION DROPSUMMER
EDITION
20
26
1st Sep | 02:00 PM UTCRESERVE YOUR SPOT NOW
Innovation Drop — Summer Edition 2026Reserve
Shufti logosBUILT BY SHUFTIHow identity verification really gets built3rd Sep | 02:00 PM UTCREGISTER NOW Shufti logosBUILT BY SHUFTIHow identity verification really gets built3rd Sep | 02:00 PM UTCREGISTER NOW Built by Shufti — how IDV really gets builtRegister WebinarShufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle18th Sep | 02:00 PM UTCREGISTER NOW Shufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle18th Sep | 02:00 PM UTCREGISTER NOW How AMLR Extends KYC Across the LifecycleRegister One sign-up screen. One rulebook behind it;  AMLR, eIDAS 2.0, EUDI wallet.Read the GUIDE One sign-up screen. One rulebook behind it;  AMLR, eIDAS 2.0, EUDI wallet.Read the GUIDE AMLR, eIDAS 2.0 & EUDI walletRead the guide Gartner Recognises Shufti for Processing Diverse Identity Documents WorldwideGartner® Magic Quadrant™Read now Gartner Recognises Shufti for Processing Diverse Identity Documents WorldwideRead now Gartner recognises Shufti worldwideRead now Shufti x FTAHKWebinarThe Lifecycle of a Compliant Crypto TransferTravel Rule, Wallet Verification & Counterparty Risk05:00 PM HKT9th September, 2026Register Now Shufti x FTAHKTravel Rule, Wallet Verification & Counterparty Risk9th September, 2026Register Now Compliant Crypto Transfer — Travel Rule & moreRegister Shufti x ACFEWebinarAI has changed fraud. Now we need to change how we fight it.Microphone icon for Shufti and ACFE fraud webinar5th October, 2026Register Now Shufti x ACFEAI has changed fraud. Now we need to change how we fight it.5th October, 2026Register Now AI has changed fraud — change how we fight itRegister

de

35.198.113.100

Crowdfunding

One compliance platform for every crowdfunding raise

Shufti verifies every backer, vets every fundraiser and screens both continuously. Built for ECSPR CSPs, AMLR-obliged crowdfunding platforms, US Reg CF portals and UK P2P marketplaces.

Shufti crowdfunding compliance ring: verify backer, vet fundraiser, screen both, monitor 24/7 and keep a regulator-ready audit trail

Trusted by Leading Digital Enterprises Worldwide

Cashew logo GemOne logo Heroo logo Bitget logo IronFX logo PENN Entertainment logo Rakuten logo Witzeal logo Noteris logo

COMPLIANCE WITHOUT COMPROMISE

Why Crowdfunding Platforms Choose Shufti

  • Ready for every crowdfunding rule

    Shufti keeps your platform in line with the rules that apply to crowdfunding today and the new EU AMLR rules landing in 2027. Every check on every backer and every fundraiser is logged, dated and ready for a supervisor to open, without your team scrambling to explain it.

  • Catch fraud on both sides of the raise

    Shufti verifies the person applying to invest and the business asking to raise, on the same platform. Deepfake detection catches AI-generated faces on the backer side. Business checks catch shell companies and hidden owners on the fundraiser side. Nothing goes live until both sides are clear.

  • Fast approvals, Ongoing peace of mind

    Shufti approves most backers in seconds, with ready-made forms for the investor questions every jurisdiction asks. Sanctions and adverse-press screening keeps running quietly in the background, so backers and fundraisers stay clean between raises.

Secure Every Stage of the Crowdfunding Lifecycle

Sign Up

Bot investor account farming

Automated scripts create accounts in bulk, later sold on to money-mule operators.

How Shufti solves it

Device fingerprinting and behavioural signals catch scripted timing, emulator artefacts and shared device IDs before KYC is invoked.

Synthetic-identity registration

Real identity fragments combined with fabricated personal attributes and entirely AI-generated selfie material.

How Shufti solves it

Device history, phone and email intelligence and address signals flag profiles that show no consistent digital footprint whatsoever.

Multi-profiling to evade investor caps

One investor opens several accounts to slip past ECSPR and FCA investment limits.

How Shufti solves it

Device fingerprinting at sign-up plus biometric 1:N face matching at KYC catches duplicate identities before investor classification begins.

Sanctioned-jurisdiction sign-up

Someone tries to sign up from a country your risk policy does not allow.

How Shufti solves it

A jurisdiction gate rejects all sign-ups at first contact, evidenced against AMLR Article 10 ready for supervisor inspection.

Fake fundraiser account

A company set up hours ago, fronted by a stand-in director, wants to raise.

How Shufti solves it

Company-age and registry-freshness signals flag the entity for enhanced KYB review at Stage 3, before any campaign launches.

Referral and bonus abuse

Coordinated sign-up rings harvest referral bonuses through large networks of throwaway disposable accounts.

How Shufti solves it

Device fingerprinting, email domain analysis and biometric duplicate-detection identify and break the entire coordinated ring at its source.

Verify investor

Stolen ID with genuine documents

A genuine passport belonging to another individual is uploaded with a darknet-sourced selfie.

How Shufti solves it

Template forensics, MRZ integrity checks and 1:1 face match catch the mismatch immediately; NFC chip read removes ambiguity.

Deepfake face-swap during selfie

A real-time face-swap tool overlays the fraudster's own face onto the identity-document photograph.

How Shufti solves it

Deepfake and AI-face detection inspects the entire video stream before the 1:1 identity face match is ever run.

Injection Attacks

Injection tools bypass the physical camera and feed pre-recorded video into the app.

How Shufti solves it

Injection Attack Detection identifies virtual-camera artefacts and challenge-response mismatches during the liveness verification step, before any match runs.

Presentation attacks

Silicone masks, printed photographs and screen replays remain attacks against retail investor onboarding.

How Shufti solves it

iBETA Level 3 certification against the ISO/IEC 30107-3 PAD Level 3 standard independently documents Shufti's measured performance.

Banned investors under new identity

An investor previously banned for cap evasion or fraud attempts a new sign-up.

How Shufti solves it

Face biometrics 1:N against the platform's own historical gallery matches the returning face before the new account opens.

Underage investor attempts

Retail crowdfunding is restricted to adults; sign-ups below the threshold create regulatory exposure.

How Shufti solves it

Document DOB validation and age-verification signals block every sign-up falling below the applicable local legal age threshold automatically.

Verify Fundraiser (KYB & UBO)

Shell SPV incorporated days before campaign

An SPV registered 48 hours before the raise has no trading history whatsoever.

How Shufti solves it

KYB captures incorporation date, address and complete filing history; freshness thresholds route the entity to enhanced compliance review.

Hidden UBO layered offshore

A director-of-record fronts for a nominee owned by a trust in another jurisdiction.

How Shufti solves it

UBO Discovery resolves the ownership graph, corroborates with primary-source documents, and applies the AMLR threshold at every layer.

Nominee directors fronting for banned persons

A person previously banned from FCA-regulated activity is listed merely as an advisor.

How Shufti solves it

Directors KYC plus adverse-media checks on every named principal catches the concealment before campaign approval proceeds.

Forged incorporation or doctored accounts

Synthetic document fraud up 300%+ Y/Y in 2024-25 now targets KYB document submissions.

How Shufti solves it

Document forensics on every business document in the set catches template mismatches, edited PDFs and digitally manipulated signatures.

Undisclosed director disqualification

A recently-discharged bankrupt or formally disqualified director is presented as the sole signatory.

How Shufti solves it

Adverse-media plus insolvency-register cross-checks surface the director's full history before campaign approval.

Cross-jurisdiction UBO evasion

Register-only checks miss beneficial owners held indirectly through offshore trusts and layered holdcos.

How Shufti solves it

Shufti pulls exactly the corroborating documents AMLR Article 20 requires: share registers, trust deeds and formal control agreements.

regulatory classification

Falsified sophisticated-investor self-certification

A retail investor self-certifies as sophisticated to escape ECSPR or FCA investment caps.

How Shufti solves it

Shufti records the classification and evidence, re-tests annually, and produces an auditable record if regulators later dispute it.

Sophistication-threshold gaming

Fake payslips or income documents, submitted to clear the sophistication thresholds.

How Shufti solves it

Document forensics on the income evidence plus source-of-funds cross-checks catches the fabrication before any investor classification is recorded.

Knowledge test copy-paste and bot-completion

Automation tools complete the ECSPR entry test faster than a human could read.

How Shufti solves it

Behavioural signals flag suspiciously fast completions for manual review before the entry test result is ever officially recorded.

Accredited-status document forgery

Fake tax returns, brokerage statements or accountant letters, submitted for Reg D checks.

How Shufti solves it

Supports the SEC 2025 minimum-investment safe harbour alongside document and third-party letter methods.

Restricted certification fraud

Restricted investors self-declare 10% or less of net investable assets without supporting evidence.

How Shufti solves it

Shufti records the certification, timestamps it, and re-tests annually with the PS22/10 cooling-off period captured in the record.

Investment-limit evasion via duplicate identities

Even a legitimately classified investor can breach caps by opening a second account.

How Shufti solves it

Biometric 1:N against the platform's own gallery at every subscription enforces the cap at the point it matters.

aML & sanctions

Sanctioned investor slipping through fuzzy-match

A designated individual applies under a slight name variant that strict-match rule misses.

How Shufti solves it

Shufti match logic tunes across transliterations, cultural naming conventions and known aliases to catch every designated person reliably.

PEP in the investor base missed at onboarding

A domestic PEP, family member or close associate applies without disclosing that status.

How Shufti solves it

PEP screening covers the full AMLR definition, including former PEPs for at least 12 months after leaving office.

Adverse media missed on a fundraiser director

A director is named in litigation, regulatory action or journalism relevant to fitness.

How Shufti solves it

Shufti screens news, court records and regulatory notices on every director.

Layered ownership hiding a sanctioned UBO

The named UBO is clean; the actual controller two layers up is sanctioned.

How Shufti solves it

Sanctions and PEP screening runs at every UBO layer resolved during KYB, not just the direct registered owner.

Cross-list mismatch

Cross-border onboarding must satisfy the EU consolidated list, UK OFSI and OFAC simultaneously.

How Shufti solves it

Shufti runs against all four sanctions lists in parallel and evidences every resolved alert for eventual supervisor inspection.

campaign approval

Deepfake founder pitch video

An AI-generated video shows a "founder" making claims the real founder never made.

How Shufti solves it

Deepfake and AI-face detection runs on the pitch video before it is admitted to the live campaign page.

Fabricated traction or social proof

Screenshots of user counts, revenue or letters of intent manufactured to justify raise.

How Shufti solves it

Document forensics on the evidence pack plus adverse-media cross-checks on every named partner catches the fabrication before approval.

KIIS or Form C" → "the offer document"

ECSPR requires a KIIS; Reg CF requires Form C. Both target doctored financials.

How Shufti solves it

Document forensics on the financial statements catches doctored PDFs, edited signatures and known-forgery templates immediately during campaign review.

Undisclosed conflict of interest

A fundraiser's lead investor turns out to be a related party or owner.

How Shufti solves it

Cross-checks between the investor and fundraiser UBO graphs surface the ownership overlap for platform review before campaign approval.

Loan-originator misrepresentation (P2P)

A P2P originator overstates loan-book quality or understates default history significantly to investors.

How Shufti solves it

Continuous KYB, adverse-media on directors surface the deterioration before the next investor tranche ever funds.

Campaign-owner criminal-record concealment

A project owner conceals a prior conviction for financial-services, insolvency or fraud offences.

How Shufti solves it

Adverse-media plus criminal-record screening on every named director surfaces the conviction record before campaign approval is ever granted.

deposit and payout

Stolen card funding investments

Stolen cards create 60 to 90 day chargeback exposure and inflate campaign traction.

How Shufti solves it

Device fingerprinting, payment-signal analysis and step-up biometric on first deposit catches the fraud pattern early in the cycle.

Payment-mule accounts for fundraiser payout

The named payout account belongs to a mule, not to the verified fundraiser.

How Shufti solves it

Payout-verification requires the account holder to match the verified fundraiser, closing the exact gap the Nightingale case exposed.

Account takeover redirecting payouts

US ATO losses hit $15.6bn in 2024; attackers use credential-stuffing and SIM-swap redirection.

How Shufti solves it

Biometric step-up on all payout instructions and material account changes blocks the redirection attack path completely and permanently.

Cross-platform Reg CF cap evasion

US Reg CF investors self-declare annual usage across portals; a live enforcement risk.

How Shufti solves it

Shufti enforces the per-platform cap and evidences the investor's own self-declaration record against the annual cross-portal investment limit.

BEC-driven payout-instruction change

A business-email-compromise variant asks the compliance team to whitelist a new payout account.

How Shufti solves it

Step-up biometric on any material account change blocks the social-engineering attack path before funds move.

Layering via small investor deposits

Coordinated small deposits from mule accounts fund a single campaign whose beneficiary withdraws.

How Shufti solves it

Behavioural monitoring and cross-account link analysis surfaces funding patterns before any payout completes.

Ongoing Monitoring

Sanctioned designation added post-onboarding

A clean investor at onboarding is added to a sanctions list months later.

How Shufti solves it

Continuous re-screening against EU consolidated, UK OFSI, US OFAC and UN lists surfaces the new designation same day.

Investor becomes a PEP after onboarding

A retail investor is appointed to public office or becomes a PEP associate.

How Shufti solves it

PEP screening runs continuously against the full AMLR definition, including domestic PEPs and the heads of local authorities.

Fundraiser adverse media appears months later

An investigation, litigation or enforcement action against a fundraiser director surfaces after approval.

How Shufti solves it

Adverse-media alerts fire on all directors and UBOs post-onboarding, with case management routed for platform review and assessment.

Originator financial deterioration (P2P)

Mintos originator defaults show exactly why originator monitoring cannot be point-in-time at all.

How Shufti solves it

Adverse-media and financial-health signals surface early distress before the next investor tranche is ever committed to the originator.

Sockpuppet investor ring post-cascade

Coordinated small investors self-fund the first 20 to 30% of a campaign raise.

How Shufti solves it

Cross-account behavioural link analysis and biometric duplicate-checks post-onboarding surface the entire coordinated ring immediately for platform compliance review.

Anomaly on high-value investor accounts

A dormant high-value account suddenly executes atypical transactions or requests new payout destination.

How Shufti solves it

Behavioural monitoring flags the account for step-up re-verification before any payout is released.

Deactivation & Wind-down

Records incomplete for AMLR Art. 77

Legacy systems retain documents but not the CDD rationale that supervisors will inspect.

How Shufti solves it

The audit trail records every decision, the supporting evidence and the decision-maker, in a single supervisor-presentable export format.

Data-portability request on closure

GDPR and equivalent rights require portable records on request even after relationship ends.

How Shufti solves it

Export produces the complete CDD file in a machine-readable format without triggering any re-verification of unrelated platform customers.

Sanctions exit-screening missed

A sanctioned individual attempts to withdraw the remaining funds at account closure time.

How Shufti solves it

Exit-screening at deactivation blocks the outbound transfer and triggers the SAR/STR reporting workflow immediately for the compliance team.

STR or SAR reference lost from the record

When a suspicious activity report is filed, the reference must remain with record.

How Shufti solves it

Adverse-media and financial-health signals surface early distress before the next investor tranche is ever committed to the originator.

Ex-user re-registering under new identity

A deactivated user attempts to re-onboard as a new investor or fundraiser account.

How Shufti solves it

Face biometrics 1:N against the platform's full historical gallery catches the biometric return regardless of the new document.

Post-deactivation export missing rationale

A supervisor requests the file three years post-closure and needs the decision rationale.

How Shufti solves it

Shufti retains the documents, decision rationale, risk classification and every re-verification event.

Built for Every Role That Owns the Raise

Compliance signs off on evidence. Product owns conversion. Engineering owns integration. Fraud owns the attack surface.

Book a Demo

Compliance Officer

The gap your evidence sits across four vendors and none of it is ready for a supervisor to open. How Shufti closes it Shufti keeps every check, decision and reason in one file, ready to hand to a supervisor at any time. Shufti runs sanctions and PEP screening continuously against EU, UK, US and UN lists, and holds the record for five years by default.

Head of Product

The gap you keep rebuilding onboarding flows every time a rule shifts. How Shufti closes it Shufti gives you one API for backer checks, fundraiser checks and owner discovery. Ready-made forms cover EU knowledge tests, UK investor certification and US accreditation, so nothing gets rebuilt per jurisdiction.

Head of Engineering

The gap — Four vendors, four integrations, four contracts and four security reviews.

How Shufti closes it — Shufti replaces the stack with one integration and one contract. Data stays in the region you choose, and one dashboard orchestrates every check.

Fraud Analyst

The gap Deepfake and AI-generated faces now show up in every batch, and old liveness checks miss them. How Shufti closes it Shufti ships certified liveness plus deepfake detection. Alerts fire on fundraiser directors and owners after onboarding, so risk stays visible after the campaign goes live.

Don’t just take our word for it, hear from our customers

The Confidence Our Clients Share

The future of digital identity is defined by trust, interoperability, and regulatory alignment, so our partnership with Shufti reinforces DevCode Identity’s commitment to supporting our global customers with the most secure, best-in-class, compliant identity verification solutions available today.

Combining our Conversion Driven Compliance Orchestration Platform with Shufti’s global KYC and IDV capabilities allows our customers not only to navigate complex regulatory demands but also to maintain a seamless customer onboarding experience with the highest achievable conversion rates.

Mark Knighton
Chief Global Development Officer -
Global Alliances, DevCode

FAQ

Answers on crowdfunding compliance

From 10 July 2027, crowdfunding platforms are named as obliged entities, so you carry the same checks, screening, and record-keeping rules as banks and payment firms.

The person investing, the business raising, its directors, its owners, and every sanctions or PEP hit against them. Then Shufti keeps checking, quietly, after the campaign has closed.

Certified liveness plus deepfake detection. The video is inspected for AI-generated faces before the face on screen is matched to the ID document.

Shufti follows the ownership chain across trusts, holding companies and offshore layers, and pulls in the supporting documents public registers do not give you.

One file per backer, one per fundraiser, with every check, decision and reason inside. Kept for five years by default, longer on request.

Traditional documents (tax returns, brokerage statements, CPA letters) all work. The 2025 minimum-investment safe harbour ($200k for individuals, $1m for entities) runs as a ready-made flow.

Yes. One authorisation covers all Member States. Shufti supports document checks in 240+ countries and connects to national eID methods where they are live.

Sandbox in minutes. One API covers every check, every screen and every record.

Ready for the crowdfunding raise. Ready for the supervisor

Shufti gives crowdfunding platforms one file per backer and one per fundraiser, screened continuously and kept ready for a supervisor at all times. Book a demo before 10 July 2027 catches up with the rest of the market.