
August 25th, 2026
Two weeks before he came on the show, Raido Saar was invited onto a different podcast. He got a link, tried to join, and hit an error demanding he install software to "fix" a connection problem. He refused. The link was a clone of a legitimate video platform, built to push malware onto his machine. The accounts that invited him checked out on X. The other "guests" in the planning calls were in on it too, playing along to make the setup look real.
Saar has spent his career on the other side of exactly this kind of forgery. In our conversation, he cited a Mastercard-published survey: global fraud losses rose 800 percent last year, reaching $9.5 trillion. Against that, the compliance industry spends roughly $500 billion annually on anti-money-laundering measures. The assets it recovers or seizes back amount to 0.02 percent of what moves through the system. Half a trillion dollars a year, and the needle barely moves.
Saar grew up on an Estonian island of about 15,000 people, in the final years the country was part of the Soviet Union. He was 18 years old when Estonia regained independence. He trained at Estonia's police academy and ended up running an intelligence unit for the Border Guard along the Russian frontier, working with forged documents, smuggling, and trafficking for close to two decades. Spotting a fake passport before it clears a checkpoint turned out to be the direct precursor to what he does now. A stint in real estate convinced him the business didn't scale. He became head of compliance at the Estonian crypto exchange Swappin, then founded the biometric identity company MatterID, then his current company, a digital identity and compliance platform.
While at Swappin, Saar's platform got a call from German police. A woman had used five separate accounts, same face, five different fake documents, to run loan scams totaling 250,000 euros in stolen funds. The identity verification vendor Swappin paid had approved every one of the accounts. When Saar pushed back, the vendor told him the final call was his, that they only supplied a recommendation. In August 2018, Swappin moved to full KYC from account creation, closing a gap that had let small transactions clear on email verification alone.
The real lesson is about ownership: who answers for it when a check fails. A vendor that says 'we flagged it, you decided' is protecting itself, not verifying your customer.
Saar's fix, first at MatterID and now at his current venture, borrows from Estonia's X-Road, the encrypted data exchange layer the country has run since 2001. Instead of handing a passport scan to every new service, a user holds an encrypted identity vault on their own device. A bank sends a specific question: Is this person over 18? Are they sanctioned? The user consents, and only that answer crosses the wire, along with an auditable record that the check happened. ComplyOnce never touches the underlying document, and the bank never receives more than the question required.
Compare that to what most services still do: collect a full copy of an ID and store it centrally, building the exact kind of data pile that gets breached and reused against the person it was meant to protect. Saar learned this isn't hypothetical. A major identity verification provider once told him it had lost his prior submission, then corrected itself: it hadn't lost the data, it had deleted it. He had to redo the entire process.
Saar has lived the impersonation side too. Clone accounts have run in his name on Facebook and LinkedIn, some promoting investment schemes. When he reported them, the platforms told him the accounts didn't violate community guidelines. The offer on the table was to block the fake account from his own view, not take it down. Fraud and impersonation, by his account of how these platforms categorize reports, aren't treated as violations the same way graphic content is.
The pattern runs wider than Estonia, crypto, or one platform's moderation queue. Every one of these failures traces to the same blind spot. Each system proves an event took place, then goes blind to who has the right to claim it. A password only proves that the correct string got typed, tied to whoever holds it at the time. A verification badge is a timestamp on a process that ran once, resting on data that has to survive every migration that comes after it.
For Demia, that gap sits at the center of the work. A supplier attestation or a production record fails the same way a stolen identity does if the system checking it can confirm the paperwork exists without confirming who generated it and whether they had the right to. Saar's fix for identity works by verifying one specific claim, disclosing nothing beyond it, and keeping an auditable receipt behind every check. Demia applies that same logic to production and supply chain records: each data point is signed at its source and bound to a verified identity, a facility, a device, an organization, so the record carries proof of who made it and stays checkable from that point forward.
🎧 Listen to the full episode: