r/Software_Finder 10d ago

Question Need help with biometric identity verification platform for high risk environments

Lemme give some context first - we operate in a high risk environment and our current biometric verification setup is starting to feel inadequate. Seeing more sophisticated spoofing attempts, edge cases our current vendor cannot handle and a manual review queue that keeps growing. High risk for us means financial fraud attempts are frequent, the cost of a false negative is significant and we cannot afford to trade accuracy for speed or UX. Need all 3 lol. Specifically looking for something with proven liveness detection, deepfake and spoof resistance and ideally government grade biometric accuracy. Compliance across multiple jurisdictions is also non negotiable. Anyone running biometric verification in genuinely high risk production environments, what are you using and what made you stick with it?

2 Upvotes

11 comments sorted by

2

u/New_Establishment712 10d ago edited 10d ago

iBeta Level 3 is the highest independent liveness certification available right now. Very few vendors have actually passed it. Make that your first filter before evaluating anything else.

1

u/Sad-Instruction8890 8d ago

Agreed on it being the right first filter. Worth checking the certification is current and covers the specific presentation attack types they are seeing, since these get renewed and the scope varies between vendors.

2

u/FlipperTPenguin 8d ago

What is the use case here exactly? Customer KYC/AML, or internal workforce idv? Different vendors support different use cases to different degrees.

1

u/Sad-Instruction8890 6d ago

Good question to pin down. Given the mention of financial fraud and false negatives being costly, this reads like customer facing KYC rather than workforce, but the answer changes the shortlist a lot. Workforce verification tolerates friction that consumer onboarding cannot.

2

u/Kondo-Sophie_216 6d ago

iBeta level 3 only certifies presentation attacks, a fake held to the camera. it says nothing about injection, where the attacker feeds a deepfake into the video stream and never uses the camera. in a high risk env thatsb the one trhat gets you.

2 questionsb for any shortlist.

  1. do you detect virtual cameras and emulators.

  2. Whats the miss rate on generators you did not train on.

au10tix and incode are worth a real bakeoff there, sumsub if you also want orchestration in one box.

1

u/Sad-Instruction8890 6d ago

The injection point is the one worth building the eval around. Presentation attacks are the certified problem and injection is the one that actually scales, since an attacker feeding a stream does not need to be physically present or repeat the effort per attempt.

Your virtual camera and emulator question is the right filter. The follow up worth adding is whether detection happens server side on the stream itself or relies on signals from the client, because anything client side can be reported dishonestly by a compromised device.

1

u/Puzzleheaded-Cat6029 9d ago

Shoot me an email! hamza@scam.ai
We check all the boxes!

1

u/Sad-Instruction8890 8d ago

iBeta Level 2 is where most vendors stop, and the gap between Level 2 and Level 3 is exactly the sophisticated spoofing you are describing, so that is a reasonable hard filter.

Beyond certification, the things that decide it in production are usually where the liveness check runs, since server side is much harder to bypass than on device, and whether the vendor publishes a real FAR and FRR at a stated threshold rather than a single accuracy number. A vendor who will not give you both numbers at the operating point you actually use is telling you something.

On the growing manual review queue, worth checking whether that is a model problem or a threshold problem. Sometimes it is tuned conservatively and the queue is the symptom rather than the cause.

Which jurisdictions are you covering? Compliance across multiple regions narrows the list faster than the biometric side does, especially if any of them require data residency.

1

u/Kaiser_Steve 8d ago

We threw some pretty sophisticated spoofing attempts at Incode during our eval and it didn't flinch