Directory of behavioural biometrics and account takeover prevention vendors
The AI FinTech Index holds 7 of them, each graded on the same 15 capability axes from public sources, with the artifact every grade was read from attached to the record.
No vendor pays for inclusion, placement or rating. Counts generated 2026-08-24 across 490 indexed vendors. What moved is in the change log.
These systems profile how a person physically interacts with a device, which is biometric data in most privacy regimes and is collected continuously rather than at a consent moment. Ask what the customer is told, what is retained, and how the model performs for users with motor or cognitive impairment.
What is in this directory. Screened to vendors authenticating a returning user from behaviour, device or biometric signal. Transaction scoring engines are held separately.
Part of the wider Fraud Detection & Transaction Risk category.
What the public record shows in this directory
The share of the 7 indexed vendors here whose public record answers each of the nine regulatory questions a financial institution diligence process works through, and where this directory ranks against the other 50 directories in the index on the same question, highest share first. A thin share means the public record is thin, not that a control is absent.
The AI FinTech Index lists 7 behavioural biometrics and account takeover prevention vendors, graded on 15 capability axes from public sources with no paid placement and no aggregate score. Across this directory the best documented part of the public record is how much the system decides on its own at 57 percent, and the thinnest is liability and customer recourse at 14 percent, which is 19 highest of 50 directories in the index on that question. Across the whole index of 490 vendors, none documents all nine regulatory axes in public and the average documents 2.94.
Source: AI FinTech Index, August 2026
| Vendor | Category | AI Centrality | Website |
|---|---|---|---|
|
B
BioCatch
BioCatch analyses how a person physically and cognitively interacts with online and mobile banking, covering typing cadence, navigation patterns, hesitation and signs of duress, and turns those signals into real time fraud risk for the bank. Its platform targets account opening fraud, account takeover, social engineering scams and money mule accounts, and it runs an inter bank intelligence sharing network in Australia that lets participating banks act on behavioural financial crime signals collectively.
|
Fraud Detection & Transaction Risk | A | biocatch.com |
|
C
Callsign
Callsign recognises returning bank customers by how they behave rather than by what they know, combining behavioural biometrics, device intelligence and contextual analytics through an orchestration engine that decides what authentication a given interaction actually needs. It covers account login, payments, account creation and network access, against account takeover, social engineering scams, malware and bots, SIM swap and call diversion, and synthetic identity. Its dynamic intervention capability detects social engineering in real time and sends the customer a contextual, personalised warning before they transfer money to a fraudster, and it fuses telecommunications network signals indicating a live call during a payment. The company publishes commissioned economic research on digital exclusion and frames security as enabling access rather than restricting it.
|
Fraud Detection & Transaction Risk | A | callsign.com |
|
I
Incandor
Incandor builds behavioural intelligence infrastructure for banks, fintechs, neobanks and digital banks, on the argument that institutions verify identity at account creation but have no continuous signal for who is actually operating an account afterwards, while identity itself has become a commodity attackers buy in bulk. It constructs a behavioural map of every user from physical interaction signals including mouse dynamics, keystroke timing, scroll patterns and how a phone is held, requiring no fraud labels or historical data, so detection works from the first session. Each individual forms a unique cluster regardless of which account they use, which surfaces account takeovers, mule handoffs, shared operators and coordinated rings, and supports bot detection and identification of sessions under stress or coercion. Rather than returning a risk score, it exposes the map as a programmable interface so a fraud team combines behavioural signals with its own transaction and customer data. It collects only behavioural signals, not what users type, read or view.
|
Fraud Detection & Transaction Risk | A | incandor.com |
|
O
OneSpan
OneSpan is a Chicago based, publicly listed security vendor built on the authentication business formerly known as Vasco, serving more than 10,000 customers including over half of the hundred largest global banks. The portfolio spans hardware and software authenticators, mobile application shielding, a mobile security developer toolkit, identity verification, electronic signature and digital agreement workflows. The inference layer is a named and separately purchasable product line. Risk Analytics scores transactions in real time using machine learning and data modelling over device integrity, application signals, user behaviour, malware indicators, transaction detail, beneficiary payment history and server side analytics, then drives workflows that act immediately according to policies and rules the bank defines, with automated alerts routed into a single case management interface for analyst review. Intelligent Adaptive Authentication couples that risk engine to multi factor authentication so that higher risk activity automatically triggers a stronger challenge rather than a uniform one, shipped with preconfigured rule sets and predictive models tuned separately for mobile, online and corporate banking. The company positions both against named regulatory regimes, including European strong customer authentication rules and a central bank mandate in the United Arab Emirates, and publishes a customer engagement modernising authentication for an Italian bank under the revised European payments directive.
|
Fraud Detection & Transaction Risk | C | onespan.com |
|
O
Oz Forensics
Oz Forensics builds facial biometric liveness detection and face matching software sold to banks, fintechs, identity verification vendors, telecommunications operators, gaming operators and government agencies across more than twenty countries. Headquartered in Dubai and founded in 2017 by chief executive Artem Gerasimov, it was acquired in September 2024 by Unico, a Brazilian digital identity company, and continues to ship under its own name with its own products. The two core products are Oz Liveness, which establishes that a real living person is present and defends against presentation attacks, injection attacks, deepfakes and three dimensional masks, and Oz Biometry, which matches two faces to confirm they belong to the same person. An optical character recognition capability for identity documents sits alongside them. Liveness can run actively or passively, on the device or on a server, in two or three dimensions, and across a single frame or multiple frames of video. The company sells both as a hosted service and as an on premises licence, so an institution can keep biometric processing entirely inside its own environment. External validation is unusually deep for the category, spanning presentation attack detection testing at levels one and two by one accredited laboratory, separate presentation and injection attack assessments by a second, a level three presentation attack evaluation, and benchmarking of the face matching model in the United States national face recognition evaluation programme. In March 2026 the company launched a public trust centre carrying its certifications, security and privacy documentation, client information and a list of its subprocessors. Named deployments include Eurasian Bank, which reported onboarding one million clients using the biometrics, and Sberbank Kazakhstan.
|
Fraud Detection & Transaction Risk | A | ozforensics.com |
|
R
Reality Defender
Reality Defender detects synthetic media in real time, running an ensemble of models against live voice on contact centre calls, participants in video meetings, and images and documents in verification flows. In financial services it is deployed against voice cloning that defeats phone based authentication, executive impersonation in video conferences used to authorise transfers, and generated media aimed at identity verification checks, and it is designed to sit alongside an institution's existing security and liveness infrastructure rather than replace it.
|
Fraud Detection & Transaction Risk | A | realitydefender.com |
|
W
Wink
Wink authenticates people at the moment of payment rather than at account opening, combining face, palm, voice and device recognition into a multi factor biometric layer that identifies a customer from a population in under a second, without a card, phone or password. It is distributed through payments infrastructure rather than sold direct, embedded into a major acquirer's point of sale estate across every device without new hardware, into terminal makers' software, into a chipset partner's platform and into self service kiosks, with on device processing at the edge in some deployments. Alongside the biometric layer the company operates its own payment gateway and network, certified at the highest card industry security tier, which merchants can own or rent and which handles hundreds of millions of transactions a year.
|
Fraud Detection & Transaction Risk | B | wink.cloud |
Common questions
Is there a directory of behavioural biometrics and account takeover prevention vendors?
Yes. The AI FinTech Index lists 7 behavioural biometrics and account takeover prevention vendors, each graded on the same 15 capability axes from public sources, with the artifact every grade was read from attached to the record. No vendor pays for inclusion, placement or rating, no vendor is contacted before it is listed, and nothing sits behind a form. Counts generated 2026-08-24.
What counts as behavioural biometrics and account takeover in this directory?
Screened to vendors authenticating a returning user from behaviour, device or biometric signal. Transaction scoring engines are held separately. The index holds 7 vendors meeting that screen, drawn from a wider Fraud Detection & Transaction Risk category and from adjacent categories where the vendor belongs on the same shortlist. A vendor filed under a different category can still appear here, because a buyer building this shortlist does not sort by our filing.
What should a buyer check before shortlisting behavioural biometrics and account takeover vendors?
Start with what this segment does not publish. Across the 7 indexed vendors, the thinnest parts of the public record are liability and customer recourse at 14 percent, deployment model and data residency at 29 percent, and AI governance and bias testing at 29 percent. A thin public record predicts the length of a diligence process rather than the absence of a control, so these are the questions to put in writing early. These systems profile how a person physically interacts with a device, which is biometric data in most privacy regimes and is collected continuously rather than at a consent moment. Ask what the customer is told, what is retained, and how the model performs for users with motor or cognitive impairment.
Comparisons inside this directory
Other directories in Fraud Detection & Transaction Risk
One category is several buying decisions sharing a label. Each of these narrows the same market to a different one.