AU10TIX
AU10TIX provides automated identity document authentication, biometric verification, liveness and fraud intelligence to banks, payment providers, trading and cryptocurrency platforms, marketplaces and other high volume digital businesses. The company grew out of border control and aviation security document authentication and is a subsidiary of ICTS International, a Dutch security group whose shares trade over the counter.
Its product line covers an identity verification suite, liveness and deepfake detection, non identity document verification, combined know your business, know your customer and anti money laundering checks, reusable credentials as a premier issuer for Microsoft Entra Verified ID, and Serial Fraud Monitor. Serial Fraud Monitor is a fraud intelligence consortium of more than sixty participating companies that links repeated identity elements, document conflicts and coordinated attack patterns across separate organisations, sectors and geographies rather than within a single customer's own traffic.
The company reports verification results in under eight seconds and estimates that its technology has helped prevent roughly twenty billion dollars of fraud losses since 2021, broken out by sector as approximately thirteen billion in payments, two point seven billion in cryptocurrency and trading, over one billion in banking and seven hundred and seventy six million in the shared economy. Named customers span PayPal, Google, Microsoft, Airbnb, Uber, Fiverr, 888 Holdings, Aspire Global and ShopBack.
It holds an unusually broad certification set including information security and privacy management certification, service organisation control type two, a United States state government cloud authorisation, accredited presentation attack detection testing, and third party conformity certification against the United States federal identity assurance standard at level two.
Capability Axes
Capability grades
15 of 15 axes rated · 10 graded A or B
Every layer of the product is model driven: document forensics, biometric matching, passive liveness, deepfake detection, behavioural analysis and the neural network that finds repeated and coordinated fraud patterns across verification attempts. The company describes the fraud intelligence layer as award winning neural network technology and states its machine learning models are designed to adapt as new attack techniques emerge. Remove the models and there is no product, only a document scanner. This is the same clean pass of the removal test recorded for Incode and Microblink.
Full automation is not merely the architecture here, it is the explicit selling proposition. The company markets the ability to screen large volumes of new users without relying on manual review teams, and returns a decision in under eight seconds. That is an accurate description of the value and it is also the entirety of the public disclosure on oversight.
Nothing describes a manual review queue, a case management surface, a confidence threshold the customer can set, an escalation path for a borderline capture, or how a human adjudicator reopens an automated rejection. The consortium layer sharpens the concern rather than easing it, because a decision informed by signals contributed by other organisations is harder for the institution acting on it to reconstruct or override than one produced from its own traffic.
External assessment here is broader than any peer, covering accredited presentation attack detection testing of the biometric layer and independent conformity certification of the identity proofing process against the federal identity assurance standard at level two, which is a defined and auditable requirement set a bank risk function can map against.
It is still held at the middle grade for the same reason as Incode and Microblink: no model documentation, no validation summary, no error rates published in either direction, no drift monitoring description, and no stated position on supporting a customer's own model validation under supervisory guidance.
Three vendors now hold the strongest external measurement available in this field and all three stop at this grade for the identical reason, which makes the boundary a property of the category rather than of any one vendor.
Both routes to the top grade are satisfied. Named customers include PayPal, Google, Microsoft, Airbnb, Uber, Fiverr, 888 Holdings, Aspire Global and ShopBack, with a named managing director of financial services quoted directly. A named financial institution case reports fake accounts reduced by five percent, a conversion success rate above ninety percent, and a fall of more than ten percent in usability related service contacts.
Independent parties with nothing to gain also assess the product, through accredited presentation attack detection testing and third party conformity certification against a federal identity assurance standard. One honest qualification recorded rather than hidden: the headline figure of roughly twenty billion dollars in fraud prevented is described by the company itself as an estimate derived from its own detection data, so it is a vendor model rather than an audited or independently reconstructed number.
The safety half is strong and externally verified, covering accredited presentation attack detection testing, deepfake and synthetic identity detection, behavioural analysis and models stated to adapt as attack techniques change. The stewardship half is where this vendor differs from every peer, and it deserves to be read carefully.
Serial Fraud Monitor is explicitly a consortium: more than sixty companies contribute fraud signals, and the stated product value is connecting those signals across separate organisations, sectors and geographies. This is the pooled data question raised more directly than anywhere else in the index, because the shared material is identity and fraud data about individuals rather than market or portfolio data.
A verification attempt made at one participant can shape how a person is treated by another participant in a different sector. Privacy management certification provides real governance around that arrangement, which is more than the comparable data flywheels at Incode or FNZ can show, but no public boundary statement describes what is shared, how long a fraud signal persists, whether a participant can decline contribution, or how an individual learns they are in the consortium at all.
Materially stronger than the category norm and the best privacy showing in this sweep. The company holds privacy information management certification, which is a full management system certification rather than a single control standard, operates a programme stated to align with European data protection law, and says it supports regional data residency requirements. Layered access control, strong authentication and continuous monitoring are described.
It stops short of the top grade on the specific exposures this product creates. Nothing public addresses United States state biometric privacy law, where Illinois, Texas and Washington impose separate consent, retention and destruction duties and Illinois carries a private right of action, which is a notable gap given the company holds a Texas state cloud authorisation and therefore plainly operates there.
No retention terms are published for identity documents, biometric templates or the fraud signals held in the consortium, and there is no service provider position under United States financial privacy law.
The most complete certification set located in this sweep after Temenos, and unusually it spans four different assurance families rather than repeating one. Information security management certification and privacy information management certification are both held. Service organisation control type two attestation is in place. A United States state government cloud programme authorisation at level two demonstrates passage through a public sector security review.
Accredited laboratory presentation attack detection testing covers the biometric layer against the international standard. Third party conformity certification against the federal identity assurance standard at level two covers the identity proofing process itself. All of it is consolidated on a dedicated public data security and privacy page rather than scattered. Short of a perfect showing only because audit periods and certificate validity dates are not published, there is no portal for requesting the attestation reports, and no subprocessor list.
AU10TIX holds no financial licence, which is the expected posture for a technology supplier in this category, but it has passed through more formal government assessment than most peers. It holds third party conformity certification against the United States federal digital identity assurance standard at level two, and a United States state government cloud programme authorisation, both of which are structured public sector reviews rather than marketing claims.
The product line is written directly against know your customer, know your business and anti money laundering obligations, and the company's origins lie in border control and aviation security, both regulated settings. It stops short of the top grade because no financial regulator has supervised or tested the product, which is the bar set by CleverChain, and no financial services authorisation or registration is published.
The credential claim on this axis is ambiguous and an ambiguous credential cannot be credited. Marketing states accuracy is powered by top rated algorithms from the national standards institute evaluations, which reads either as the company submitting its own models to those evaluations, which would be meaningful because they measure demographic differentials by design, or as the company using third party algorithms that scored well, which would be a supply chain fact rather than a fairness one.
Nothing located resolves it. Either way no demographic breakdown, no bias testing methodology, and no analysis of how error rates vary across document types, regions or skin tone is published. The consortium raises a second and distinct fairness question that nothing addresses: shared fraud signals can concentrate suspicion on particular populations, document types or geographies, and a person carried across sixty organisations by such a signal has no visibility into it.
This is the most consequential recourse gap recorded in the index so far, because of the consortium rather than despite it. A person wrongly flagged by a single vendor is refused by one institution. A person wrongly carried in a shared fraud signal is potentially refused across more than sixty participating companies in several sectors, and would have no way to know a shared signal was the cause.
Nothing public describes an appeal route, a correction or removal mechanism for a contested fraud signal, a retention period after which a signal expires, an accuracy guarantee, or how responsibility is divided between the vendor supplying the signal, the participant who contributed it and the institution acting on it. The product is marketed as operating without manual review teams, which removes the most obvious point at which a person could contest an outcome.
The company describes its technology as proprietary and does not name a base model, provider, version or external component for any layer of the product. The one place a supplier relationship is named, the verified credential partnership with Microsoft, concerns credential issuance and distribution rather than model supply.
The reference to top rated algorithms from the national standards institute evaluations is genuinely unclear as to whether those algorithms are the company's own or licensed, which is the opposite of a supply chain disclosure. There is no subprocessor list and no identifier a bank could record against a decision to establish which model version produced it. This is the pattern already established across the index: a proprietary claim substitutes for a disclosure.
Delivery covers application programming interfaces, software development kits and a hosted verification flow, with results returned in under eight seconds, and the modular structure lets an institution take document checks, biometrics, liveness or fraud intelligence separately.
The most substantive integration evidence is being a premier identity verification issuer for Microsoft's verified credential service, with the reusable identity technology planned into that platform's third party onboarding flow, which is a named integration into another vendor's product rather than a generic connector claim.
It falls short of the top grade because nothing published describes depth into core banking, account opening or lending origination systems by name, and no partner directory, public status page or changelog was located.
Delivery is hosted software as a service with application programming interface and software development kit options. The residency position is better evidenced than most in this lane: the company states it supports regional data residency requirements, and it holds a United States state government cloud programme authorisation at level two, which is a jurisdiction specific security and hosting review rather than a general assurance.
Corporate and engineering footprint spans the Netherlands, the United Kingdom, the United States, Singapore, Israel and Eastern Europe. Held below the top grade because specific hosting regions and in country residency options are not enumerated publicly, data transfer mechanisms are not described, and there is no subprocessor list, which matters for a vendor moving identity documents and biometric templates across jurisdictions with sharply different rules.
Sales run through an enterprise motion with no published rates, tiers, volume bands or minimum commitments, and third party evaluators note the vendor is less suited to small volume self serve buyers. Pricing for identity verification is normally per verification and for a fraud consortium is normally a separate subscription, and neither unit nor band is published. Every route terminates in a contact or demo request, so a buyer cannot size a deal or model the cost of the consortium layer without entering a sales process.
Coverage is not only broad, it is quantified by segment, which almost no vendor in this index does. The company publishes fraud prevention figures broken out across payments, cryptocurrency and trading, banking and the shared economy, which demonstrates real operating presence in each rather than a vertical landing page. Named customers span payments, technology, marketplaces, mobility, gaming and retail finance.
Operations run from the Netherlands, London, New York, Singapore and Amsterdam with research and development in Israel and Eastern Europe. The fraud intelligence consortium spans more than sixty participating companies across multiple sectors and geographies, which is itself evidence of multi segment reach.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to AU10TIX
The closest documented capability profiles to AU10TIX in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Core Systems and Integration Depth
Documents Autonomy and Oversight Model where AU10TIX does not
Documents Autonomy and Oversight Model where AU10TIX does not
A lighter documented profile than AU10TIX
Documents Commercial Transparency and Autonomy and Oversight Model where AU10TIX does not
Documents AI Governance and Bias Disclosure and Model Supply Chain Disclosure where AU10TIX does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.