Fraud Detection & Transaction Risk
W

Wink

Wink authenticates people at the moment of payment rather than at account opening, combining face, palm, voice and device recognition into a multi factor biometric layer that identifies a customer from a population in under a second, without a card, phone or password. It is distributed through payments infrastructure rather than sold direct, embedded into a major acquirer's point of sale estate across every device without new hardware, into terminal makers' software, into a chipset partner's platform and into self service kiosks, with on device processing at the edge in some deployments.

Alongside the biometric layer the company operates its own payment gateway and network, certified at the highest card industry security tier, which merchants can own or rent and which handles hundreds of millions of transactions a year.

Last VerifiedAugust 12, 2026
Compare Wink with other vendors
Founded
Headquarters
Plano, Texas, United States
Website
wink.cloud
Categories
fraud-and-transaction-risk, aml-kyc-financial-crime, customer-banking-agents
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 8 graded A or B

AI Capability
AI Centrality
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a rules or workflow system.
Vendor Published

The biometric layer is entirely model work, combining face, palm, voice and device recognition into sub second identification of a person drawn from a population rather than confirmation of a claimed identity, and none of that exists without the models.

But the removal test does not empty the company, because it separately operates a payment gateway and network certified at the highest card industry tier, connected to major acquirers globally and processing hundreds of millions of transactions a year, adopted by independent sales organisations and fintechs in its own right. Two businesses sit here and only one is a model business, which is what holds this below the top grade.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

Authentication completes in under a second with no human involved, which is inherent to the use case since a checkout queue cannot accommodate review. Real robustness is engineered in through multiple factors, combining face, palm, voice and device signals so a single weak reading does not determine the outcome, and that is a genuine design control rather than a claim.

What is absent is the failure path: nothing describes what happens to a customer the system cannot recognise, whether a fallback to card is automatic or awkward, or what recourse exists at the till when a match is wrong in a queue of waiting people.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No false match rate, false rejection rate, presentation attack detection result or independent benchmark was located, and the published figures measure speed rather than correctness, with sub second verification describing latency and nothing describing accuracy. The analyst recognition as best in class is a market assessment rather than a technical evaluation.

That gap matters more here than in onboarding verification because a one to many system fails in a direction that transfers money between strangers, and the rate at which it does so is the number a merchant and an acquirer both need.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Six enterprise partnerships are named and dated across a single year, and their calibre is the point. A major listed payments and financial technology group has integrated the biometric layer into its point of sale platform across every device in the estate without requiring new hardware, with rollout announced at the industry's largest retail conference.

A global terminal manufacturer has integrated through its own point of sale application, a second terminal maker is deploying on device processing across a worldwide Android fleet with a major chipset partner, a kiosk manufacturer covers self service, and an identity verification partner extends the work into agent driven commerce. The gateway business independently handles hundreds of millions of transactions annually. A research firm named the company best in class for biometric authentication delivered as a service in late 2025, and it won a leading industry showcase in 2023.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

One question sits above all others here and nothing published answers it. Identification from a population only works against an enrolment set, and the commercial value of the model rises sharply if a customer enrolled once at one merchant is recognised at every other merchant on the network.

Whether enrolment is contained to the merchant that captured it or shared across the estate of a major point of sale platform is the difference between a convenience feature and a national biometric identity register assembled through checkout, and it is not addressed anywhere in published material.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

The most consequential biometric architecture in this index and the least described. Identifying a customer from a population rather than verifying a claimed identity requires an enrolment database of face and palm templates searched on every transaction, and palm and facial geometry are permanent physical characteristics that cannot be reissued after a breach.

Privacy is asserted as a design principle and one deployment pattern genuinely supports it, with processing performed on the device at the edge in the terminal partnerships rather than in a central service. Against that, no retention schedule, deletion route or consent description was located, and no biometric privacy statute is named despite the company being headquartered in a state with its own biometric identifier law and selling into others with private rights of action attached.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

Two named certifications are published and one of them is demanding. Certification at the highest card industry security level is the most rigorous tier available for an entity handling card data, assessed annually on site against a prescriptive requirement set, and a service organisation control attestation accompanies it. That combination places this ahead of most of the index.

What holds it below the top grade is the absence of anything covering the biometric half of the business, with no accredited presentation attack certification and no biometric specific standard named, so the assurance published addresses the payments rails rather than the face and palm data.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

One genuine admission process has been passed and it is the operative one for the payments half of the business. Certification at the highest card industry security tier requires annual assessment by a qualified external assessor against a prescriptive control set, and it is the standard an acquirer will insist on before allowing a gateway near its rails.

A service organisation control attestation sits alongside it, and age verification is offered as a named use case, which is itself a regulated function. What is missing is the regime governing the other half: biometric capture is separately legislated in several of the markets served, with consent, notice, retention and deletion requirements and in places a private right of action, and no such statute is named.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

Face recognition carries the best documented demographic error differentials in applied machine learning, and identifying someone from a population is a materially harder problem than confirming a claimed identity, so error rates that are tolerable in one to one verification compound in one to many matching. Palm recognition is far less studied across populations, and voice varies with accent, age and speech difference.

The consequence profile is unusual and cuts both ways: a customer who cannot be recognised is inconvenienced rather than excluded, since a card still works, but a false match in one to many identification means charging the wrong person's account, which is a harm with no equivalent in onboarding verification. No demographic performance data, accredited presentation attack testing or government evaluation result was located.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No guarantee, indemnity or falsifiable accuracy commitment was located. The consumer is in an unusual position: enrolment is voluntary and alternatives remain available, so nobody is excluded from paying by a failed match, which places this well above the identity vendors whose errors deny bank accounts.

But the person whose biometric is falsely matched to another customer's payment credential has no described route at all, and would in most cases discover it only through a disputed charge. Nothing describes correction, deletion on request, or how a person removes an enrolment captured at a merchant they never return to.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

The hardware and distribution chain is named at every level, covering the acquirer whose platform carries the technology, two terminal manufacturers, a kiosk maker, a semiconductor partner supplying the on device processing platform and an identity verification partner for agent driven commerce, so a buyer can see exactly whose equipment and software the biometric layer runs inside. Models appear to be the company's own and no external provider is named.

What is not disclosed is the acquirer set behind the gateway, described only as major acquirers globally, and no subprocessor list or hosting arrangement was located for centrally processed deployments.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

Integration reaches further down the stack than anything else in this index. The technology is embedded in a major acquirer's point of sale platform across its full device range with no additional hardware required, in a terminal manufacturer's own operating software through semi integration, in a second manufacturer's global Android fleet with processing performed on the device, in self service kiosks and customer facing displays, and at chipset platform level through a semiconductor partner.

Alongside that the company's own gateway connects to major acquirers worldwide. Being present in the terminal, the operating software and the silicon is a structurally different distribution position from selling an interface.

Deployment Model and Data Residency
BB on Deployment Model and Data ResidencyStated residency commitments or regional hosting options.
Vendor Published

A meaningful architectural choice is published rather than left implicit. In the terminal partnerships biometric authentication is processed on the device at the edge rather than sent to a central service, which for face and palm data is the strongest privacy position available and materially changes what leaves the store.

Held at B because it is described for specific partnerships rather than as a platform wide guarantee, and no hosting provider, region selection or residency commitment is published for the deployments that do process centrally or for the gateway business.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing, packaging or basis of charge is published for the biometric platform. One structural commercial fact is stated and it is unusual: the payment gateway can be owned outright by a merchant or rented, which is a real choice about who holds the infrastructure and is rarely offered either way.

That concerns the gateway rather than the biometric layer, and nothing indicates whether biometric authentication is charged per enrolment, per verification, per terminal or through the distribution partner.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Distribution runs through payments infrastructure rather than direct sales, so the buyers are acquirers and processors, terminal manufacturers, a chipset platform, kiosk makers, independent sales organisations and fintechs, and the reach that follows is very wide because each of those carries the technology to its own installed base. End environments named include retail, hospitality, quick service restaurants, venues and stadiums.

The limit is that the direct customer is infrastructure rather than a financial institution making its own decision, which is the Forter position, and no bank is named as deploying the technology for its own customers.

Alternatives to Wink

The closest documented capability profiles to Wink in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Autonomy and Oversight Model where Wink does not

Documents Autonomy and Oversight Model where Wink does not

Documents Autonomy and Oversight Model and Model Risk Management and Transparency where Wink does not

Documents Autonomy and Oversight Model where Wink does not

Documents Commercial Transparency and AI Safety and Data Stewardship, among others where Wink does not

Documents Model Risk Management and Transparency where Wink does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746