Tech firm Identy.io tops DHS biometric test with zero attack acceptance

Tech firm Identy.io tops DHS biometric test with zero attack acceptance

NAIROBI, Kenya, Mar 31 – Biometric technology firm Identy.io has emerged as the top performer in a U.S. government-led biometric security evaluation, recording zero successful attacks while leading on speed and user satisfaction metrics.

Results from the 2025 Remote Identity Validation Rally (RIVR), conducted by the U.S. Department of Homeland Security (DHS) Science and Technology Directorate, show the firm was the only vendor among 18 participants to achieve a 0% attack presentation classification error rate (APCER) in the Active Presentation Attack Detection (PAD) category.

The evaluation tested systems under real-world conditions, measuring not only security performance but also transaction speed and user experience.

Identy.io reported the fastest transaction times across all systems and was the only one to meet the 20-second benchmark, alongside the highest user satisfaction scores exceeding 95%.

The company’s system also maintained low false rejection rates, with a 3.4% rate on Android devices and slightly above the 5% threshold on iOS, indicating minimal trade-offs between security and usability.

“RIVR puts liveness technology under conditions designed to expose its limits three attack classes, independent scoring, genuine captures. Coming out with zero attack acceptance across all of them, while also leading on speed and satisfaction, is not a tradeoff. It is the result of building security and usability as a single problem, not two competing ones.”

The RIVR assessment builds on earlier testing where Identy.io’s biometric system recorded zero attack acceptance and zero false rejection rates under iBeta ISO 30107-3 Level 1 and 2 standards.

The latest results also highlight growing industry concerns around increasingly sophisticated threats, including synthetic identity attacks and deepfake-based fraud.

The RIVR evaluation included higher-grade attack simulations, including Class C attacks, which typically require specialized hardware and resources.

Identy.io said its system integrates multiple layers of defense, including capture-stage protection and deepfake detection, aimed at addressing emerging risks such as injection attacks, where synthetic content is fed directly into verification systems.

The DHS-led RIVR programme is increasingly becoming a benchmark for evaluating the resilience of remote identity verification systems as digital transactions and onboarding processes expand globally.