• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Fulcrum Biometrics, Inc.

Fulcrum Biometrics, Inc.

Biometric Solutions

  • Solutions
    • Live Scan
    • Single Sign-on
    • Digital Onboarding
    • Biometric Collection
    • AFIS/ABIS
    • Palm Vein Identification
    • Palm Vein Payments
    • Enhanced Customer Experiences
  • Industries
    • Law Enforcement
    • Healthcare
    • Financial
    • Government
    • Enterprise
    • Education / Non-profit
    • Cannabis
    • Retail
  • About
    • About Fulcrum
    • About Fujitsu
    • Our Partners
    • Case Studies
    • Careers
  • News
  • Events
  • Contact
    • Support
  • Store

Cyber Resilience & Responsibility

We build biometric technology the way it should be trusted — secure by design, for its whole lifetime.

Our identification software protects some of the most sensitive decisions our customers make. Cyber resilience is not a feature we add — it is the standard we hold every release to, and a commitment we keep long after a product ships.

Report a vulnerability

Our Mission

Resilience is a promise we keep across the entire life of a product.

As a provider of biometric matching and identification software, we sit inside systems where security and integrity are everything. Our components are engineered to perform their work — including matching that returns anonymous results, without resolving a person’s real-world identity — while resisting compromise and giving the teams who integrate our technology what they need to stay secure.

That commitment rests on four practices we hold ourselves to on every release:


Secure by design and by default

Security is built into how we design, develop and ship — minimal attack surface, safe defaults, and threat modelling before code, not after an incident.


Transparency for integrators

We give the partners who build on our software a clear software bill of materials and the security information they need to make their own products resilient.

Vulnerability handling, for real

We identify, assess and remediate vulnerabilities throughout each product’s support period, and we publish security advisories and updates when they matter.


Working with the community

We welcome reports from security researchers and treat good-faith disclosure as a partnership, not a threat. See our disclosure policy below.



EU Cyber Resilience Act

Our approach to the Cyber Resilience Act (Regulation (EU) 2024/2847)

The CRA sets mandatory cybersecurity requirements for products with digital elements placed on the EU market. As a manufacturer of software components supplied to integrators, we take these obligations seriously and are aligning our engineering and disclosure practices with them ahead of the deadlines.

Concretely, we are committed to: designing and maintaining our products to the CRA’s essential cybersecurity requirements; handling vulnerabilities effectively across a defined support period; maintaining a software bill of materials; reporting actively exploited vulnerabilities and severe incidents to the relevant authorities within the required timelines; and providing integrators with the information they need to meet their own obligations.


11 Sep 2026


Reporting obligations take effect


11 Dec 2027


Full requirements apply


Support period


Vulnerabilities handled for the product’s stated lifetime



Coordinated vulnerability disclosure

Found a security issue? Here’s exactly what happens next.

We operate a coordinated vulnerability disclosure process. Report an issue in good faith and we will work with you through to a fix and, where appropriate, public acknowledgement of your contribution.


You report

Submit through our form or contact our security point of contact directly.

We acknowledge

We confirm receipt within [X business days] and assign a point of contact.

We triage

We validate, assess severity and keep you informed of our findings.

We remediate

We develop, test and release a fix, and notify affected users.

We disclose

We coordinate timing of any public advisory with you.


Safe harbour for good-faith research

If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, will work with you to understand and resolve the issue quickly, and will not recommend or pursue legal action related to your report.



Footer

  • LinkedIn
  • YouTube

Solutions

  • Live Scan
  • Single Sign-on
  • Digital Onboarding
  • Biometric Collection
  • AFIS/ABIS
  • Palm Vein Identification
  • Palm Vein Payments
  • Enhanced Customer Experiences

Industries

  • Law Enforcement
  • Healthcare
  • Financial
  • Government
  • Enterprise
  • Education / Non-profit
  • Cannabis
  • Retail

Company

  • About Fulcrum
  • Careers
  • Locations
  • Store
  • Legal Policies
  • Support
  • M&S Program
  • Cyber Resilience & Responsibility
  • Get Fingerprinted Now

Fulcrum Biometrics, Inc.
(Global Headquarters)
16108 University Oak
San Antonio, TX 78249

Office: +1-800-430-4601
Intl: +1-210-257-5615

Copyright © 2026, Fulcrum Biometrics | Privacy Policy | Log in