Cyber Resilience & Responsibility
We build biometric technology the way it should be trusted — secure by design, for its whole lifetime.
Our identification software protects some of the most sensitive decisions our customers make. Cyber resilience is not a feature we add — it is the standard we hold every release to, and a commitment we keep long after a product ships.
Our Mission
Resilience is a promise we keep across the entire life of a product.
As a provider of biometric matching and identification software, we sit inside systems where security and integrity are everything. Our components are engineered to perform their work — including matching that returns anonymous results, without resolving a person’s real-world identity — while resisting compromise and giving the teams who integrate our technology what they need to stay secure.
That commitment rests on four practices we hold ourselves to on every release:
EU Cyber Resilience Act
Our approach to the Cyber Resilience Act (Regulation (EU) 2024/2847)
The CRA sets mandatory cybersecurity requirements for products with digital elements placed on the EU market. As a manufacturer of software components supplied to integrators, we take these obligations seriously and are aligning our engineering and disclosure practices with them ahead of the deadlines.
Concretely, we are committed to: designing and maintaining our products to the CRA’s essential cybersecurity requirements; handling vulnerabilities effectively across a defined support period; maintaining a software bill of materials; reporting actively exploited vulnerabilities and severe incidents to the relevant authorities within the required timelines; and providing integrators with the information they need to meet their own obligations.
Coordinated vulnerability disclosure
Found a security issue? Here’s exactly what happens next.
We operate a coordinated vulnerability disclosure process. Report an issue in good faith and we will work with you through to a fix and, where appropriate, public acknowledgement of your contribution.
You report
Submit through our form or contact our security point of contact directly.
We acknowledge
We confirm receipt within [X business days] and assign a point of contact.
We triage
We validate, assess severity and keep you informed of our findings.
We remediate
We develop, test and release a fix, and notify affected users.
We disclose
We coordinate timing of any public advisory with you.
