The face passed every check. It was generated — HyperVerge Fraud Prevention was the only system of sixteen to meet every DHS RIVTD Track 2 benchmark — deepfake detection, deduplication and AML on the same journey as onboarding.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Fraud Prevention — deepfake, forgery and AML. The rest of the platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Deepfake detection, deduplication, forgery checks and AML on one journey — with the DHS RIVTD Track 2 sole pass as its strongest measured evidence.
What consolidation actually replaces, dimension by dimension.
| Dimension | A blink prompt and a reviewer | Fraud Prevention (HyperVerge) |
|---|---|---|
| Liveness | A blink prompt | ISO 30107-3 Level 2 certified |
| Deepfakes | Not considered | DeepfakeSafe at the point of capture |
| Injection | Invisible | Device intelligence — ask how it is handled |
| Repeat fraud | Each application judged alone | Dedup across everyone enrolled |
| AML | A separate batch queue | Screened inside the same journey |
| What it is NOT | — | Not a permanent guarantee — attacks move |
Ask about INJECTION attacks separately from liveness: ISO 30107-3 certifies presentation attacks, and a virtual camera never presents anything. Certifications are point-in-time — ask about retraining cadence too.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Distinguishing a live person from a printed photo, a screen replay, a mask or a rendered deepfake held to the camera. Certified against ISO 30107-3 Level 2, which tests against a defined set of attack instruments.
A virtual camera feeding synthetic video directly into the app never passes through a lens at all, so presentation-attack detection alone does not see it. Ask specifically how this is handled — it is the attack that is growing fastest.
Matching a new applicant's face against everyone already enrolled, to catch the same person opening accounts under different identities. Catches organised fraud that per-application checks pass individually.
Tampering detection on submitted documents, plus screening against sanctions and PEP watchlists. Forgery detection looks for edits and template mismatches rather than checking whether the person is real.
One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.
HyperVerge Fraud Prevention catches the synthetic and the repeat — deepfakes, dedup and the portfolio, and paired with the human firewall.
Identifying synthetic and manipulated faces at the point of verification. The capability behind the DHS Track 2 result, and the one under the most active attack development.
Presentation attack detection tested by iBeta against a defined set of attack instruments — photos, replays, masks. A measured result on a published protocol, not a marketing claim.
Matching against everyone already enrolled to catch one person opening several accounts. This finds organised fraud that every individual application check would pass.
Tampering and template-mismatch detection on submitted documents. A different question from whether the person is real, and one a face check cannot answer.
Emulators, virtual cameras, repeated device fingerprints and other environmental signals. Often the layer that catches an injection attack the biometric check alone would miss.
Watchlist screening as part of the same journey rather than a separate system with its own queue, so a hit surfaces before onboarding completes rather than in a batch review.
How the NIST benchmarks work, and fraud prevention deployed in the field.
How face-recognition benchmarks actually work.
Fraud prevention deployed in a fintech.
Verification at exchange scale.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
In August 2024 the US Department of Homeland Security Science and Technology Directorate published results from its Remote Identity Validation Technology Demonstration. Track 2 assessed one specific task: matching a selfie against an identity document and correctly identifying impostors. Sixteen systems were approved to participate, benchmarks were set at a minimum 90% true positive rate and a maximum 1% false positive rate, and HyperVerge was the only system to meet all of them. That is a strong and unusually concrete credential, and it is worth repeating in exactly those terms rather than expanding it. It says nothing about the other tracks, it is a point-in-time result on a defined test set, and it is not a statement that no deepfake will ever pass in your deployment. Precision here protects you: an inflated version of this claim collapses the moment a technical evaluator checks it.
Presentation attack detection asks whether what the camera sees is a live person. An injection attack never goes near the camera: a virtual camera driver or a tampered client feeds synthetic video straight into the application, so the image arriving looks like a perfect capture because nothing was ever presented. Certification schemes like ISO 30107-3 test presentation attacks specifically, which means a Level 2 badge — genuinely meaningful — does not by itself tell you how injection is handled. This is where device intelligence earns its place, spotting emulators, virtual cameras and manipulated clients. When you evaluate any vendor in this category, ask about injection separately from liveness, because the two are different problems and the second is growing faster.
Every check discussed so far evaluates a single application in isolation: is this document real, is this face live, does the selfie match the ID. An organised fraud ring passes all of them, repeatedly, because each individual application is genuinely consistent — the same real person, with real documents, opening the fifteenth account. Face deduplication is the check that operates across applications rather than within one, matching a new applicant against everyone already enrolled. It tends to be the capability that surprises buyers most in a pilot, because it surfaces a category of loss that existing controls were structurally incapable of seeing rather than merely bad at catching.
Both the DHS result and the iBeta ISO 30107-3 certification are point-in-time outcomes against defined protocols using known attack instruments. They are real evidence and considerably better than a vendor claim, and they are not permanent guarantees. Generative models improve continuously, real-time face swaps are now cheap, and an attack developed after a test set was frozen is by definition not in it. The questions that age better than the badge are operational: how often are the detection models retrained, how quickly does a newly observed attack technique reach production, how is injection handled as distinct from presentation, and what is the re-certification cadence. TechBag asks these during scoping, because a vendor with a slightly weaker benchmark and a faster model-update cycle can be the safer choice over a three-year contract.
Synthetic identities, document forgery, repeat applications or account takeover are different problems with different controls. Start from your loss data, not the threat list.
Separately from liveness. ISO 30107-3 certifies presentation attacks; a virtual camera never presents anything. Get the specific answer in writing.
This is where pilots surprise people. Matching new applicants against everyone enrolled surfaces losses your per-application checks were structurally unable to see.
Too tight floods manual review, too loose defeats the point. Budget a couple of months of real volume before the balance settles — it will not settle in a pilot.
A fraud signal at onboarding should reach the credit decision and the review queue, not sit in its own dashboard nobody opens between incidents.
Attacks move faster than contracts. How quickly a newly observed technique reaches production matters more over three years than the benchmark did on day one.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Deduplication found a ring running fifteen accounts off variations of the same face. Every one of those applications had passed our existing checks individually.”
“The DHS Track 2 result is what got them shortlisted. It is a real test with published thresholds, which is more than most vendors in this space can point at.”
“Ask about injection attacks specifically. Liveness certification covers presentation attacks, and a virtual camera is a different problem that needs a different answer.”
“Good detection, but budget for tuning. Our first thresholds sent too much to manual review, and getting that balance right took a couple of months of real traffic.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity fraud prevention market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
DHS Track 2 sole pass; ISO 30107-3 L2.
The grid nobody publishes — strength of measured benchmark evidence vs breadth across the onboarding journey.
Measured benchmarks, on one journey.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against a global IDV vendor, rules with manual review, and nothing beyond KYC — on measured evidence, injection and dedup.
| Dimension | HyperVerge Fraud Prevention | A global IDV vendor | Rules and manual review | Nothing beyond KYC |
|---|---|---|---|---|
| Deepfake / liveness evidence | DHS Track 2 sole pass | Varies, often certified | Human judgement | None |
| Injection attack handling | Device intelligence | Varies | No | No |
| Cross-application dedup | Face deduplication | Usually available | If someone notices | No |
| AML in the same journey | Yes | Usually | Batch | No |
| India data residency | Not stated | Varies | Your servers | — |
| Published pricing | Quote-only | Varies | Staff cost | Free |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Drag the sliders (monthly verification volume; average fraud loss per incident). Estimates model losses from synthetic identities and repeat applications that per-application checks pass individually. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote-only — HyperVerge publishes no price, and per-check cost varies by type. TechBag scopes the check mix including the tuning ramp, then quotes in INR with GST.
Best when deepfakes are already live
Best for a broader rollout
Best across the journey
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which fraud type is actually costing you? Synthetic identity, forgery, repeat applications and takeover need different controls.
How are injection attacks handled, specifically? ISO 30107-3 certifies presentation attacks; a virtual camera is a different problem.
When was the liveness certification issued, and what is the re-certification cadence? Point-in-time results age.
How quickly does a newly observed attack technique reach production? Over a three-year contract this beats a day-one benchmark.
Is dedup against your whole enrolled base, and is it included in the quote? It is often priced separately.
Who works the exception queue during tuning? Thresholds take real traffic and a couple of months to settle.
Where is biometric data stored? Nothing is published, and biometric data carries its own sensitivities under DPDP.
Which checks are billed, and at what rate each? Per-check pricing varies by type and nothing is published.
Run deduplication against your existing base first — that is where pilots surprise people — or let a TechBag advisor get the injection-attack and residency answers in writing.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.