Item 1A. Risk Factors 13
Item 1B. Unresolved Staff Comments 27
Item 2. Properties 27
Item 3. Legal Proceedings 27
Item 4. Mine Safety Disclosures 27
PART II
Item 6. Reserved 32
Item 8. Financial Statements and Supplementary Data 43
Item 9A. Controls and Procedures 43
Item 9B. Other Information 43
Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspection 43
PART III
Item 10. Directors, Executive Officers and Corporate Governance 44
Item 11. Executive Compensation 49
Item 14. Principal Accounting Fees and Services 60
PART IV
Item 15. Exhibits and Financial Statement Schedules 61
SIGNATURES 62
i
FORWARD-LOOKING
STATEMENTS
Certain
statements discussed in Item 1 (Business), Item 1A (Risk Factors), Item 3 (Legal Proceedings), Item 7 (Management’s Discussion
and Analysis of Financial Condition and Results of Operations), Item 7A (Quantitative and Qualitative Disclosures About Market Risk)
and elsewhere in this Annual Report on Form 10-K as well as in other materials and oral statements that the Company releases from time
to time to the public constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform
Act of 1995. Such forward-looking statements concerning management’s expectations, strategic objectives, business prospects, anticipated
economic performance and financial condition and other similar matters involve significant known and unknown risks, uncertainties and
other important factors that could cause the actual results, performance or achievements of results to differ materially from any future
results, performance or achievements discussed or implied by such forward-looking statements. Such risks, uncertainties and other important
factors are discussed in Item 1A (Risk Factors) and Item 7 Management’s Discussion and Analysis of Financial Condition and Results
of Operations. In addition, these statements constitute the Company’s cautionary statements under the Private Securities Litigation
Reform Act of 1995. It should be understood that it is not possible to predict or identify all such factors. Consequently, the following
should not be considered to be a complete discussion of all potential risks or uncertainties. The words “anticipate,” “estimate,”
“expect,” “project,” “intend,” “believe,” “plan,” “target,” “forecast”
and similar expressions are intended to identify forward-looking statements. Forward-looking statements speak only as of the date of
the document in which they are made. The Company disclaims any obligation or undertaking to provide any updates or revisions to any forward-looking
statement to reflect any change in the Company’s expectations or any change in events, conditions or circumstances on which the
forward-looking statement is based. It is advisable, however, to consult any further disclosures the Company makes on related subjects
in its Quarterly Reports on Form 10-Q and Current Reports on Form 8-K filed with the Securities and Exchange Commission.
Emerging
Growth Company Status
We
are an “emerging growth company,” as defined in the Jumpstart Our Business Startups Act enacted in April 2012, and, for as
long as we continue to be an “emerging growth company,” we may choose to take advantage of exemptions from various reporting
requirements applicable to other public companies including, but not limited to, not being required to comply with the auditor attestation
requirements of Section 404 of the Sarbanes-Oxley Act of 2002, reduced disclosure obligations regarding executive compensation in our
periodic reports and proxy statements, and exemptions from the requirements of holding a nonbinding advisory vote on executive compensation
and stockholder approval of any golden parachute payments not previously approved. We will remain an “emerging growth company”
until the earliest of (i) the last day of the fiscal year in which we have total annual gross revenues of $1 billion or more; (ii) the
last day of the fiscal year following the fifth anniversary of the date of the first sale of our common equity securities pursuant to
an effective registration statement; (iii) the date on which we have issued more than $1 billion in non-convertible debt during the prior
three year period; and (iv) the date on which we are deemed to be a “large accelerated filer.” We may take advantage of the
extended transition period until the first to occur of the date we (i) are no longer an “emerging growth company” or (ii)
affirmatively and irrevocably opt out of the extended transition period. Consequently, our financial statements may not be comparable
to companies that comply with public company effective dates
ii
PART
I
Item
1. Business Overview
Ipsidy
Inc. dba authID.ai (together with its subsidiaries, the “Company”, “authID.ai”, “we” or “our”)
is a leading provider of secure, mobile, biometric identity verification software products delivered by an easy to integrate Identity
as a Service (IDaaS) platform. Our mission is ultimately to eliminate all passwords and to be the preferred global platform for biometric
identity authentication. Our vision is to enable every organization to “Recognise Your Customer” instantly, without friction
or loss of privacy, powered by the most sophisticated biometric and artificial intelligence technologies.
The explosive growth in online
and mobile commerce, telemedicine, remote working and digital activities of all descriptions is self-evident to everyone who lived through
the Covid 19 pandemic since 2020. Identity theft, phishing attacks, spear-phishing, password vulnerabilities, account takeovers, benefits
fraud - it seems like these words have entered our daily lexicon overnight. These are significant impediments to the operations and growth
of any business or organization, and dealing with the risks and consequences of these criminal activities has created significant friction
in both time, cost and lost opportunity. Consider all the outdated methods that organizations have implemented in order to prevent fraud.
The requests to receive and enter one-time passwords, that can be easily hijacked. The vulnerable security questions you get asked –
whether on-line or when reaching out to a call center – what was your first pet’s name? who was your best friend in high
school? These steps all add up to friction, making it difficult for consumers to login, transact and execute daily tasks, with little
added protection from fraud. Surely there is a better way to address these challenges? authID.ai believes there is.
authID.ai
provides secure, facial biometric, identity verification, and strong customer authentication. We maintain a global, cloud-based IDaaS
platform for our enterprise customers to enable their users to easily verify and authenticate their identity through a mobile device
or desktop (with camera) of their choosing (without requiring dedicated hardware, or authentication apps). We can help our customers
establish a proven identity, creating a root of trust that ensures the highest level of assurance for our passwordless login and step-up
verification products. Our system enables participants to consent to transactions using their biometric information with a digitally
signed authentication response, embedding the underlying transaction data and each user’s identity attributes within every electronic
transaction message processed through our platform.
Digital
transformation across all market segments requires trusted identity. Our identity platform offers innovative solutions that are flexible,
fast and easy to integrate and offer seamless user experiences. authID’s products help advance digital transformation efforts without
the fear of identity fraud, while delivering frictionless user experiences. We believe that it is also essential that electronic transactions
have an audit trail, proving that the identity of the individual was duly authenticated. Our platform provides biometric and multi-factor
identity software, which are intended to establish, authenticate and verify identity across a wide range of use cases and electronic
transactions.
authID’s
products focus on the broad requirement for enabling frictionless commerce by allowing an entity to instantly “Recognise their
Customer”. Organizations of all descriptions require cost-effective and secure means of growing their business while mitigating
identity fraud. We aim to offer our enterprise customers products that can be integrated easily into each of their business and organizational
operations, in order to facilitate their adoption and enhance the end user customer experience.
Our
management believes that some of the advantages of our IDaaS Platform approach are the ability to leverage the platform to support a
variety of vertical markets and the adaptability of the platform to the requirements of new markets and new products requiring cost-effective,
secure, and configurable mobile solutions. Our target markets include banking, fintech and other disrupters of traditional commerce,
small and medium sized businesses, and system integrators working with government and Fortune 1000 enterprises. At its core, the Company’s
offering, combining its proprietary and acquired biometric and artificial intelligence technologies (or AI), is intended to facilitate
frictionless commerce, whether in the physical or digital world. The Company intends to increase its investment in developing, patenting
and acquiring the various elements necessary to enhance the platform, which are intended to allow us to achieve our goals. One of the
principal intended areas of investment is to enhance and expand our use of artificial intelligence in proprietary software, that we believe
will increase our value to enterprise customers and stockholders alike.
1
authid.ai
is dedicated to developing advanced methods of protecting consumer privacy and deploying ethical and socially responsible AI. authID
is developing a culture that proactively encourages and rewards our employees for considering the ethical implications of our products.
We believe that a proactive commitment to ethical AI presents a strong business opportunity for authID and will enable us to bring more
accurate products to market more quickly and with less risk to better serve our global user base. Our methods to achieve ethical AI include
engaging the users of our products with informed consent, prioritizing the security of our user’s personal information, considering
and avoiding potential bias in our algorithms, and monitoring of algorithm performance in our applications.
The Company also owns an entity in South Africa Cards Plus which
manufactures secure plastic identity credentials and loyalty card products.
The
Company was incorporated in the State of Delaware on September 21, 2011, and changed our name to Ipsidy Inc. on February 1, 2017. In
order to better align the branding of our Company with our future focus and goals on June 14, 2021 we changed our business name to “authID.ai”.
To that end, we registered domain names under that name and applied for a United States trademark registration in that name.
Our
Common Stock is traded on the Nasdaq Capital Market under the trading symbol “AUID”. Our corporate headquarters is located
at 670 Long Beach Blvd., Long Beach, NY 11561 and our main phone number is (516) 274-8700. We maintain a website at www.authid.ai.
The information contained on, or that can be accessed through, our websites is not incorporated by reference into this prospectus and
is intended for informational purposes only.
Global
Market Opportunity
The disruption caused by the
global COVID-19 pandemic since 2020 has contributed significantly to several market trends driving growth and demand for stronger, more
secure identity verification and authentication solutions and services such as those authID.ai provides. A key trend is the accelerated
pace of digital transformation at the enterprise level, driven largely by the increased demands for online goods and sharing-economy services
by consumers, The shift to working from home, and the remote IT challenges this lifestyle change presents is also driving opportunities
for strong workforce identity and application access authentication. Today, even as companies begin to announce return to work policies,
data show that millions of workers will continue to work remotely, a long-term shift that will require enhanced security across many industry
sectors.
Unfortunately, the increase in remote work and digital, non-face-to-face
commerce has also resulted in increased fraud, phishing scams and cyber security risks. These trends, as well as increased regulation
mandates by governments, whether Federal, State, local or international, are key drivers of the need for improved processes to verify
and authenticate identities.
Digital
Transformation
Digital transformation, or the integration of digital technology into
all areas of a business, is fundamentally changing how organizations operate and deliver value to customers. The global disruption of
the last two years dramatically increased the need for organizations to be more agile to meet changing markets, evolving technology and
consumer demands. According to IBM research, more than 60% of surveyed executives are using this period of change to rapidly advance their
enterprise’s transformation. (IBM Institute for Business Value “Digital Transformation Report” 2021) A McKinsey Global
Survey of executives found that companies have accelerated the digitization of their customer and supply-chain interactions and of their
internal operations by three to four years (McKinsey, October 2020). According to Statista, spending on digital transformation in 2022
will reach $1.8 trillion, growing to $2.8 trillion by 2025. Statista also forecasts that as much as 65% of the world’s gross domestic
product will be digitalized by 2022. (Statista “Spending on digital transformation technologies and services worldwide from 2017
to 2025” 2022).
Digital
and mobile technologies have significantly changed people’s lives in a remarkably short time, including how we work, shop, socialize
and bank. Escalating increases in mobile application downloads for digital goods and services by even the most reluctant consumers, dramatically
altered service delivery across broad market segments, creating lasting effects that we believe are likely to stay.
Enterprises
that were able to, scrambled to reduce reliance on physical outlets and to drive customers to remote digital channels offering seamless
and secure user experiences. Electronic services—from mobile banking to online grocery shopping to tele-medicine—have increased
multifold within the past year.
Key
to realizing digital transformation goals and driving revenue growth is collaborative trust between buyers and sellers delivered through
a positive user experience (UX). Strong identity assurance that is established from day one and spans the entire customer online or in-person
journey ensures that service providers and consumers, employers and employees that operate within the digital economy are who they say
they are. Efficient and reliable identity assurance, reduces friction and improves user experience in the process.
MarketsandMarkets,
the B2B research firm, projects that the global digital identity solutions market will grow from $23 billion in 2021 to $49.5 billion
by 2026, at a CAGR of 16.3%. The company attributes this significant growth to the increase in identity-related frauds and data breaches,
as well as compliance with existing and upcoming regulations. The firm further predicts that the market for digital identity and document
verification services, a subset of the digital identity market, offers significant potential for growth opportunities, with revenues
to rise to US$15.8 billion by 2025. (MarketsandMarkets “Digital Identity Market” 2020 and “Identity
Verification Market” 2020).
2
Forrester
Research has stated that the average help desk labor cost for a single password reset is about $70. (Forrester Research “Best
Practices: Selecting, Deploying, And Managing Enterprise Password Managers” 2018) Forrester Research determined that large
organizations spend up to $1 million per year on staffing and infrastructure to handle password resets alone. Passwords are the leading
cause of major security breaches and Verizon’s 2021 Data Breach report estimates that over 80% of breaches are caused by weak or
stolen passwords. The ability to eliminate the need for passwords by enabling the consumer to easily and securely authenticate with their
own biometrics represents a significant cost savings opportunity across all industries.
Remote
Working
Over
the last two years, the pandemic’s stay-at-home mandates accelerated the transition to remote and hybrid work across many industries.
According to the Pew Research Institute, roughly six-in-ten U.S. workers who say their jobs can mainly be done from home are working
from home all or most of the time. This compares to the 23% who say they teleworked frequently before the coronavirus outbreak. (Pew
Research Center “COVID-19 Pandemic Continues To Reshape Work in America” Feb 2022 ).With workers’ preferences
for flexibility, companies are adapting their operations to meet the IT, security and mobility needs of a workforce that may never fully
return to the traditional office setting. According to estimates by Gartner Inc, remote workers will represent 32% of all employees worldwide
by the end of 2021, almost doubling in two years from 17% of employees in 2019. Gartner also estimates that 51% of all knowledge workers-
those involved in knowledge-intensive occupations, such as writers, accountants, or engineers will be working remotely at least one day
a week by the end of 2021, (Gartner, “Gartner Forecasts 51% of Global Knowledge Workers Will Be Remote by the End of 2021”,
2021 ).
While remote, decentralized
teams can boost morale and productivity, remote work can also increase opportunities for hackers to infiltrate corporate networks. Enterprise
IT organizations must now address new IT requirements and cyber challenges generated in the work from home environment. Studies have also
shown that employees are more likely be distracted when working from home and more susceptible to phishing scams. According to Equifax,
cyber-attacks are much more likely to occur through mundane errors like a user choosing an easy-to-guess password or not changing the
default password on something like a router.
To
meet the increased enterprise security and mobility needs of this expanded remote workforce, IT decision makers are reassessing their
data protection strategies in an effort to secure these remote workers and protect company assets. While IT continues to drive password
hygiene through security training sessions, we believe legacy tools like one-time pin codes and knowledge-based authentication are no
longer effective in mitigating risks.
The
result is increased demand for next-generation biometric authentication technology and a greater urgency to transform quickly. According
to Ranjit Atwal, Senior Research Director at Gartner, “Through 2024, organizations will be forced to bring forward digital business
transformation plans by at least five years. Those plans will have to adapt to a post-COVID-19 world that involves permanently higher
adoption of remote work and digital touchpoints
The
Increase in Identity Fraud
Unfortunately, with this increased
demand for online services, remote working and digital convenience, organizations also face another proliferating challenge – the
need to improve cybersecurity measures. We believe that never before, have criminals been so active in using stolen data or credential-stuffing
attacks in attempts to infiltrate corporate networks.
According
to Statista, over 11,000 data breaches have occurred in the United States since 2005 with more than 1.7 billion individual records breached
(Statista “Annual number of data breaches and exposed records in the United States from 2005 to 1st half 2020” 2021).
Recent research conducted by the Identity Theft Resource Center reported a total of 1,862 data breaches in 2021, surpassing both 2020’s
total of 1,108 and 23% higher than the previous record of 1,506 set in 2017. (Identity Theft Resource Center “2021 Data Breach
Report”, 2022).
Verizon’s 2021 Data Breach
Investigations Report found that phishing efforts by hackers to entice users to ‘reveal’ passwords were present in 36% of
breaches in 2020, up from 25% in 2019. Ransomware attacks are also on the rise, with almost 85% of ransomware attacks showing evidence
of credential theft activity (Coveware “Quarterly Ransomware Report”, 2021)
Digital
transformation efforts must address these risks.
3
The
Drive for Zero Trust Security
First coined in 2010, by Forrester analyst John Kindervag, the term
‘Zero Trust’ declares that all network traffic is untrusted and that any request to access any resource must be done securely.
(Forrester Research “Build Security Into Your Network’s DNA: The Zero Trust Network Architecture”, 2010). Zero Trust
requires that all users, both inside or outside the organization’s network, be authenticated before being allowed to access applications
and data.
In 2021, as the rate of cybercrime,
digital fraud and ransomware spiraled upward, the Biden Administration issued an executive order (the “Biden Order”) calling
on the U.S. government to institute “bold changes and significant investments” in security measures to better insulate federal
networks from attack. This was followed by the White House Office of Management and Budget in October 2021 defining a “zero trust”
strategy, outlining the security architecture required to overhaul federal cybersecurity practices. In January 2022, the Administration
gave federal agencies until the end of the fiscal year 2024 to “achieve specific zero trust security goals.”
The Zero Trust approach will
likely further drive nationwide adoption of multi-factor authentication (MFA), the requirement of additional verification factors, so
users cannot log in with just a username and password. Solutions for achieving zero trust are not likely to include legacy MFA options
like vulnerable one-time pin codes or easy-to-discover, knowledge-based questions like “What was the make of your first car?”
The Biden Order specifically stated that “agency systems must discontinue support for authentication methods that fail to resist
phishing, including protocols that register phone numbers for SMS or voice calls, supply one-time codes, or receive push notifications”
Attacks on these legacy methods have proven enterprises will need stronger authentication alternatives to establish trust and defend against
highly sophisticated cybercriminal networks.
The Biden Order is expected
to drive deployment of upgraded security methods by both the federal government and private sector businesses that contract with the government.
We may also expect to see a change from security vendors and enterprise organizations across a range of market segments, as they look
to the Biden Order for guidance. In the post-COVID-19 scenario, the global zero trust security market size is projected to grow from USD
19.6 billion in 2020 to USD 51.6 billion by 2026, recording a compound annual growth rate (CAGR) of 17.4% from 2020 to 2026 (MarketsandMarkets,
“Zero-Trust Security Market” 2021).
Identity
Verification Impact Across Sectors
Financial
services, ecommerce and the shared economy, and healthcare are confronted by the challenges of identifying their customers, patients
and benefits recipients with ease and certainty in the digital world. Organizations across all sectors need to control access to their
data and technology systems by their employees. Governments around the world are imposing new data privacy and authentication regulations,
which also impose a “call to action” for many of these businesses and organizations. authID.ai’s approach is to offer
our products to enterprises and organizations for their customers in a Customer Identity & Access Management (“CIAM”)
model as well as for their employees in a workforce model.
Financial
Services & Fintech
Financial services institutions
are facing a range of digital transformation challenges and a growth in the embrace of non-traditional fin-tech providers, such as non-bank
lending companies, peer-to-peer mobile payment apps and the rapid emergence of cryptocurrencies, NFT’s and other digital assets
exchanges. Key to this effort is providing enhanced digital customer experience while balancing the need for high assurance identity authentication
to prevent fraud and account take-over throughout the customer journey,
4
Convenience, however, traditionally
opposes stronger identity assurance – the easier it is to open or access an account, the less safeguards there may be to prevent
fraud. Javelin Strategy & Research found that in 2020 identity fraud losses in the financial services industry grew to $56 billion.
(Javelin Strategy & Research “2020 Identity Fraud Report” 2020). The study reported that identity fraud scams that targeted
consumers directly to steal passwords and other personally identifiable information accounted for $43 billion of that cost. LexisNexis
found that the cost of fraud for U.S. financial services and lending firms has increased, with every $1 of fraud loss now costing U.S.
financial services firms $4, up 25% from 2019. Their study also found that fraudsters followed consumer’s pandemic shift towards
mobile transactions, with more than half of surveyed financial services firms reporting a 10% or greater increase in fraud in the mobile
channel. (“LexisNexis® True Cost of FraudTM Study: Financial Services & Lending”, 2021). And with 40% of all
fraudulent activity related to account takeover reported to occur within a day after the attack, the need for strong customer authentication
is critical.
Experts
recommend that efforts to combat this fraud must focus on moving consumers from static passwords to safer authentication methods. According
to Gartner, their clients are increasingly seeking “passwordless” authentication methods such as FIDO2 Strong Authentication
to improve user experience (UX) and enhance security by eliminating centrally stored passwords—a key target for cyber criminals
(Gartner Research Ibid). Goode Intelligence believes that mobile biometrics are key to securely effecting this transformation and forecasts
that over $5.8 trillion of mobile biometric payments will be made annually and over three billion biometric payment users by 2026. (Goode
Intelligence “Mobile Biometrics for Financial Services; Market and Technology Analysis, Adoption Strategies and Forecasts 2021-2026”
2021).
E-Commerce &
Shared Economy
Good
consumer experience and personalization is key to driving revenue growth in e-commerce and the shared economy. Biometric identity verification
seamlessly integrated into online experiences can reduce friction for first-time buyers who are uninterested in opening accounts before
completing their orders or for return customers who expect online purchases to be seamless and secure. A survey of 7,000 North American
and European consumers indicated that 92 percent expect digital retail experiences to be fast, frictionless and secure, and 73 percent
believe account creation or online transactions should happen instantly. Allowing users to identify themselves with their trusted biometrics
not only foils the scammers, but it is also a more effortless and elegant user interface.
In
the last year, both traditional and online retailers were driven by the COVID-19 pandemic to meet the surge in demand for online fulfilment.
According to Digital Commerce360 estimates, consumers spent more than $860 billion online with U.S. merchants in 2020, up 44.0% year
over year. That increase is purported to be the highest annual U.S. ecommerce growth in at least two decades, and is nearly triple the
15.1% increase in 2019 over 2018.
The
sharing economy is expected to grow to $335 billion by 2025 (Statista, “Value of the sharing economy worldwide in 2014 and 2025”
2020). In the sharing economy where assets owned by members of a network can be temporarily accessed by other members of the network,
collaborative trust between buyers and sellers is paramount. Identity verification is critical for security and adherence to regulatory
requirements such as validating driving or criminal history, age verification, and credit history. Secure biometric identification ensures
that service providers and consumers within the sharing economy are who they say they are, reduces friction and improves user experience
in the process.
Healthcare
Since
2020, remote healthcare services have expanded exponentially - virtual urgent-care visits spiked by 683% between March and April 2020,
while virtual, nonurgent care visits grew by an unprecedented 4,345%. (Journal of the American Medical Informatics Association “COVID-19
transforms health care through telemedicine: Evidence from the field” 2020). ResearchAndMarkets predicts that the global
telemedicine market will increase to a value of $144.2 billion by 2030, from $27.8 billion in 2019. (ResearchAndMarkets “Telemedicine
Market Research Report to 2030”. 2020).
5
Unfortunately,
with this shift to remote care, a record of weak authentication practices such as shared passwords, and a trove of rich personal data,
the healthcare market is believed to be even more susceptible to identity fraud. Further, IBM reported that data breaches in the healthcare
sector had the highest average cost amounting to $7.13 million per breach amid the COVID-19 pandemic (IBM Security “Cost of Data
Breach Report 2020” 2020).
Medical
identity theft has an annual economic impact of around $41 billion a year and the value of stolen medical information is 10 times the
value of stolen credit cards. Identity thieves can use compromised medical records to acquire medical treatment, receive elective surgery,
and even fill prescriptions using the victim’s personal details. In one study, 20 percent of victims indicated they got the wrong
diagnosis or treatment, or that their care was delayed because there was confusion about what was true in their records due to identity
theft. In addition, because there are currently no regulatory consumer protections in place that limit the financial liabilities for
medical identity fraud, the average out-of-pocket cost to victims is $13,500 (Medical Identity Fraud Alliance).
The
FIDO Alliance – The Mission To Eliminate Passwords
The
reliance on passwords has long been acknowledged as highly frustrating for users, costly for organizations to maintain and reset quickly,
as well as one of the weakest security practices for user authentication. The reuse of the same passwords by individuals across multiple
sites, the massive data breaches targeting user credentials, and widespread phishing efforts by hackers to entice users to ‘reveal’
passwords create security risks for every organization.
The
FIDO (Fast Identity Online) Alliance was formed in 2012 to address the security risks to enterprises and the problems individual users
face in creating and remembering multiple usernames and passwords. FIDO compliant solutions eliminate passwords by using the combination
of biometric verification and device authentication via cryptographic security, thereby speeding up and securing user login. FIDO Alliance
members include global leaders and household names in technology and across enterprise software, payments, banking, telecom, ecommerce,
identity, government, and healthcare (https://fidoalliance.org/members/). This cross-industry coalition works jointly to develop interoperable
authentication standards that reduce reliance on passwords with authentication that is more secure, private, and easier to use.
Privacy
Regulations (Ethical AI)
All
business, governmental and other sectors of society are impacted by the need for organizations to comply with increasing data privacy
and authentication regulations. The European Union has led the way with its General Data Protection Regulation, or GDPR, widely considered
the gold standard of data privacy regulation, and other jurisdictions around the world are scrambling to catch up. The United States
has been slow and has only limited regulation at the federal level, which applies only to specific industries such as the Health Insurance
Portability and Accountability Act, or HIPAA. It is therefore falling to the States and local authorities to adopt data privacy requirements
such as the California Consumer Privacy Act or CCP and Illinois’ Biometric Information Privacy Act or BIPA, which are being cloned
by other jurisdictions. We believe that this growing trend will impose an urgency on organizations of all descriptions to improve their
data security and privacy processes, and we believe that biometric identity verification will be a key part of the solution.
We
are dedicated to developing advanced methods of protecting consumer privacy and deploying ethical and socially responsible AI. authID
is developing a culture that proactively encourages and rewards our employees for considering the ethical implications of our products.
Our products are critical to onboarding consumers globally into the digital economy, while better securing their assets and privacy.
We
believe that a proactive commitment to ethical AI presents a strong business opportunity for authID and will enable us to bring more
accurate products to market more quickly and with less risk to better serve our global user base. Our methods to achieve ethical AI include
engaging the users of our products with informed consent, prioritizing the security of our user’s personal information, considering
and avoiding potential bias in our algorithms, and monitoring of algorithm performance in our applications.
6
Our
Solutions and Products
We
have established our Identity as a Service Platform with internally developed software as well as acquired and licensed technology, which
provide the following services: (1) biometric capture and matching (e.g. for faces, voices and fingerprints); (2) remote document collection
and authentication; (3) multi-factor authentication and passwordless login; and (4) step-up verification for electronic transactions
(e.g. for high value payment transactions).
VerifiedTM
Identity as a Service (IDaaS) Platform Solutions
authID’s
customers can leverage our Verified IDaaS Platform by using a simple API integration. The product suite includes a range
of developer integration tools and documentation that help our customers and systems integrator partners easily configure their identity
and transaction authentication solutions via integration to our secure RESTful API’s. Our platform is designed to support a wide
variety of identity and electronic transactions across a broad range of verticals. Our technical implementation team can assist our customers
and systems integrators to configure the API calls to our platform, and mobile biometric identity authentication services to meet a specific
commercial, geographic or market need. We can thereby provide the next level of transaction security, control and certainty for everyday
transactions. We also make certain services available without integration, using our CloudConnect integrations to identity access management
(IAM) and financial services technology vendors. The Company has the following IDaaS platform capabilities:
7
Other
Identity Products
Payment
Processing
Growth
Strategy
To
achieve our goals of increasing our product penetration in the identity authentication market, the following plans comprise our growth
strategy. authID intends to expand our focus on channel partners, by signing payment processors, system integrators and additional software
suppliers. We are also working to augment our go-to-market model with a new self-service fulfilment model to enable our customers to
directly purchase and integrate our identity software products. The Company also intends to increase its investment in developing, patenting
and acquiring the various elements necessary to enhance our IDaaS platform, which are intended to allow us to achieve our growth goals.
Channel
Strategy
We
intend to expand upon our channel strategy in order to bring our products to a broad market in an efficient and cost-effective way. We
have signed and are pursuing channel partners that play a key role in their respective verticals, including become a member of
the Temenos Marketplace, a digital technology provider for banks and the Auth0 Marketplace, a catalog of trusted technology integrations
that extend the functionality of Auth0’s identity management platform. Our agreement with CU Next Gen provides integration to technology
for credit unions in the United States. We are also pursuing additional strategic partners, including payment processors, system integrators
and software suppliers.
These
channel partners provide access to their wide-ranging enterprise customer portfolios, including new fintech disruptors, merchant services,
ecommerce and sharing economy businesses, all of whom we believe could benefit from the use of our identity verification and authentication
software products. By entering into agreements with such channel partners and leveraging their relationships, we believe we can expand
our footprint much more rapidly and cost effectively, as compared to pursuing direct sales efforts with each customer. Moving forward,
we intend to build a small, high-touch, strategic sales team to identify new use cases and drive expansion and standardization on authID
within our partners’ customer portfolios.
8
Self-Service
We
intend to enhance our sales model by enabling self-service options for our identity authentication products to efficiently reach the
small and medium sized business segment in the United States as well as technology disruptors who require quick and easy use of our platform
for authenticating their users. Our planned self-service offerings are intended to increase software developer and IT operator familiarity
with our products and lead to quicker deployment of our products by our customers. Customers can then expand the use-cases of our services
either through self-service deployment, or with the assistance of our customer success team. We also intend to expand our digital marketing
efforts to drive prospective customers to the self-service portal, and therefore limit the need for extensive outbound sales efforts.
Innovation
As
banking, fintech, traditional retailer, online e-tailers, and sharing economy providers continue to drive digital transformation across
their channels, we aim to be at the forefront by developing new software products that leverage our platform and core competencies in
biometric identity authentication. Our focus on innovation, is intended to add value to and retain our existing customers, as well as
attract new customers. authID intends to build on its patent pending solutions by using machine learning to enhance the artificial intelligence
capabilities of our IDaaS software and platform. We intend to build a team focused on artificial intelligence, employing leading data
scientists and machine learning experts. Their mission will be to make the authID biometric authentication platform the fastest and most
accurate in the market, and then to continually improve our platform to maintain our leading position.
Consumer
frustration with passwords, along with phishing attacks, social engineering and data breaches have driven the need to eliminate passwords
and accelerate adoption of multifactor security across all channels. Today there are more than 5 billion smartphones, laptops and tablets
around the world that can be used as secure authentication devices to access online services and authorize transactions. These trends
are driving the need for a simple, secure, and fast way to manage device registration and deregistration. By combining our patent pending
methods for single message authentication, authorization, and audit, and for device registration through strong identity verification,
authID has created an Identity Recovery (IDR) software product that puts device management in the control of the account owner. By eliminating
the need for users to contact a support center, this product helps our enterprise customers reduce their systems and personnel costs
for supporting users attempting to recover their identity or register a new device for authentication.
We
have an agreement with LoginID, under which we have jointly developed a FIDO2 compliant strong authentication solution, which we offer
as AuthentifID. The AuthentifID service is intended to address the growing demand across all verticals for eliminating the security risks,
operational costs, and consumer dissatisfaction with passwords. We also became a member of the FIDO Alliance, the leading international
organization comprising global leaders in technology that help establish best practices for FIDO authentication deployment. FIDO
compliant solutions eliminate passwords by using the combination of biometric verification and device authentication via cryptographic
security, thereby speeding up and securing user login. By combining our core technologies, we have enhanced our IDaaS platform to offer
device-based multi-factor identity software to complement our biometric multi-factor authentication product in order to support secure
login as well as a broader set of electronic transactions.
In
November 2021, the Company received a US patent for Systems and Methods Using a Primary Account Number to Represent Identity Attributes
(the ’777 Patent”). The ’777 Patent is for a method that enables various attributes of the individual, to be securely
linked to a Primary Account Number (PAN) to authenticate the user’s identity. The PAN of a user may then be used for identifying
a user, without any sensitive data being released, as well as used to provide access, such as accessing a bank account, or other payment
method of the user. The PAN has become the most ubiquitous way of processing credit card and other payment transactions, which can be
sent over established communications networks between banks and merchants anywhere in the world. Using this invention, identity authentication
transactions can be authorized via the individual’s biometrics, such as the user’s unique facial features and routed over
the same networks in the same way as payment transactions.
In February 2022, the Company
received a Notice of Allowance for its US patent application “A Method and System for Transaction Authorization Based on a Parallel
Autonomous Channel Multi-User and Multi-Factor Authentication”. The patent protects a core component of authID’s intellectual
property relating to its Verified identity verification platform. The patent comprises a method that enables an account holder to authorize
a transaction, and at the same time a third-party identity verifier (such as authID) to validate the identity of the account holder, for
example through a personal code or biometrics, and confirm the account holder’s consent for the transaction. By orchestrating authentication
transactions, authID.ai’s method combines explicit consent for the transaction with identity verification, and creates a permanent
record of both, for all parties, secured with a unique digital signature.
9
Select
Acquisitions
As
we have done in the past, we intend to selectively pursue acquisitions that will help us achieve our strategic goals, enhance our technology
capabilities and accelerate growth. We believe pursuing these types of acquisitions will increase our ability to work with existing customers,
add new customers, enter new markets, develop new services and enhance our processing platform capabilities. However, we have no commitments
with respect to any such acquisitions at this time.
Marketing
and Sales
The Company will primarily
target these market segments: 1) fintech and other disrupters of traditional commerce, 2) businesses requiring zero-trust authentication
for their workforce and 3) Fortune 1000 enterprises via channel and OEM partnerships established with some of the largest identity access
management providers (IAM), risk engines, payment providers, and adjacent software providers. To serve these segments, we have begun to
offer turn-key solutions via authID’s CloudConnect program, supporting industry leading IAM, banking and ecommerce platforms to
allow our software to be easily deployed with low-code or even no-code implementations.
Our branding and messaging
will focus on the fact that all three segments understand the critical requirement to recognize the customer instantly without friction.
The Company’s marketing will emphasize the high return on investment that any businesses selling to consumers can achieve if they
replace password models with biometric authentication software. We intend to draw prospects to authID by our ability to empower them to
fight synthetic identities, account takeovers, phishing attacks while achieving their digital transformation goals. The contracts we seek
will be of a recurring nature where we receive an annual fee for every active user (who logs into an application, changes their account
profile, or attempts a high value transaction).
In
order to achieve these goals and thereby drive sales and new revenue, the Company intends to build our sales and marketing team, expand
our sales and marketing activities, as well as invest in innovative technologies.
Revenue
Model
Identity
Management Solutions and Products
The biometric software products
are priced based on a multi-year licensing model which is driven by the number of enrollees in the system and the volume of authentications
required (for example the number of times a consumer is required to present proof of identity). The Company provides its new IDaaS platform
services based on a subscription model, with tiered fees per enrolled user Verified Workforce) or active user (Verified Consumer), comprising
a periodic subscription and where applicable a per transaction fee. The Company’s CardsPlus plastic and credentials card products
are sold at a per unit price which will vary based on the configuration of the features and functionality of the product, as well as the
services provided. Additionally, the Company receives an annual maintenance fee for support for an identity product previously sold to
one of its customers.
Payment
Processing Solutions and Products
The
electronic payment gateway services are volume priced on a per transaction or monthly minimum basis The pricing for the Company’s
closed loop financial payment platform is based on a combination of transaction fee and a subscription model based on numbers of cardholders
and merchants enrolled. The Company also earned leasing income from the rental of unattended kiosks but does not expect this revenue
stream to continue in the future.
10
Competition
authID
offers its VerifiedTM IDaaS platform allowing the Company to on-board customers who wish to deploy our services and solutions in
order to know with biometric certainty who is engaging with them. authID’s solutions include the ability to verify the identity
of a user, via remote identity proofing, then enable digital access, as well as transaction and device authentication, all digitally
signed by the user’s identity. The Company’s platform utilizes commodity, consumer grade mobile devices for customer deployment
with users engaging with the platform via a web-browser or corresponding Android or iOS smartphone app.
We
also offer certain payment processing solutions and smart card products manufacturing and printing. The industry sectors in which these
products compete are characterized by rapid change and new entrants. We will need to consistently develop and improve our products in
order to remain competitive.
The Company’s proprietary,
patent pending Verified IDaaS platform allows our customers to establish trust in identity, authenticate and verify an identity without
a password but with both device and biometric certainty, and not with just a password or one-time pin code. authID.ai’s IDaaS
platform has several identity verification and authentication products each facing different competitors and incumbent technologies we
can replace.
For
onboarding users, employees or customers remotely, Verified delivers seamless identity verification with quick, mobile identity document
verification and facial biometric matching of a selfie to the identity credential photo with liveness confirmation. Our FIDO2 strong
customer authentication and passwordless login product, leverages strong identity verification during device authenticator registration
to create a digital chain of trust between biometrically verified individuals, their accounts, and their devices. Rooted to a trusted
identity obtained during the identity verification and onboarding process, Verified’s biometric multi-factor authentication offers
high-assurance, biometric, cloud-based, multi-factor authentication to secure high-risk transactions.
In reviewing the competitors
that exist for the Company’s current and planned platform products relating to the three main elements of identity management:
the establishing of identity, use of identity through device-based authentication, and use of identity through cloud-based biometric
verification, the Company considers a number of factors. authID’s platform utilizes an Identity as a Service (IDaaS) approach which
combines the three elements into a single fast, secure, and fully automated, platform. authID believes that this full stack platform
approach is exceptional in that it offers documentary identity verification, FIDO device authentication, and cloud based, biometric,
multi-factor verification covering digital account access and transaction confirmation use cases. The competitive landscape includes
several companies that mainly address only one element, with some addressing multiple elements independently without a seamless integration
between them.
In
looking further at our competition, the Company does not consider providers which are major conglomerates with vertically integrated
cybersecurity companies, due to the vast array of services which they offer. Furthermore, some of the competitors which do offer solutions
for digital use cases, are major legacy providers offering hardware heavy solutions principally for governmental users. These include
Idemia, Thales, and Supercom. This is in contrast to authID’s IDaaS approach which is based on offering app and browser-based software
products which are usable on mobile and desktop computing devices without additional hardware requirements.
To further breakdown the competitive
landscape into companies that provide identity proofing we consider the following competitors: Jumio, Au10Tix, OnFido, Mitek, Trulioo,
ID.me, Veriff, and Acuant. Companies that provide only a single solution may be seeking to combine with authentication and biometric verification
technology providers to expand their ID proofing solutions’ capabilities. While authID will continue to offer Proofing (especially
for SMBs that need a complete IDaaS solution) Proof is used once at enrollment, whereas our authentication service is used over and over
in a recurring revenue model. In appropriate cases we may decide to cooperate with these entities and yield the one-time revenue to gain
the recurring authentication revenue.
Another
aspect of the competitive landscape is device-based authentication products using the FIDO standard. Companies that are believed to be
competing with authID in this area are: HYPR, Strongkey, Daon, Trusona, Callsign, Duo and Transmit Security.
11
authID
believes that the simplicity and elegance of simply looking at your phone to “trust your selfie” should compete well against
these incumbents, and offer a more ubiquitous, cost-effective solution without dedicated hardware.
Finally,
looking at the competitive landscape for cloud-based biometric identity verification applications the companies that are believed to
be competing with authID in this area are Jumio, Aware, Acuant, Au10Tix, NEC, and Idemia.
There
are new entrants into each of these markets continually. Each competitor may have a different offering or approach to solve similar problems,
which overlap with those of the Company. Some competitors also include manufacturers who provide systems, or platform solutions to third
party operators and, therefore, do not directly compete with the Company, which operates its own systems. For example, Stripe announced
in June 2021 that they are entering the proofing market, but it is not possible to say what impact that may have on competition.
The
Cards Plus business faces competition both locally in South Africa and internationally. China has become a source of imports of card
products at highly competitive pricing and some local suppliers are reliant on Chinese card manufacturers. Local competitors include
Card Technology Services, Easy Card and Open Gate, Cardz Group and XH Smart Technology (Africa). That said, we believe that we are the
only significant manufacturer in South Africa using digital print technology.
The
payment processing industry has many competitors who provide gateway services, closed loop end-to-end solutions, payment processing,
peer-to-peer payments and bill payments. As these types of services are usually supplied by regional or country specific companies, the
following summary of this competitive landscape, is focused on those countries or regions the Company is actively pursuing business in
today. In Colombia and elsewhere in Latin America where the Company is focused, major competitors include PayU, Credibanco, Redeban,
Mercado Pago, Nequi, and QPagos. Some of these companies may on the other hand be potential customers for our identify transaction platform
and biometric authentication services. Companies in this region that also compete in those sectors include Veritran, Certicamaras, Olimpia
IT, Evertec-Processa and Indra.
Governmental
Regulations
The
Company does not need or require any approval from government authorities or agencies in order to operate its regular business and operations.
However, it is possible that any proposed expansion to the Company’s business and operations in the future would require government
approvals.
Due
to the security applications and biometric technology associated with the Company’s products and platforms, the activities and
operations of the Company are subject to license restrictions and other regulations, such as (without limitation) export controls and
other security regulation by government agencies. Expansion of the Company’s activities in payment processing may in due course
require government licensing in different jurisdictions and may subject it to additional regulation and oversight.
Data
protection legislation in various countries in which the Company does business (including Colombia and the United Kingdom) may require
it to register its databases with governmental authorities in those countries and to comply with additional disclosure and consent requirements