bkyi20231231_10k.htm
Table of Contents
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
FORM10-K
FOR THE FISCAL YEAR ENDEDDecember 31, 2023
OR
FOR THE TRANSITION PERIOD FROM ___ TO ___
COMMISSION FILE NUMBER: 1-13463
BIO-KEY INTERNATIONAL,INC.
(Exact name of registrant as specified in its charter)
101 CRAWFORDS CORNER ROAD, SUITE 4116, HOLMDEL, NJ07753
(Address of principal executive offices) (Zip Code)
(732) 359-1100
Registrant’s telephone number, including area code.
Securities registered pursuant to Section 12(b) of the Act:
Title of each class Trading Symbol(s) Name of each exchange on which registered
Common Stock, $0.0001 par value per share BKYI Nasdaq Capital Market
Securities registered pursuant to Section 12(g) of the Act: None
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☐ No ☒
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐
Table of Contents
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
Large accelerated filer ☐ Accelerated filer ☐
Non-accelerated filer ☒ Smaller reporting company ☒
Emerging growth company ☐
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☐
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☒
As of June 30, 2023 (the last business day of the registrant’s most recently completed second fiscal quarter), the aggregate market value of the registrant’s common stock held by non-affiliates was $6,303,798 based upon the closing price for shares of the registrant’s post-split common stock of $13.50 as reported by the Nasdaq Stock Market on that date.
As of June 4, 2024 the registrant had 1,814,228 shares of common stock outstanding.
Table of Contents
TABLE OF CONTENTS
PART I 1
Item 1. Business 1
Item 1A Risk Factors 9
Item 1B Unresolved Staff Comments 18
Item 1C Cybersecurity 18
Item 2 Properties 18
Item 3 Legal Proceedings 18
Item 4 Mine Safety Disclosures 18
Item 6 Reserved 19
Item 7A Quantitative And Qualitative Disclosures About Market Risk 25
Item 8 Financial Statements and Supplementary Data 25
Item 9A Controls and Procedures 26
Item 9B Other Information 26
Item 9C Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 26
PART III 27
Item 10 Directors, Executive Officers and Corporate Governance 27
Item 11 Executive Compensation 30
Item 14 Principal Accountant Fees and Services 36
Item 15 Exhibits and Financial Statement Schedules 37
Signatures 73
Table of Contents
EXPLANATORY NOTE
BIO-key International, Inc., and its consolidated subsidiaries (the “Company”, “we” or “us”) is filing this comprehensive annual report on Form 10-K for the fiscal year ended December 31, 2023 (the “Comprehensive Form 10-K”). This Comprehensive Form 10-K contains our audited financial statements for the fiscal year ended December 31, 2023 and 2022 as well as restatement of the following previously filed periods: (i) our unaudited consolidated financial statements covering the quarterly reporting periods during fiscal year 2023, consisting of the quarters ended March 31, 2023, June 30, 2023, and September 30, 2023.
Restatement Background
As previously disclosed, on April 16, 2024, the Audit Committee (the “Audit Committee”) of the Board of Directors of the Company determined, after consultation with the Company’s management and its independent auditors, that the Company made certain errors in the manner in which it recognized revenue generated by its European subsidiary, Swivel Secure Europe, SA, in the first quarter of 2023. In addition, certain allowances for accounts receivable and certain reserves for inventory were understated. As a result, the Company concluded that its previously issued consolidated financial statements for the three months ended March 31, 2023, the three and six months ended June 30, 2023, and the three and nine months ended September 30, 2023 included in the Company’s previously filed Quarterly Reports on Form 10-Q for such periods (collectively, the “Restatement Periods”) should be restated to correct historical errors related principally to the of recognition of the Company’s revenues, allowances for accounts receivable, and certain reserves for inventory.
The need for the restatement arose out of the results of certain financial analysis the Company performed in the course of preparing its fiscal year-end 2023 consolidated financial statements. In the course of the audit of the Company’s consolidated financial statements for the fiscal year ended December 31, 2023, the Company determined that certain errors were made which require the restatement of the Company’s previously issued financial statements for the Restatement Periods. These errors resulted in the overstatement of accounts receivable and revenue, understatements in certain allowances for accounts receivable and certain reserves for inventory, and an understatement of net loss and an overstatement of total stockholders’ equity which errors may also impact other amounts included in the financial statements for the Restatement Periods. The Company principally attributes the errors to a material weakness in internal controls over the recording and processing of revenues, allowances for accounts receivable, and certain reserves for inventory, which the Company is working to remediate in fiscal year 2024.
Items Restated in this Form 10-K
This Form 10-K for the fiscal year ended December 31, 2023 includes the restatement of consolidated financial statements for the quarterly and year-to-date periods in fiscal year which are disclosed in Note U to the consolidated financial statements. Other sections impacted are: Part I, Item 1A. Risk Factors; and Part II, Item 9A. Controls and Procedures.
The Company has not filed, and does not intend to file, amendments to the previously filed Quarterly Reports on Form 10-Q for any of the quarters for the year ended December 31, 2023. Accordingly, investors should rely only on the financial information and other disclosures regarding the Restatement Periods in this Form 10-K or in future filings with the SEC (as applicable), and not on any previously issued or filed reports, earnings releases, or similar communications relating to these periods.
See Note U to the consolidated financial statements, included in Part II, Item 8 of this Form 10-K, for additional information on the restatement and the related consolidated financial statement effects.
PRIVATE SECURITIES LITIGATION REFORM ACT
All statements other than statements of historical facts contained in this Annual Report on Form 10-K, including statements regarding our future financial position, business strategy and plans and objectives of management for future operations, are forward-looking statements. The words “anticipate,” “believe,” “should,” “estimate,” “will,” “may,” “future,” “plan,” “intend” and “expect” and similar expressions generally identify forward-looking statements. These statements are not guarantees of future performance or events and are subject to risks and uncertainties that may cause actual results to differ materially from those included within or implied by such forward-looking statements. These risks and uncertainties include, without limitation, our history of losses and limited revenue; our ability to raise additional capital; our ability to protect our intellectual property; changes in business conditions; changes in our sales strategy and product development plans; changes in the marketplace; continued services of our executive management team; security breaches; competition in the biometric technology and identity access management industries; market acceptance of biometric products generally and our products under development; our ability to convert sales opportunities to customer contracts; our ability to expand into Asia, Africa and other foreign markets; our ability to integrate the operations and personnel of Swivel Secure into our business; fluctuations in foreign currency exchange rates; the duration and extent of continued hostilities in Ukraine and its impact on our European customers; delays in the development of products, the commercial, reputational and regulatory risks to our business that may arise as a consequence of our need to restate our financial statements, including any consequences of non-compliance with Securities and Exchange Commission (“SEC”) and Nasdaq periodic reporting requirements; our temporary loss of the use of a Registration Statement on Form S-3 to register securities in the future; any disruption to our business that may occur on a longer-term basis should we be unable to remediate during fiscal year 2024 certain material weaknesses in our internal controls over financial reporting, the nature and amount of adjustments that may be required from our preliminary estimates of our results of operations for the first quarter of 2024, as the results may vary from the narrative included in prior reports filed with the SEC, and such variance may be material, statements of assumption underlying any of the foregoing, and numerous other matters of national, regional and global scale, including those set forth under the caption “Risk Factors”in Item 1A of this Annual Report and other filings with the Securities and Exchange Commission (“SEC”). These factors are not intended to represent a complete list of the general or specific factors that may affect us. It should be recognized that other factors, including general economic factors and business strategies, may be significant, presently or in the future. Except as required by law, we undertake no obligation to update any forward-looking statement, whether as a result of new information, future events or otherwise.
Table of Contents
PART I
ITEM 1.BUSINESS
Solely for convenience, trademarks and tradenames referred to in this Annual Report on Form 10-K appear (after the first usage) without the ® and TM symbols, but those references are not intended to indicate, in any way, that we will not assert, to the fullest extent under applicable law, our rights or that the applicable owner will not assert its rights, to these trademarks and tradenames.
Overview
BIO-key International, Inc. (the “Company,” “BIO-key,” “we,” or “us”) is a leading identity and access management (IAM) platform provider enabling secure work-from-anywhere for enterprise, education, and government customers using secure multi-factor authentication (MFA). Our vision is to enable any organization to secure streamlined and passwordless workforce, customer, citizen and student access to any online service, workstation, or mobile application, without a requirement to use tokens or phones for roving users and shared workstations. Our products include PortalGuard® and PortalGuard Identity-as-a-Service (IDaaS) enterprise IAM, WEB-key® biometric civil and large-scale ID infrastructure, MobileAuth® mobile phone authentication application for iOS and Android, and high-quality, low-cost accessory fingerprint scanner and FIDO-compliant hardware to provide a full and complete solution for identity-innovating customers.
BIO-key PortalGuard empowers organizations to maximize the power of cloud, mobile and web technologies by securing users’ identities and connecting them with the applications they rely on, while keeping cyber-intruders and unauthorized delegates (proxy users) out. Competing MFA solutions require a phone or token for every user authentication use case, but this is expensive and ineffective for workforce users who cannot use a phone in their workplace, who rove among workstations or share kiosks for access to information systems. BIO-key’s exclusive Identity-Bound Biometrics (IBB) authentication methods address this by making biometric identification based available at any end point device, making the user, not their phone or a token, their own credential.
Our customers trust BIO-key® to secure access to a variety of cloud, mobile and web applications, on-premise and cloud-based hypervisor servers from all of their devices. Employees and contractors sign into BIO-key PortalGuard to seamlessly and securely access the applications needed to do their work, and customers sign into BIO-key PortalGuard to access online services. Organizations use PortalGuard to securely collaborate and communicate with their partners and to provide their customers with flexible, resilient user experiences online and while using mobile devices. PortalGuard can operate standalone as a comprehensive MFA, Single Sign On, and Self-Service Password Reset solution, directly authenticating for Windows sign in and application access, or as an upgraded MFA user experience within an enterprise IAM framework such as Microsoft, Okta, Ping or ForgeRock.
BIO-key’s WEB-key is a scalable biometric service management platform, incorporating key functions for regulatory compliance, enrollment, authentication or identification, and integrity in a multi-tenant private or public cloud delivery platform. Government agencies use BIO-key for their large-scale civil ID projects, because WEB-key underpins a biometric identity ecosystem, is cloud-ready, and provides a scalable, high-integrity trust platform which can be operated anywhere and supports over 30 fingerprint scanners interchangeably.
We also deliver biometric software integration application programming interfaces, or APIs, allowing software developers to leverage our platform to securely and efficiently embed biometric multi-factor authentication, or MFA, into their own products. This allows software developers to focus on their core functionality while BIO-key ensures users enter the application without requiring them to carry their phone or any token.
Even the most security-focused organizations are suffering breaches as a result of human error or improper conduct. As enterprises scale the number of software as a service, or SaaS applications, and multi-cloud services they rely on and the interconnections between them increase, assured identity has emerged as a critical component of an organization’s security framework, directly affecting each triad of cybersecurity – confidentiality, integrity, and availability. As access perimeters dissolve, organizations must evolve from network-based security models to Zero Trust and Continuous Authentication and Risk Trust Assessment (CARTA) security models, focusing on adaptive and context-aware controls. True server-secured biometric verification removes the human nature vulnerability at the root of many security compromises creating a more reliable means to manage user access and protect digital assets against rogue users willing to hand over their credentials to a proxy. Our global identity as a service, or IDaaS, hosting capability allows our customers to simplify and efficiently scale their security infrastructures across internal IT systems and external customer facing applications without installation overhead, security or uptime management efforts.
1
Table of Contents
We designed BIO-key PortalGuard IDaaS and WEB-key to provide organizations an integrated approach to managing and securing all of their identities using the technologies they already use while providing capacity for future needs through the strategic use of biometrics to limit vulnerability and contain authentication costs. Our platform allows users to authenticate their customers, employees, contractors, and partners. It enables any user to connect to any device, cloud or application, all with a simple, customizable, intuitive and consumer-friendly user experience. We utilize server-secured Identity-Bound Biometrics to support roving users without requiring them to carry their phone or a token. As of December 31, 2023, more than 600 customers across multiple industries use BIO-key to secure and manage access for users around the world.
Development of Business
BIO-key was founded in 1993 to develop and market advanced fingerprint biometric technology and related security software solutions. First incorporated as BBG Engineering, the company was renamed SAC Technologies in 1994 and renamed BIO-key International, Inc. in 2002. Our principal executive office is located at 101 Crawfords Corner Road, Suite 4116, Holmdel, NJ, 07733.
BIO-key was a pioneer in developing automated finger identification technology that supplements or compliments other methods of identification and verification, such as personal inspection identification, passwords, tokens, smart cards, ID cards, credit card, passports, driver’s licenses, or other form of possession or knowledge-based credentialing. Our advanced technology and is used to improve both the accuracy and speed of fingerprint biometrics in some of the largest biometric systems in the world.
On June 30, 2020, we enhanced our product offering by acquiring PistolStar, Inc. (“PistolStar”). PistolStar provides enterprise-ready identity access management solutions to commercial, government and education customers throughout the United States and internationally. PistolStar develops and markets our PortalGuard line of software and services.
On March 8, 2022, we expanded our sales and support operation into Europe, Africa and the Middle East (“EMEA”) by acquiring Swivel Secure Europe, SA. Swivel Secure Europe is a Madrid, Spain based provider of IAM solutions serving over 300 customers through a network of dozens of channel partners throughout EMEA. Swivel Secure Europe is the exclusive distributer of AuthControl® Sentry, AuthControl Enterprise and AuthControl MSP product line in Europe, Middle East, and Africa, excluding the United Kingdom. Swivel Secure maintains a direct sales force with offices in Madrid, Spain and Lisbon, Portugal.
Our Products
BIO-key PortalGuard and PortalGuard IDaaS
BIO-key PortalGuard is an independent, customer-controlled and neutral-by-design cloud-based identity platform that allows our customers to integrate with any cloud or on-premise SaaS application, service or cloud host, as well as Windows device authentication through a single secure, reliable and scalable IAM platform. It provides identical capabilities in both a SaaS (PortalGuard IDaaS) or on-premise (PortalGuard) delivery model. PortalGuard integrates BIO-key’s Identity Bound Biometric (IBB) authentication as what-you-are authentication options that are not tied to a device or “what you have” authentication, allowing our customers to positively identify who is accessing their systems, not the device they might have handed off to another user. Our three-way IAM neutrality consists of:
These capabilities allow our customers to combine and authenticate legacy and future technologies and to securely connect users to the technology that they choose. We design transparent compatibility of the BIO-key PortalGuard IDaaS with on-premise infrastructures and public and hybrid clouds.
Our customers use the BIO-key PortalGuard IDaaS to secure their workforces and student populations and make their partner networks more collaborative. PortalGuard IDaaS provides more and secure experiences for their customers and end users, which enables our customers to future-proof their environments. PortalGuard IDaaS can be used as the central system for an organization’s connectivity, access, authentication and identity lifecycle management needs across all of its users, technology and applications. We enable our customers to easily deploy, manage and secure applications and devices, and offer provisioning services using open source tools.
Developers can leverage an extensive suite of API and modular SDK tools to build custom cloud, mobile and web application enrollment and authentication experiences that leverage BIO-key PortalGuard and WEB-key as the underlying identity management platform. Once deployed, PortalGuard allows administrators to enforce contextual access management decisions based on conditions such as user identity, device, geolocation, application destination identity, IP range, and time of day.
2
Table of Contents
Our customers use BIO-key to (i) manage and secure work-related IT access of their employees, contractors and supply chain partners, which we call workforce identity; and (ii) manage and secure the identities of users of their web properties, which we call customer identity.
BIO-key PortalGuard and PortalGuard IDaaS for Workforce Identity. PortalGuard streamlines the way an organization’s employees, contractors and supply chain partners connect to its applications and data from any device, while increasing user efficiency, preventing unauthorized delegation, credential sharing, and keeping digital environments secure through our MFA capabilities. We enable organizations to provide their workforces with immediate and secure access to every application from any device they use, without maintaining multiple credentials. Our multi-directory support interfaces with the directories in place at an organization, while allowing SQL-based custom directories where none presently exist. BIO-key PortalGuard Desktop allows customers to extend the BIO-key PortalGuard IDaaS to their existing on-premises and remote workstation Windows sign in.
BIO-key PortalGuard and PortalGuard IDaaS for Customer Identity. BIO-key PortalGuard allows organizations to secure access to their online properties, while upgrading their customers’ user experience by delivering self-enrollment and management for customer-facing cloud, mobile or web applications. We enable an organization’s product team to layer BIO-key’s MFA, SSO and self-service password reset, or SSPR, functionality into their cloud, web and mobile applications through federation standards or using our APIs. Our customers are able to centrally manage policies, audit and log access across their properties, leading to more seamless customer experiences.
BIO-key VST and WEB-key; Products; Civil and Large-Scale ID Infrastructure
We have developed what we believe is the most discriminating and effective commercially available finger-based biometric technology. This technology is embedded in our PortalGuard product for enterprise security, providing customers with a unique capability to authenticate users without a phone or token, where appropriate, such as manufacturing, retail, call centers, and health care workers. Other markets for scalable biometric engines include government markets, large scale identity projects such as voter’s registration, driver’s license, national ID programs, and SIM card registration.
We also offer a full line of easy to use finger scanners for both enterprise and consumer markets. Our PIV Pro, SidePass®, EcoID II® and SideSwipes® finger readers can be used on any laptop, tablet or other device which contains a USB A or C port. We market and sell these fingerprint scanners through distributors and directly to end users via Amazon.
AuthControl Sentry; AuthControl Enterprise; AuthControl MSP
Swivel Secure is the exclusive distributer of AuthControl Sentry, AuthControl Enterprise, and AuthControl MSP product line in Europe, Africa and the Middle East, or EMEA, excluding the United Kingdom and Ireland. These solutions include a patented one-time-code extraction technology, helping enterprises manage the increasing data security risks posed by cloud services and bring your own device policies.
Fingerprint Readers
Our series of compact fingerprint readers, we find commercial companies use SidePass®, SideSwipe® or EcoID II® to replace their Windows passwords and enable Windows Hello for Business without replacing or upgrading laptops or tablets.
Identity and Access Management, User Multi-Factor Authentication, Single Sign On, Privilege Entitlement and Access Control
Our products simplify the authentication process for enterprise users and consumers, while raising security levels. This allows our customers to meet new, stronger authentication requirements and security best practices across many industries, while delivering a superior end-user experience. Customers use our products to reduce risk of theft, fraud, loss, account takeover attacks, and unauthorized account sharing by limiting access to valuable assets, privileges, data, services, networks and places to only authorized individuals. Our products provide stronger identity binding and a superior user experience versus traditional credentialing systems, which utilize a physical or knowledge-based electronic credential to authenticate the holder but fail to authenticate the actual user in addition to the token. Both commercial enterprises and the public sector have seen a shift in the requirement for stronger authentication, and the FBI, NIST and industry thought leaders such as SalesForce and Microsoft have encouraged entities to enhance their security posture by implementing stronger 2-factor authentication (2FA) or MFA. We believe the market for advanced user MFA, including fingerprint biometrics, extends to nearly every industry segment and the market opportunity for our products is massive, global and growing.
Our Markets
Historically, our largest market has been identity and access management for highly regulated industries like government and healthcare. However, we are witnessing a change in the landscape as organizations within all industries and of all sizes are embracing biometric technology and MFA as a security and workflow solution. Millions of users have been successfully using biometrics in phones from Apple and Samsung and they welcome the same user experience to access applications without passwords or tokens.
Our acquisition of PistolStar added a large customer base in the state and local government and higher education (SLED) vertical. Colleges and universities throughout the United States use our PortalGuard MFA and SSO platform. As governments, colleges and universities continue to operate in remote environments, we have seen additional demand for our solutions.
3
Table of Contents
We believe there is potential for significant market growth in the following key areas:
● Enterprise MFA for access to computer networks, and applications.
● Government funded initiatives, including the state board of elections.
Business Model
Our business model is focused on the following key areas:
4
Table of Contents
We have grown our business through a combination of organic growth and the strategic acquisitions of PistolStar and Swivel Secure Europe. We expect to continue to pursue strategic acquisitions of select businesses and assets in the IAM space. In furtherance of this strategy, we are active in the industry and regularly evaluate businesses that we believe will either provide an entry into new market verticals or be synergistic with our existing operations and in either case, be accretive to earnings. We cannot provide any assurance as to whether we will be able to complete any acquisition and if completed, successfully integrate any business we acquire into our operations. Please see the section captioned “RISK FACTORS” for additional information regarding acquisition risks.
Marketing and Distribution
We sell our products directly through our field and inside sales teams, as well as indirectly through our network of channel partners. Through our Channel Alliance Program, we have partnered with more than 85 resellers, system integrators and other distribution partners. We are committed to continue to aggressively grow this program in 2024.
We partner with leading application, managed service and infrastructure vendors, such as Intelisys, Insight, NGEN, Amazon Web Services, Pathify (formerly UCROO Campus), Software House International (SHI), BlueAlly, Atlassian, and ProCirrus.
We offer our software under a SaaS term license and generate annual recurring revenue (ARR) primarily by selling multi-year subscriptions to our software. We employ a customer success team, focused on customer satisfaction and early remediation.
Intellectual Property Rights
We develop and own significant intellectual property and believe that our intellectual property is fundamental to our biometric and IAM product operation: We own patented technologies and trade secrets developed or acquired by us.
Patents
On December 26, 2006, we were issued US patent No. 7,155,040 covering our unique image processing technology, which is critical for enhancing information used in the extraction of biometric minutiae. The issued patent protects a critical part of an innovative four-phase image enhancement process developed by us. With the payment of all maintenance fees, this patent will expire on January 29, 2025.
On April 15, 2008, we were issued US patent No. 7,359,553 covering our image enhancement and data extraction core algorithm components. The solution protected under this patent provides the capability to quickly and accurately transform a fingerprint image into a computer image that can be analyzed to determine the critical data elements. With the payment of all maintenance fees, this patent will expire on January 3, 2025.
5
Table of Contents
On November 18, 2008, we were issued US patent No. 7,454,624 for our “Match Template Protection within a Biometric Security System” method. The solution protected under this patent limits the scope of enrollment templates usage and also eliminates the need for revocation or encryption processes, which can be expensive and time consuming. With the payment of all maintenance fees, this patent will expire on May 17, 2025.
On March 10, 2009, we were issued US patent No. 7,502,938 for our “Trusted Biometric Device” which covers a simple, yet secure method of protecting a user’s biometric information. It covers the transmission of information from the point the information is collected at the biometric reader until the data reaches the computer or device that is authenticating the user’s identity. With the payment of all maintenance fees, this patent will expire on October 25, 2025.
On November 8, 2011, we were issued US Patent No. 8,055,027 for our “Generation of Directional Information in the Context of Image Processing” method for image enhancement and processing. With the payment of all maintenance fees, this patent will expire on October 10, 2027.
On June 5, 2012, PistolStar was issued US Patent No. 8,196,193 for “Method For Retrofitting Password Enabled Computer Software with a Redirectional User Authentication Method”, where a device, method, and system may be used to integrate and control authentication and passwords among various applications and platforms. With the payment of all maintenance fees, this patent will expire on November 1, 2030.
On March 12, 2013, PistolStar was issued US Patent No. 8,397,077 for “Client Side Authentication Redirection”, where user specific attributes may be accessed and used to produce a generated password, using an algorithm and the user attributes. With the payment of all maintenance fees, this patent will expire on August 7, 2030.
On May 3, 2017, we were issued US Patent No. 9,646,146 for our “Utilization of Biometric Data”, a method enables existing small area sensors to capture substantially more fingerprint surface area, leading to a higher degree of accuracy when performing a match. With the payment of all maintenance fees, this patent will expire on March 6, 2035.
On June 19, 2018, we were issued U.S. Patent No. 10,002,244 for our “Utilization of Biometric Data” to allow continuous, passive user authentication on a mobile device. With the payment of all maintenance fees, this patent will expire on March 6, 2035.
On July 27, 2018, we were issued U.S. Patent No. 10,025,831 for “Adaptive Short Lists and Acceleration of Biometric Database Search”, a method to quickly and iteratively search a database of biometric data. With the payment of all maintenance fees, this patent will expire on August 10, 2036.
On September 3, 2019, we were issued U.S. Patent No. 10,400,481 for “Fingerprint Lock”, a lock design method of the shackle and spring integration to electronics. With the payment of all maintenance fees, this patent will expire on June 27, 2037.
On September 10, 2019, we were issued U.S Patent No. 10,410,040 for “Fingerprint Lock Control method and Fingerprint Lock System”, a lock design method of the control process of scanning, and server communications for user profile management. With the payment of all maintenance fees, this patent will expire on July 26, 2037.
On April 20, 2021, we were issued U.S. Patent No. 10,984,085 for “Biometric Recognition for Uncontrolled Acquisition Environments”, expected to be deployed in mobile devices, the patent provides a method of continuous capture of the users biometric data before the need of the authentication or enrollment, as well as during an active session with a user, to assure the user has not changed. With the payment of all maintenance fees, this patent will expire on March 13, 2039.
We have also been granted parallel patents to the US Patent portfolio to certain of our patents in many foreign countries offering protection of our intellectual property rights around the world.
Trademarks
We have registered our trademarks “BIO-key”, “True User Identification”, “Intelligent Image Indexing”, “WEB-key”, “SideSwipe”, “SidePass”, “EcoID”, “PistolStar®”, “PortalGuard”, “MobileAuth”, “PASSIVEKEY®” and “PISTOLSTAR®” with the U.S. Patent & Trademark Office, as well as many foreign countries, protecting the names of our companies and our key technology offerings.
6
Table of Contents
We also own the following unregistered trademarks: “PortalGuard NebulaTM”, “Password PowerTM” and “ScoochTM”.
Copyrights and trade secrets
We take measures to ensure copyright and license protection for our software releases prior to distribution. When possible, the software is licensed in an attempt to ensure that only licensed and activated software functions to its full potential. We also take measures to protect the confidentiality of our trade secrets.
Research and Development
Our PortalGuard IAM product line is mature, with hundreds of active customers, and we are adding additional factors and capabilities to the product, as well as enhancing the self-management for the functionally equivalent PortalGuard IDaaS offering. A significant new authentication factor set will come via our MobileAuth application for users to experience multiple biometric secure authentication via their mobile phone devices. Our VST and WEB-key biometric platforms are mature, stable, and widely-deployed. We concentrate our research and development efforts on enhancing the functionality, reliability and integration of our current products as well as acquiring and developing new and innovative products and solutions for providing broader access to the BIO-key user experience.
Although we believe that our identification technology is one of the most advanced and discriminating fingerprint technologies available today, the markets in which we compete are characterized by rapid technological change and evolving standards and use-cases. In order to maintain our position in the market, we will need to continue to upgrade and refine our existing technologies as new standards become relevant to our customers and markets.
During the years ended December 31, 2023 and 2022, we incurred expenses of $2,394,926 and $3,252,236, respectively, for research and development.
In future periods our R&D efforts will remain focused on updating and advancing our core software products including PortalGuard and PortalGuard IDaaS, MobileAuth, WEB-key and VST. These products are critical to support the anticipated growth in enterprise IAM.
Competition
The IAM, MFA and SSO market is characterized by multiple solution providers of solutions in either standalone or IAM suite delivery models. We believe that our unique differentiator in this market is the incorporation of an unparalleled server-secured biometric authentication capability among our seventeen authentication factors. There are numerous companies involved in the development, manufacturing and marketing of fingerprint biometrics products to commercial, government, law enforcement and prison markets. These companies include, but are not limited to, IDEMIA, Thales, NEC, Neurotechnology, and Innovatrics.
The majority of sales for automated fingerprint identification products in the market to date have been deployed for government agencies, healthcare facilities, and law enforcement applications. The consumer and commercial markets represent areas of growth potential for biometrics, led by the use of mobile devices.
The epidemic of security and data breaches reported over the past few years is one of the driving factors for identifying new methods of protecting valuable data. After attempting to create a more sophisticated password, or more efficient token or PIN, it has become apparent that each of these methods are easily compromised, and the downside risks are significant.
We have also seen FIDO-compliant keys enter the market, led by Yubico’s YubiKey, a hardware token device that acts as a credential for access. FIDO officially recommends enterprises purchase two or more keys for every user, to prevent lockout in the event of a lost or misplaced FIDO token. These hardware tokens alone do not meet the needs of large organizations for which key sharing and lost keys are concerns, establishing the opportunity for our Identity Bound Biometric differentiation. Where FIDO is needed, we offer a line of equivalent function and quality, but lower-cost FIDO 2.0 keys.
With respect to competing biometrics technologies, each has its strengths and weaknesses and none has emerged as a market leader:
7
Table of Contents
Government Regulations
Various state, federal and EU privacy laws govern the collection, storage, use and any sale of biometric-related data. To the extent that BIO-key’s IDaaS offerings include the collection and storage of customer users’ personal or biometric data, we operate as a processor of such data. Our WEB-key platform includes compliance features to ensure automated compliance with these laws including collection of informed written consent during enrollment workflows and robust auditing to control and report on the retention of biometric data and removal requests. Additionally, our customers have access to these tools to maintain their own compliance, including deletion of user data when business relationships terminate.
We believe in biometric privacy rights, and that both users and their organizations benefit from a responsibly operated biometric identity infrastructure. We actively participate in industry privacy workgroups as recognized biometric subject matter experts in order to influence and keep abreast of any proposed changes to these regulations. Beyond these regulations, we are not currently subject to direct regulation by any government agency, other than regulations generally applicable to businesses or related to specific project requirements. In the event of any international sales, we would be subject to various domestic and foreign laws regulating such exports and export activities.
Environmental Regulations
As of the date of this report, we have not incurred any material expenses relating to our compliance with federal, state, or local environmental laws and do not expect to incur any material expenses in the foreseeable future.
Seasonality
Generally, our revenues do not exhibit a seasonal pattern, however, revenue is affected by customer budgeting, government fiscal year planning, and capital budgets.
Human Capital Resources
As of the date of this report, we have forty-two employees consisting of forty-three individuals on a full-time basis and one part-time employee as follows: (i) nineteen in engineering, customer support, and research and development; (ii) ten in finance and administration; and (iii) thirteen in sales and marketing. We also have two factory contractors in China. None of our employees are represented by a labor union and we believe that our relationship with our employees is good.
8
Table of Contents
ITEM 1A. RISK FACTORS
Set forth below are the risks that we believe are material to our investors. This section contains forward-looking statements. You should refer to the explanation of the qualifications and limitations on forward-looking statements appearing just before the section captioned “BUSINESS” in Item 1 above.
BUSINESS AND FINANCIAL RISKS
The restatement of our previously issued financial statements has been time-consuming and expensive and could expose us to additional risks that could materially adversely affect our financial position, results of operations and cash flows.
As discussed in the Explanatory Note to this Annual Report and in Note U, Quarterly Financial Data (Unaudited and Restated), to the consolidated financial statements included in this Annual Report, we are restating our previously issued financial statements for our unaudited consolidated financial statements covering the quarterly reporting periods during fiscal year 2023, consisting of the quarters ended March 31, 2023, June 30, 2023 and September 30, 2023 (the "Restatement Periods"). These restatements, and the remediation efforts we have undertaken and are continuing to undertake, have been time-consuming and expensive and could expose us to a number of additional risks that could materially adversely affect our financial position, results of operations and cash flows. To the extent these steps are not successful, we could be forced to incur additional time and expense. Our management’s attention has also been diverted from the operation of our business in connection with the restatements and ongoing remediation of material weaknesses in our internal controls.
We identified a material weakness in our internal control over financial reporting related to the recording and processing of revenue transactions. Such material weaknesses could materially and adversely affect our operations, financial condition, reputation and stock price.
As discussed in Note U of our consolidated financial statements, Management has concluded that the Company’s previously issued consolidated financial statements should be restated due to inadvertently including certain revenue from our European subsidiary, Swivel Secure Europe, Ltd., in the first quarter of 2023. In addition, certain allowances for accounts receivable and certain reserves for inventory were understated. Therefore, the Company misstated gross revenues, accounts receivable, and inventory during the Restatement Periods. The restatement related to the Company’s material weakness in internal control over financial reporting over the recording of revenue, accounts receivable, and inventory transactions. A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of a company’s annual or interim financial statements will not be prevented or detected on a timely basis. We completed the restatement and are now evaluating and working towards the appropriate corrective actions to remediate the material weakness to strengthen our internal controls over the recording of revenue transactions.
It is possible that we may discover significant deficiencies or material weaknesses in our internal control over financial reporting in the future. For example, internal control over financial reporting may not achieve their intended objectives. Control processes that involve human diligence and compliance, such as our disclosure controls and procedures and internal control over financial reporting, are subject to lapses in judgment and breakdowns resulting from human failures. Controls can also be circumvented by collusion or improper management-override of such controls. Because of such limitations, there are risks that material misstatements due to error or fraud may not be prevented or detected, and that information may not be reported on a timely basis.
Based on our limited cash resources, history of significant losses, and negative cash flow, our independent registered public accounting firm has included an explanatory paragraph in their opinion as to the substantial doubt about our ability to continue as a going concern.
Due to, among other factors, our history of significant losses, limited cash resources, and negative cash flow, our independent registered public accounting firm has included an explanatory paragraph in their opinion for the year ended December 31, 2023 as to the substantial doubt about our ability to continue as a going concern. Our financial statements have been prepared in accordance with accounting principles generally accepted in the United States, which contemplate that we will continue to operate as a going concern. Our financial statements do not contain any adjustments that might result if we are unable to continue as a going concern.
We have historically not generated significant revenue and have sustained substantial operating losses.
In order to increase revenue, we have developed a direct sales force and anticipate the need to retain additional sales, marketing and technical support personnel and may need to incur substantial expenses. We cannot assure you that we will be able to secure these necessary resources, that a significant market for our technologies will develop, or that we will be able to achieve our targeted revenue. If we are unable to achieve revenue or raise capital sufficient to cover our ongoing operating expenses, we will be required to scale back operations, including marketing and research initiatives, or in the extreme case, discontinue operations.
9
Table of Contents
We may need to obtain additional financing to execute our business plan over the long-term, which may not be available. If we are unable to raise additional capital or generate significant revenue, we may not be able to continue operations.
We have historically financed our operations through access to the capital markets by issuing secured and convertible debt securities, convertible preferred stock, common stock, and through factoring receivables. We currently require approximately $732,000 per month to conduct our operations, a monthly amount that we have been unable to consistently achieve through revenue generation. During 2023, we generated approximately $9.0 million of revenue, which is below our average monthly requirements. If we are unable to generate sufficient revenue to cover operating expenses and fund our business plan, we will need to obtain additional third-party financing. We may, therefore, need to obtain additional financing through the issuance of debt or equity securities. We cannot assure you that we will be able to secure any such additional financing on terms acceptable to us or at all. If we cannot obtain such financing, we will not be able to execute our business plan, will be required to reduce operating expenses, and in the extreme case, discontinue operations.
The delayed filing of this annual report has made us currently ineligible to use a registration statement on Form S-3 to register the offer and sale of securities, which could adversely affect our ability to raise future capital.
As a result of the delayed filing of this annual report with the SEC, we will not be eligible to register the offer and sale of our securities using a registration statement on Form S-3 until one year from the date we regain and maintain status as a current filer. Should we wish to register the offer and sale of our securities to the public prior to the time we are eligible to use Form S-3, both our transaction costs and the amount of time required to complete the transaction could increase, making it more difficult to execute any such transaction successfully and potentially harming our financial condition.
Our biometric technology has yet to gain widespread market acceptance and we do not know how large of a market will develop for our technology.
Biometric technology has received only limited market acceptance, particularly in the private sector. Our technology represents a novel security solution and we have not yet generated significant sales. Although recent security concerns relating to identification of individuals and appearance of biometric readers on popular consumer products, including the Apple iPhone, have increased interest in biometrics generally, it remains an undeveloped, evolving market. Biometric based solutions compete with more traditional security methods including keys, cards, personal identification numbers and security personnel. Acceptance of biometrics as an alternative to such traditional methods depends upon a number of factors including:
● the performance and reliability of biometric solutions;
● marketing efforts and publicity regarding these solutions;
● public perception regarding privacy concerns;
● costs involved in adopting and integrating biometric solutions;
● proposed or enacted legislation related to privacy of information; and
For these reasons, we are uncertain whether our biometric technology will gain widespread acceptance in any commercial markets or that demand will be sufficient to create a market large enough to produce significant revenue or earnings. Our future success depends, in part, upon business customers adopting biometrics generally, and our solution specifically.
Biometric technology is a relatively new approach to Internet security, which must be accepted in order for our WEB-key solution to generate significant revenue.
Our WEB-key authentication initiative represents a relatively new approach to Internet security, which has been adopted on a limited basis by companies that distribute goods, content or software applications over the Internet. The implementation of our WEB-key solution requires the distribution and use of a finger scanning device and integration of database and server side software. Although we believe our solutions provide a higher level of security for information transmitted over the Internet than existing traditional methods, unless business and consumer markets embrace the use of a scanning device and believe the benefits of increased accuracy outweigh implementation costs, our solution will not gain market acceptance.
10
Table of Contents
The market for our solutions is still developing and if the biometrics industry adopts standards or a platform different from our standards or platform, our competitive position would be negatively affected.
The market for identity solutions is still developing. The evolution of this market may result in the development of different technologies and industry standards that are not compatible with our current solutions, products or technologies. Several organizations set standards for biometrics to be used in identification and documentation. Although we believe that our biometric technologies comply with existing standards, these standards may change and any standards adopted could prove disadvantageous to or incompatible with our business model and current or future solutions, products and services.
Our software products maycontain defects which will make it more difficult for us to establish and maintain customers.
Although we have completed the development of our core biometric technology, it has only been used by a limited number of business customers. Despite extensive testing during development, our software may contain undetected design faults and software errors, or “bugs” that are discovered only after it has been installed and used by a greater number of customers. Any such defect or error in new or existing software or applications could cause delays in delivering our technology or require design modifications. These could adversely affect our competitive position and cause us to lose potential customers or opportunities. Since our technologies are intended to be utilized to secure physical and electronic access, the effect of any such bugs or delays will likely have a detrimental impact on us. In addition, given that biometric technology generally, and our biometric technology specifically, has yet to gain widespread acceptance in the market, any delays would likely have a more detrimental impact on our business than if we were a more established company.
In order to generate revenue from our biometric products, we are dependent upon independent original equipment manufacturers, system integrators and application developers, which we do not control. As a result, it maybe more difficult to generate sales.
We market our technology through licensing arrangements with:
As a technology licensing company, our success will depend upon the ability of these manufacturers and developers to effectively integrate our technology into products and services which they market and sell. We have no control over these licensees and cannot assure you that they have the financial, marketing or technical resources to successfully develop and distribute products or applications acceptable to end users or generate any meaningful revenue for us. These third parties may also offer the products of our competitors to end users. While we have commenced a significant sales and marketing effort, we have only begun to develop a significant distribution channel and may not have the resources or ability to sustain these efforts or generate any meaningful sales.
We face intense competition and maynot have the financial and human resources necessary to keep up with rapid technological changes, which mayresult in our technology becoming obsolete.
The Internet, facility access control, and information security markets are subject to rapid technological change and intense competition. We compete with both established biometric companies and a significant number of startup enterprises as well as providers of more traditional methods of access control. Most of our competitors have substantially greater financial and marketing resources than we do and may independently develop superior technologies, which may result in our technology becoming less competitive or obsolete. We may not be able to keep pace with this change. If we are unable to develop new applications or enhance our existing technology in a timely manner in response to technological changes, we will be unable to compete in our chosen markets. In addition, if one or more other biometric technologies such as voice, face, iris, hand geometry or blood vessel recognition are widely adopted, it would significantly reduce the potential market for our fingerprint identification technology.
We recognized revenues from Africa and the European Union in 2022 and 2023 and expect continued revenues from these regions in future periods. Our financial performance will be subject to risks associated with changes in the value of the U.S. dollar versus local currencies.
Owing to the international scope of our operations, including our recent acquisition of Swivel Secure Europe, SA, we are exposed to foreign exchange risk. Our primary exposure to movements in foreign currency exchange rates relates to non-U.S. dollar-denominated sales and operating expenses worldwide. Weakening of foreign currencies relative to the U.S. dollar will adversely affect the U.S. dollar value of our foreign currency-denominated sales and earnings, if any, and could lead to us raising international pricing, potentially reducing the demand for our products. In addition, margins on sales of our products in foreign countries and on sales of products that include components obtained from foreign suppliers could be materially adversely affected by foreign currency exchange rate fluctuations. As a result, our business and the price of our common stock may be affected by fluctuations in foreign exchange rates, which may have a significant impact on our results of operations and cash flows from period to period. Currently, we do not have any exchange rate hedging arrangements in place.
11
Table of Contents
Although we have made significant sales of our products throughout Asia and Africa in prior years, we have not been able to consistently enforce our contract rights and collect all receivables which has resulted in material write-offs.
Our ability to enforce our international contracts is contingent on our relationships with foreign resellers, and their financial viability. Although we are making efforts to better enforce our contract rights, there can be no assurance that we will be able to fully collect all receivables originating in Asia and Africa or that will not have to write-off future receivables which may be material in amount. Any such write-offs have negatively impacted our financial position and results of operation.
We depend on key employees and members of our management team, including our Chairman of the Board and Chief Executive Officer, Chief Financial Officer, and our Chief Legal Officer, in order to achieve our goals. We cannot assure you that we will be able to retain or attract such persons.
Our employment contracts with Michael W. DePasquale, our Chairman of the Board and Chief Executive Officer, Cecilia C. Welch, our Chief Financial Officer, and James D. Sullivan, our Chief Legal Officer, expire annually, and renew automatically for successive one-year periods unless notice of non-renewal is provided by the Company. Although the contracts do not prevent them from resigning, they do contain confidentiality and non-compete clauses, which are intended to prevent them from working for a competitor within one year after leaving our Company. Our success depends on our ability to attract, train and retain employees with expertise in developing, marketing and selling software solutions. In order to successfully market our technology, we will need to retain additional engineering, technical support and marketing personnel. The market for such persons remains highly competitive and our limited financial resources will make it more difficult for us to recruit and retain qualified persons.
We cannot assure you that the intellectual property protection for our core technology provides a sustainable competitive advantage or barrier to entry against our competitors.
Our success and ability to compete is dependent in part upon proprietary rights to our technology. We rely primarily on a combination of patent, copyright and trademark laws, trade secrets and technical measures to protect our propriety rights. We have filed a patent application relating to both the optic technology and biometrics solution components of our technology wherein several claims have been allowed. The U.S. Patent and Trademark Office has issued us a series of patents for our Vector Segment fingerprint technology (VST), and our other core biometric analysis and identification technologies. However, we cannot assure you that we will be able to adequately protect our technology or other intellectual property from misappropriation in the U.S. and abroad. Any patent issued to us could be challenged, invalidated or circumvented or rights granted thereunder may not provide a competitive advantage to us. Furthermore, patent applications that we file may not result in issuance of a patent or, if a patent is issued, the patent may not be issued in a form that is advantageous to us. Despite our efforts to protect our intellectual property rights, others may independently develop similar products, duplicate our products or design around our patents and other rights. In addition, it is difficult to monitor compliance with, and enforce, our intellectual property rights on a worldwide basis in a cost-effective manner. In jurisdictions where foreign laws provide less intellectual property protection than afforded in the U.S. and abroad, our technology or other intellectual property may be compromised, and our business would be materially adversely affected. If any of our proprietary rights are misappropriated or we are forced to defend our intellectual property rights, we will have to incur substantial costs. Such litigation could result in substantial costs and diversion of our resources, including diverting the time and effort of our senior management, and could disrupt our business, as well as have a material adverse effect on our business, prospects, financial condition and results of operations. We can provide no assurance that we will have the financial resources to oppose any actual or threatened infringement by any third party. Furthermore, any patent or copyrights that we may be granted may be held by a court to infringe on the intellectual property rights of others and subject us to the payment of damage awards.
We may be subject to claims with respect to the infringement of intellectual property rights of others, which could result in substantial costs and diversion of our financial and management resources.
Third parties may claim that we are infringing on their intellectual property rights. We may violate the rights of others without our knowledge. We may expose ourselves to additional liability if we agree to indemnify our customers against third party infringement claims. While we know of no basis for any claims of this type, the existence of and ownership of intellectual property can be difficult to verify, and we have not made an exhaustive search of all patent filings. Additionally, most patent applications are kept confidential for twelve to eighteen months, or longer, and we would not be aware of potentially conflicting claims that they make. We may become subject to legal proceedings and claims from time to time relating to the intellectual property of others in the ordinary course of our business. If we are found to have violated the intellectual property rights of others, we may be enjoined from using such intellectual property, and we may incur licensing fees or be forced to develop alternative technology or obtain other licenses. In addition, we may incur substantial expenses in defending against these third party infringement claims and be diverted from devoting time to our business and operational issues, regardless of the merits of any such claim.
12
Table of Contents
In addition, in the event that we recruit employees from other technology companies, including certain potential competitors, and these employees are engaged in the development of portions of products which are similar to the development in which they were involved at their former employers, we may become subject to claims that such employees have improperly used or disclosed trade secrets or other proprietary information. If any such claims were to arise in the future, litigation or other dispute resolution procedures might be necessary to retain our ability to offer our current and future services, which could result in substantial costs and diversion of our financial and management resources. Successful infringement or licensing claims against us may result in substantial monetary damages, which may materially disrupt the conduct of our business and have a material adverse effect on our reputation, business, financial condition and results of operations. Even if intellectual property claims brought against us are without merit, they could result in costly and time consuming litigation, and may divert our management and key personnel from operating our business.
If we are unable to effectively protect our intellectual property rights on a worldwide basis, we may not be successful in the international expansion of our business.
Access to worldwide markets depends in part on the strength of our intellectual property portfolio. There can be no assurance that, as our business expands into new areas, we will be able to independently develop the technology, software or know-how necessary to conduct our business or that we can do so without infringing the intellectual property rights of others. To the extent that we have to rely on licensed technology from others, there can be no assurance that we will be able to obtain licenses at all or on terms we consider reasonable. The lack of a necessary license could expose us to claims for damages and/or injunction from third parties, as well as claims for indemnification by our customers in instances where we have a contractual or other legal obligation to indemnify them against damages resulting from infringement claims. With regard to our own intellectual property, we actively enforce and protect our rights. However, there can be no assurance that our efforts will be adequate to prevent the misappropriation or improper use of our protected technology in international markets.
We maynot achieve profitability if we are unable to maintain, improve our offerings.
We believe that our future business prospects depend in part on our ability to maintain and improve our current services and to develop new ones on a timely basis. Our services will have to achieve market acceptance, maintain technological competitiveness, and meet an expanding range of customer requirements. We may experience difficulties that could delay or prevent the successful development, introduction or marketing of new services and service enhancements. Additionally, our new services and service enhancements may not achieve market acceptance. If we cannot effectively develop and improve services, we may not be able to recover our fixed costs or otherwise become profitable.
If we fail to adequately manage our resources, it could have a severe negative impact on our financial results or stock price.
We could be subject to fluctuations in technology spending by existing and potential customers. Accordingly, we will have to actively manage expenses in a rapidly changing economic environment. This could require reducing costs during economic downturns and selectively growing in periods of economic expansion. If we do not properly manage our resources in response to these conditions, our results of operations could be negatively impacted.
We are subject to risks and uncertainties associated with the continued growth of our international operations, which may harm our business.
We have international operations and continue to expand our international operations when we acquired Swivel Secure Europe SA. Accordingly, our business is subject to risks and uncertainties associated with doing business outside of the United States and could be adversely affected by a variety of factors, including:
● additional potentially relevant third-party patent rights;
● difficulties in staffing and managing foreign operations;
Any of these factors could significantly harm our business, operating results, financial condition or prospects.
13
Table of Contents
Our business could be negatively impacted by security threats, including cybersecurity threats, ransomware, and other disruptions.
Our customers use our solutions to access their business systems and store data related to their employees, contractors, partners and customers. Our systems’ integrity is essential to their use of our platform, which stores, transmits and processes customers’ proprietary information and users’ personal data. If the confidentiality, integrity or availability of our customers’ data or systems is disrupted, we could incur significant liability to our customers and to individuals or businesses whose information was being stored by our customers, and our platform may be perceived as less desirable, which could negatively affect our business and damage our reputation. We, our third-party service providers, and our customers may be unable to anticipate these techniques or to implement adequate preventive measures. Further, because we do not control our third-party service providers, or the processing of data by our third-party service providers, we cannot ensure the integrity or security of measures they take to protect customer information and prevent data loss beyond evaluating and relying on their representations as to their security methods and posture. Although we utilize various procedures and controls to monitor these threats and mitigate our exposure to such threats, there can be no assurance that these procedures and controls will be sufficient in preventing security threats from materializing. If any of these events were to materialize, they could lead to losses of sensitive information, critical infrastructure, personnel or capabilities, essential to our operations and could have a material adverse effect on our reputation, financial position, results of operations, or cash flows. As a technology company, we face various security threats, including cybersecurity threats to gain unauthorized access to sensitive information. on an ongoing basis.
In addition to threats from traditional computer “hackers,” malicious code (such as malware, viruses, worms and ransomware), employee or contractor theft or misuse, password spraying, phishing and denial-of-service attacks, we and our third-party service providers now also face threats from sophisticated nation-state and nation-state-supported actors who engage in attacks (including advanced persistent threat intrusions) that add to the risks to our systems (including those hosted on AWS’ systems), internal networks, our customers’ systems and the information that they store and process. Cybersecurity attacks in particular are evolving, we expect that they will continue, and we expect the scope and sophistication of these efforts may increase in future periods. As a result, we and our third-party service providers may be unable to anticipate these techniques or implement adequate preventative measures quickly enough to prevent either an electronic intrusion into our systems or services or a compromise of customer data, employee data or other protected information.
Although we have implemented systems and procedures that are designed to protect customer, employee, vendor and Company information, prevent data loss and other security breaches, and otherwise identify, assess, and analyze cybersecurity risks, these measures may not function as expected or may not be sufficient to protect our internal networks and platform against certain attacks. Development and maintenance of these systems is costly and requires ongoing monitoring and updating as technologies change and efforts to overcome security measures increase and become more sophisticated. We face an evolving threat landscape in which cybercriminals, among others, employ a complex array of techniques designed to access personal data and other information, including, for example, the use of fraudulent or stolen access credentials, malware, ransomware, phishing, denial of service and other types of attacks. While, to the best of our knowledge, we have not experienced any material misappropriation, loss or other unauthorized disclosure of confidential or personally identifiable information as a result of a security breach or cyberattack that could materially increase financial risk to the Company or our customers, such a security breach or cyberattack could adversely affect our business and operations, including by damaging our reputation and our relationships with our customers, employees and investors, exposing us to litigation, fines, penalties or remediation costs.
We maintain cybersecurity insurance, but our insurance may be insufficient to cover all liabilities incurred in any such incident, and any incident may result in loss of, or increased costs of, that cybersecurity insurance. Any breach, or any perceived breach, of our systems, our customers’ systems, or other systems or networks secured by our products, without regard to whether any breach is due to a vulnerability in our platform, may also undermine confidence in our platform or the identity as a service industry and could result in damage to our reputation and brand, negative publicity, loss of partners, customers and sales, increased costs to correct any problem, costly litigation and other liabilities. In addition, a breach of the security measures of one of our partners could result in the disclosure of confidential information or other data that may provide additional avenues of attack, and if a high profile security breach occurs with respect to a comparable cloud technology provider, our customers and potential customers may lose trust in the security of the cloud business model generally, which could adversely impact our ability to retain existing customers or attract new ones. Any of these negative outcomes could adversely impact market acceptance of our products and could harm our business, results of operations, and financial condition.
Our failure to comply with applicable privacy, data protection and information security laws or related contractual obligations could subject us to significant liability and negatively impact our financial position and results of operation.
There are numerous laws and regulations in various jurisdictions regarding privacy, data protection, information security, and the storing, sharing, use, processing, transfer, disclosure and protection of personal data. In light of the increasing pace of new technology development, including with respect to biometric data, the scope of these data protection and privacy-related laws and regulations are expanding, subject to differing interpretations, and may be inconsistent among jurisdictions, or conflict with other rules that we are subject to. These evolving laws and regulations may result in increasing regulatory and public scrutiny and escalating levels of enforcement and sanctions. We are also subject to the terms of our privacy policies and contractual obligations to third parties related to privacy, data protection and information security.
Any failure or perceived failure by us to comply with our privacy policies, our privacy-related obligations to customers or other third parties, or applicable laws or regulations relating to privacy, data protection, or information security may result in governmental investigations or enforcement actions, litigation, claims or public statements against us by consumer advocacy groups or others, and could result in significant liability or cause our customers to lose trust in us, which could cause them to cease or reduce use of our products and services and otherwise have an adverse effect on our reputation and business. Any similar failure or perceived failure by users of our products or services may also have an adverse effect on our reputation and business. In addition, legal, regulatory, contractual and other obligations as well as public concerns relating to privacy, data protection or information security could restrict our ability to store and process data as part of our solutions or otherwise impact our ability to provide our solutions in certain jurisdictions and may result in the loss of business opportunities from customers operating in, or seeking to expand into, those jurisdictions. Additionally, in 2023, the SEC adopted new rules related to cybersecurity risk management, which may further increase our regulatory burden and the cost of compliance in such events.
14
Table of Contents
Our failure to maintain appropriate environmental, social, and governance ("ESG") practices and disclosures could result in reputational harm, a loss of customer and investor confidence, and adverse business and financial results.
There is an increasing focus from certain investors, employees, customers and other stakeholders concerning corporate responsibility, specifically related to environmental, social and governance matters (“ESG”). Some investors may use these non-financial performance factors to guide their investment strategies and, in some cases, may choose not to invest in us if they believe our policies and actions relating to corporate responsibility are inadequate. The growing investor demand for measurement of non-financial performance is addressed by third-party providers of sustainability assessment and ratings on companies. The criteria by which our corporate responsibility practices are assessed may change due to the constant evolution of the sustainability landscape, which could result in greater expectations of us and cause us to undertake costly initiatives to satisfy such new criteria. If we elect not to or are unable to satisfy such new criteria, investors may conclude that our policies and/or actions with respect to corporate social responsibility are inadequate. We may face reputational damage in the event that we do not meet the ESG standards set by various constituencies.
Furthermore, if our competitors’ corporate social responsibility performance is perceived to be better than ours, potential or current investors may elect to invest with our competitors instead. In addition, in the event that we communicate certain initiatives and goals regarding environmental, social and governance matters, we could fail, or be perceived to fail, in our achievement of such initiatives or goals, or we could be criticized for the scope of such initiatives or goals. If we fail to satisfy the expectations of investors, employees and other stakeholders or our initiatives are not executed as planned, our reputation and business, operating results and financial condition could be adversely impacted.
New climate disclosure rules adopted by the SEC, may increase our costs and litigation risks, which could materially and adversely affect our future results of operations and financial condition.
In March 2024, the SEC adopted new climate disclosure rules, which require new disclosure in certain SEC filings about material climate-related risks, activities to mitigate or adapt to such risks, board oversight of climate-related risks and management’s role in managing material climate-related risks, and climate-related targets and goals. The new climate disclosure rules have been the subject of multiple legal challenges, so the extent to which the new rules will go into effect remains uncertain. We are currently assessing the impact of the new rules, but at this time, we cannot predict the costs of implementation or any potential adverse impacts resulting from the new rules. However, we may incur increased costs relating to the assessment and disclosure of climate-related risks and increased litigation risks related to disclosures made pursuant to the new rules, either of which could materially and adversely affect our future results of operations and financial condition.
The war in Ukraine and the international community’s response have created substantial political and economic disruption, uncertainty, and risk.
Russia’s military intervention in Ukraine in late February 2022, Ukraine’s widespread resistance, and the NATO led and United States coordinated economic, financial, communications, and other sanctions imposed by other countries have created significant political and economic world uncertainty. There is significant risk of expanded military confrontation between Russia and other countries. It is not possible to predict the broader consequences of the conflict, including related geopolitical tensions, and the measures and retaliatory actions taken by the U.S. and other countries in respect thereof, as well as any counter measures or retaliatory actions by Russia in response. At a minimum, the continuing conflict is likely to cause regional instability, geopolitical shifts and could materially adversely affect global trade, currency exchange rates, regional economies and the global economy, which could materially adversely affect our financial condition or results of operations. Current and likely additional international sanctions against Russia may contribute to higher costs, particularly for petroleum-based products. These and related actions, responses, and consequences that cannot now be predicted or controlled may contribute to world-wide economic reversals.
There is a scarcity of and competition for acquisition opportunities.
There are a limited number of operating companies available for acquisition that we deem to be desirable targets. In addition, there is a very high level of competition among companies seeking to acquire these operating companies. Many established and well-financed entities are active in acquiring interests in companies that we may find to be desirable acquisition candidates. Many of these entities have significantly greater financial resources, technical expertise and managerial capabilities than us. Consequently, we will be at a competitive disadvantage in negotiating and executing possible acquisitions of these businesses. Even if we are able to successfully compete with these entities, this competition may affect the terms of completed transactions and, as a result, we may pay more or receive less favorable terms than we expected for potential acquisitions. We may not be able to identify operating companies that complement our strategy, and even if we identify a company that complements our strategy, we may be unable to complete an acquisition of such a company for many reasons, including:
● competition from other acquirers of operating companies;
● lack of sufficient capital to acquire a profitable company; and
● unwillingness of a potential acquiree to work with our management.
15
Table of Contents
Risks related to acquisition financing.
We have limited financial resources and our ability to make additional acquisitions without securing additional financing from outside sources is also limited. In order to continue to pursue our acquisition strategy, we may be required to obtain additional financing. We may obtain such financing through a combination of debt financing or the placement of debt and equity securities. We may finance some portion of our future acquisitions by either issuing equity or by using shares of our common stock for all or a portion of the purchase price for such businesses. In the event that our common stock does not attain or maintain a sufficient market value, or potential acquisition candidates are otherwise unwilling to accept our common stock as part of the purchase price for the sale of their businesses, we may be required to use more of our cash resources, if available, in order to maintain our acquisition program. If we do not have sufficient cash resources, we will not be able to complete acquisitions and our growth could be limited unless we are able to obtain additional capital through debt or equity financings.
We may experience difficulties in integrating the operations, personnel and assets of any business we acquire which may disrupt our business, dilute stockholder value, and adversely affect our operating results.
A component of our business plan is to acquire businesses and assets in the biometric and identity access management industry. There can be no assurance that we will be able to identify, acquire or profitably manage businesses or successfully integrate acquired businesses into the Company without substantial costs, delays or other operational or financial problems. Such acquisitions also involve numerous operational risks, including:
● difficulties in integrating operations, technologies, services and personnel;
● the diversion of financial and management resources from existing operations;
● the risk of entering new markets;
● difficulties in retaining the existing customers;
As a result, if we fail to properly evaluate and execute any acquisitions or investments, our business and prospects may be seriously harmed.
To the extent we make any material acquisitions, our earningsmaybe adversely affected by non-cash charges relating to the amortization of intangible assets.
Under applicable accounting standards, purchasers are required to allocate the total consideration paid in a business combination to the identified acquired assets and liabilities based on their fair values at the time of acquisition. The excess of the consideration paid to acquire a business over the fair value of the identifiable tangible assets acquired must be allocated among identifiable intangible assets including goodwill. The amount allocated to goodwill is not subject to amortization. However, it is tested at least annually for impairment. The amount allocated to identifiable intangible assets, such as customer relationships and the like, is amortized over the life of these intangible assets. We expect that this will subject us to periodic charges against our earnings to the extent of the amortization incurred for that period. Because our business strategy focuses, in part, on growth through acquisitions, our future earnings may be subject to greater non-cash amortization charges than a company whose earnings are derived solely from organic growth. As a result, we may experience an increase in non-cash charges related to the amortization of intangible assets acquired in our acquisitions. Our financial statements will show that our intangible assets are diminishing in value, even if the acquired businesses are increasing (or not diminishing) in value.
RISKS RELATED TO OUR COMMON STOCK
We have issued a substantial number of warrants exercisable into shares of our common stock which could result in substantial dilution to the ownership interests of our existing stockholders.
As of the date of this report, approximately 1,814,000 shares of our common stock (as adjusted to reflect our 1-for-18 reverse stock split, which was effective December 21, 2023) were reserved for issuance upon exercise or conversion of outstanding stock options and warrants. The exercise or conversion of these securities will result in a significant increase in the number of outstanding shares and substantially dilute the ownership interests of our existing stockholders.
16
Table of Contents
An active trading market for our common stock may not be sustained.
Although our common stock is listed on the Nasdaq Capital Market, an active trading market for our shares may not be developed and if developed, sustained. If an active market for our common stock is not developed or sustained, it may be difficult for you to sell your shares without depressing the market price for the shares or sell your shares at all. Any inactive trading market for our common stock may also impair our ability to raise capital to continue to fund our operations by selling shares and may impair our ability to acquire other companies or technologies by using our shares as consideration.
If we fail to comply with the requirement to timely file all required periodic financial reports with the Securities and Exchange Commission, or other continued listing requirements of The Nasdaq Stock Market, our Common Stock may be delisted and the price of our Common Stock and our ability to access the capital markets could be negatively impacted.
Our common stock is listed for trading on Nasdaq. We must satisfy Nasdaq’s continued listing requirements, including, among other things, to timely file all required periodic financial reports with the Securities and Exchange Commission. On April 17, 2024, we received notice from Nasdaq indicating that were not in compliance with Nasdaq continued listing rule which requires us to timely file all required periodic financial reports with the Securities and Exchange Commission due to our failure to timely file this Annual Report on Form 10-K for the fiscal year ended December 31, 2023. On May 22, 2024, we received a second notice from Nasdaq indicating that we were not in compliance with Nasdaq’s continued listing rules due to our failure to timely file our Quarterly Report on Form 10-Q for the fiscal quarter ended March 31, 2024. We have 60 calendar days from the initial notification letter, or until June 17, 2024 to submit a plan to regain compliance with Nasdaq’s continued listing requirements. If the plan is accepted, we may be eligible for up to 180 calendar days from the original due date to file this Annual Report on Form 10-K, or until October 14, 2024, to regain compliance. The delisting of our common stock from Nasdaq could materially reduce the liquidity of our common stock and result in a corresponding material reduction in the price of our common stock. Delisting could also harm our ability to raise capital through alternative financing sources on terms acceptable to us, or at all, and may result in the potential loss of confidence by investors, employees and fewer business development opportunities.
We may need to raise additional funds in the future through issuances of securities and such additional funding may be dilutive to stockholders or impose operational restrictions.
We may need to raise additional capital in the future to help fund our operations through sales of shares of our common stock or securities convertible into shares of our common stock, as well as issuances of debt. Such additional financing may be dilutive to our stockholders, and debt financing, if available, and may involve restrictive covenants which may limit our operating flexibility. If additional capital is raised through the issuance of shares of our common stock or securities convertible into shares of our common stock, the percentage ownership of existing stockholders will be reduced. These stockholders may experience additional dilution in net book value per share and any additional equity securities may have rights, preferences and privileges senior to those of the holders of our common stock.
Because we do not expect to pay dividends for the foreseeable future, investors seeking cash dividends should not purchase our shares of common stock.
We have never declared or paid any cash dividends on our common stock, and we do not anticipate paying any cash dividends on our common stock in the foreseeable future. Payment of any future dividends will be at the discretion of our board of directors after taking into account various factors, including but not limited to our financial condition, operating results, cash needs, growth plans and the terms of any credit agreements that we may be a party to at the time. Accordingly, investors seeking cash dividends should not purchase shares of our common stock.
Provisions of our certificate of incorporation, bylaws and Delaware law may make a contested takeover of our Company more difficult.
Certain provisions of our certificate of incorporation, bylaws and the General Corporation Law of the State of Delaware (“DGCL”) could deter a change in our management or render more difficult an attempt to obtain control of us, even if such a proposal is favored by a majority of our stockholders. For example, we are subject to the provisions of the DGCL that prohibit a public Delaware corporation from engaging in a broad range of business combinations with a person who, together with affiliates and associates, owns 15% or more of the corporation’s outstanding voting shares (an “interested stockholder”) for three years after the person became an interested stockholder, unless the business combination is approved in a prescribed manner. Our certificate of incorporation also includes undesignated preferred stock, which may enable our board of directors to discourage an attempt to obtain control of us by means of a tender offer, proxy contest, merger or otherwise. Finally, our bylaws include an advance notice procedure for stockholders to nominate directors or submit proposals at a stockholders meeting. Delaware law and our charter may, therefore, inhibit a takeover.
The trading price of our common stock may be volatile.
The trading price of our shares has from time to time fluctuated widely and, in the future, may be subject to similar fluctuations. The trading price may be affected by a number of factors including the risk factors set forth in this Annual Report on Form 10-K as well as our operating results, financial condition, announcements of innovations or new products by us or our competitors, general conditions in the biometrics and access control industries, and other events or factors. We cannot assure you that any of the broker-dealers that currently make a market in our common stock will continue to serve as market makers or have the financial capability to stabilize or support our common stock. A reduction in the number of market makers or the financial capability of any of these market makers could also result in a decrease in the trading volume of and price of our shares. In recent years broad stock market indices, in general, and the securities of technology companies, in particular, have experienced substantial price fluctuations. Such broad market fluctuations may adversely affect the future-trading price of our common stock.
17
Table of Contents
ITEM 1B. UNRESOLVED STAFF COMMENTS
Not applicable.
ITEM 1C. CYBERSECURITY
We take a defense-in-depth approach, leveraging multiple, layered security measures, to protect our data, our customers’ data, our infrastructure, and our employees. We embed data protection throughout our operations and information technology programs, relying on multiple and various controls to prevent and detect threats, with the goal of safeguarding our assets, data and personnel.
We evaluate cybersecurity risks as part of our overall enterprise risk management. A steering committee of senior executives meets quarterly to evaluate any changes to the Company’s exposure to cybersecurity risks, discuss potential mitigation plans and provide updates on mitigation efforts already underway. Our cybersecurity team keeps up to date on the latest threats and risks through multiple channels and is also involved in evaluating risks associated with any new proposed service providers. We employ a Cybersecurity Engineer, reporting directly to our Chief Technology Officer, who manages our cybersecurity team that is comprised entirely of security professionals with industry recognized certifications. The cybersecurity team within BIO-key is responsible for assessing and managing risks and informing/gaining feedback from the cybersecurity steering committee.
Additionally, our team of dedicated cybersecurity experts/professionals maintain a comprehensive set of cybersecurity policies and standards, including a security incident response framework. The framework is a set of coordinated procedures and tasks that our incident response team executes to ensure timely and accurate reporting and resolution of computer security incidents. The framework details who, how and when appropriate persons or committees, including the Board of Directors and Audit Committee are kept informed on the status of potential cybersecurity incidents. A summary of recent incidents is also presented by the Chief Law Officer (“CLO”) at each regular Audit Committee meeting. Our policies and standards were developed in collaboration with a wide range of disciplines, including information technology, cybersecurity, legal, compliance and business. Our cybersecurity strategy and policies are continually reassessed to ensure they attempt to identify and proactively address the constant changes in the global threats. Decision makers such as the CLO, executive team, and Audit Committee are regularly kept up to date on cybersecurity trends. Ongoing collaboration with stakeholders throughout the business also helps to build continued awareness and visibility of future needs.
We engage external vendors to assess the cybersecurity program as needed. An independent third party will perform annual multi-stage penetration testing of our IT environment.
Our cybersecurity program is governed by the Audit Committee of our Board. The Audit Committee of the Board and the full Board will each receive quarterly updates on cybersecurity risks identified through the enterprise risk management processes described above.
Notwithstanding our processes to oversee and identify risk from cybersecurity threats, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us. We identify nation state-sponsored threat actors and the rise in sophistication and proliferation of ransomware campaigns as top reasonable material risks to the business. The theft, unauthorized use or publication of our intellectual property and/or confidential business or personal information (whether through a breach of our own systems or the breach of a system of a third party that provides services to us) could harm our competitive or negotiating positions, reduce the value of our investment in research and development and other strategic initiatives, compromise our patent enforcement strategies or outlook, damage our reputation or otherwise adversely affect our business. To date there have not been any risks that have materially affected our operations.
See Item 1A. “RISK FACTORS” for a discussion of cybersecurity risks.
ITEM 2.PROPERTY
We do not own any real estate. We conduct operations from leased premises in Eagan, Minnesota (5,544 square feet), Bedford, New Hampshire (3,364 square feet), and Holmdel, New Jersey (150 square feet). Internationally, we conduct operations from leased premises in Tsuen Wan, Hong Kong (1,098 square feet), Jiangmen, China (3,267 square feet), and Madrid, Spain (1,504 square feet). Our Eagan, Minnesota and Bedford, New Hampshire offices provide research and development, and customer support, for BIO-key software and PistolStar software, respectively. Our Holmdel, New Jersey location serves as our corporate headquarters. Our Hong Kong location is a small warehouse for finished goods as well as administrative and sales support. Our Jiangmen, China facility provides our hardware research and development, contract manufacturing and warehousing of raw materials, work-in-process, and finished goods. Our Madrid, Spain office serves as our sales organization for Europe, the Middle East, and parts Africa.
ITEM 3.LEGAL PROCEEDINGS
From time to time, we may be involved in litigation relating to claims arising out of our operations in the normal course of business. As of the date of this report, we are not a party to any pending lawsuit.
ITEM 4.MINE SAFETY DISCLOSURES
Not applicable.
18
Table of Contents
PARTII
ITEM 5.MARKET FOR REGISTRANT’S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES
Our common stock currently trades on the Nasdaq Capital Market under the symbol “BKYI”.
Holders
As of June 4, 2024 the number of stockholders of record of our common stock was 159.
Dividends
We have not paid any cash dividends on our common stock to-date and have no intention of paying any cash dividends on our common stock in the foreseeable future. The declaration and payment of dividends on our common stock is also subject to the discretion of our Board of Directors and certain limitations imposed under the Delaware General Corporation Law. The timing, amount, and form of dividends, if any, will depend on, among other things, our results of operations, financial condition, cash requirements and other factors deemed relevant by our Board of Directors.
Securities Authorized for Issuance under Equity Compensation Plans
For information on securities authorized for issuance under the Company’s equity compensation plans, see “Item 12 - Security Ownership of Certain Beneficial Owners and Related Stockholder Matters.”
Unregistered Sales of Equity Securities
There were no unregistered sales of the Company’s equity securities during 2023 that were not previously disclosed in a Quarterly Report on Form 10-Q or in a Current Report on Form 8-K.
Issuer Purchases of Equity Securities
None.
ITEM6. RESERVED
Not Applicable.
19
Table of Contents
ITEM 7.MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS
This Management’s Discussion and Analysis of Financial Condition and Results of Operations, and other parts of this Report contain forward-looking statements that involve risks and uncertainties. All forward-looking statements included in this Report are based on information available to us on the date hereof, and we assume no obligation to update any such forward-looking statements. Our actual results could differ materially from those anticipated in these forward-looking statements as a result of a number of factors, including those set forth in the section captioned “RISK FACTORS” in Item 1A and elsewhere in this Report.
The following Management’s Discussion and Analysis of Financial Condition and Results of Operations is intended to help you understand our Company. This discussion is provided as a supplement to and should be read in conjunction with our consolidated financial statements for the years ended December 31, 2023 and 2022 and the accompanying notes included elsewhere in this Report.
All share totals reported herein have been adjusted to reflect our 1-for-18 reverse stock split, which was effective December 21, 2023.
Overview
We are a leading identity access management (IAM) platform provider for the enterprise and large-scale customer and civil ID solutions. Built to leverage BIO-key’s world-class biometric core platform among seventeen strong authentication factors, BIO-key PortalGuard and hosted PortalGuard IDaaS are platforms that enable our customers to securely and easily assure that only the right people can access the right systems. PortalGuard goes beyond traditional multifactor authentication (MFA) solutions by addressing functional gaps, such as allowing roving users to biometrically authenticate at any workstation without using their phones or tokens, eliminating unauthorized account delegation, detecting duplicate users, and accommodating in-person identification.
Our customers use BIO-key every day to securely access a variety of cloud, mobile and web applications, on-premise and cloud-based servers from all of their devices. Employees, contractors, students and faculty sign in through PortalGuard to seamlessly and securely access the applications they need to do their important work, without relying on personal phone use or per-user tokens. Organizations use our platform to securely collaborate with their supply chain and partners, and to provide their customers with flexible, resilient user experiences online or in-person.
Large-scale customer and civil ID customers use our scalable biometric management platform and FBI-certified scanner hardware to manage enrollment, de-duplication and authentication for millions of users. One large bank has enrolled and identifies over 21.7 million of their customers using BIO-key fingerprint biometrics in branches on a daily basis.
PortalGuard and IBB deliver unique value to enterprises who find that mainstream MFA solutions do not adequately address their workforce use cases. PortalGuard operates as a single MFA user experience, providing a rich set of authentication choices to meet every use case. We sell our branded biometric and FIDO authentication hardware as accessories to our IAM platforms, so that customers can have a single vendor providing all components of their IAM solution. We do not mandate the use of BIO-key hardware with our software and services. Our NIST-certified fingerprint biometric platform is unique in that it supports interoperable mixing and matching combinations of different manufactures’ fingerprint scanners in a deployment, so that the right scanner can be selected for the right use case, without mandating the user of a particular scanner.
Security-conscious software developers leverage our platform APIs and federation interfaces to securely and efficiently embed biometric and MFA identity capabilities into their software. Our approach to IDaaS allows our customers to efficiently scale their security and identity infrastructures to protect both internal cloud workforce- and external customer-facing applications.
In 2022, we expanded our product offerings and customer base when we acquired Swivel Secure, a Madrid, Spain based provider of IAM solutions. Swivel Secure is the exclusive distributer of AuthControl Sentry, AuthControl Enterprise, and AuthControl MSP product line in Europe, Africa and the Middle East, or EMEA, excluding the United Kingdom and Ireland. These solutions include a patented one-time-code extraction technology, helping enterprises manage the increasing data security risks posed by cloud services and bring your own device policies.
We operate a SaaS business model with customers subscribing to term use of our software for annual recurring revenue. We sell our products directly through our field and inside sales teams, as well as indirectly through our network of channel partners including resellers, system integrators, master agents and other distribution partners. Our subscription fees include a term license of hosted or on-premise product and technical support and maintenance of our platform. We base subscription fees primarily on the products used and the number of users enrolled in our platform. We generate subscription fees pursuant to noncancelable contracts with a weighted average duration of approximately one year.
20
Table of Contents
Strategic Outlook
We plan to have a more significant role in the IAM market which continues to expand. We plan to continue to offer customers a suite of authentication options that complement our biometric solutions. The more well-rounded offerings of authentication options will allow customers to customize their approach to authentication all under one umbrella.
We expect to grow our business within government services and highly-regulated industries in which we have historically had a strong presence including financial services, higher education, and healthcare. We believe that continued heightened security and privacy requirements in these industries, and as colleges and universities continue operating in remote environments, we will generate increased demand for security solutions, including biometrics. In addition, we expect that the compatible, yet superior portable biometric user experience offered by our technology for Windows 10 users will accelerate the demand for our computer network log-on solutions and fingerprint readers. Through value add-offerings via direct sales, resellers, and strategic partnerships with leading higher education platform providers, we will continue to grow our installed base.
Our primary sales strategies are focused on (i) increased marketing efforts into the IAM market, (ii) dedicated pursuit of large-scale identification projects across the globe and (iii) growing our channel alliance program which we have grown to more than eighty-five participants and continues to generate incremental revenues.
A second component of our growth strategy is to pursue strategic acquisitions of select businesses and assets in the IAM space. In furtherance of this strategy, we are active in the industry and regularly evaluate businesses that we believe will either provide an entry into new market verticals or be synergistic with our existing operations and in either case, be accretive to earnings. We cannot provide any assurance as to whether we will be able to complete any acquisition and if completed, successfully integrate any business we acquire into our operations.
Recent Developments
As discussed under “Item 1A. Risk Factors”, given the uncertainty the current economic and political environment and their effects on our business operations, sales cycles, personnel, and the geographic markets in which we operate, and numerous other matters of national, regional and global scale, including those of a political, economic, business and competitive nature, the related financial impact cannot be reasonably estimated at this time.
The current trend of continued remote work environments increases the risk of unauthorized users, phishing attacks, and hackers who are eager to take advantage of the challenges of securing remote workers. A growing trend of security incidents that highlight potential cybersecurity vulnerabilities, additional regulatory requirements, and increasingly stringent Cyber Insurance underwriting standards that mandate enhanced security solutions has resulted in many businesses requiring MFA for their employees, partners and customers to access their business systems and data. We believe that biometrics should continue to play a key role in remote user authentication.
RESULTS OF OPERATIONS
Consolidated Results of Operations
Two Year % trend
Years ended
December 31,
Revenues
License fees 56 % 65 %
Hardware 15 % 9 %
Costs and other expenses
Cost of services 11 % 10 %
Cost of license fees 15 % 13 %
Cost of hardware 9 % 6 %
Cost of hardware reserve 47 % 6 %
Gross Profit 18 % 65 %
Operating expenses
Selling, general and administrative 101 % 133 %
Research, development and engineering 31 % 46 %
Reversal of earnout payable-Swivel acquisition 0 % -7 %
Impairment of goodwill 0 % 34 %
Total operating expenses 132 % 206 %
Other income (expense)
Total other income (expense) 2 % -29 %
Loss before provision for income tax benefit -112 % -170 %
Provision for income tax benefit 2 % 0 %
21
Table of Contents
Revenues and Costs and other expenses
Revenues
Costs and other expenses
Revenues
Revenue increased $734,647 or 10% to $8,654,905 in 2023 as compared to $7,020,258 in 2022 due to the factors stated below.
For the years ended December 31, 2023, and 2022, service revenues included approximately $1,193,000 and $1,243,000, respectively, of recurring maintenance and support revenue, and approximately $1,026,000 and $546,000, respectively, of non-recurring custom services revenue. Recurring service revenue decreased 4% in 2023 due to delayed renewals in the fourth quarter. Non-recurring custom services increased 88% in 2023 due to increased new customer installations, Swivel Secure service fees, and conversion to the cloud platform. Although inflation has negatively impacted many industries, we have continued to see our pipeline increase for the cybersecurity protection software and services that we offer.
For the year ended December 31, 2023 and 2022 license revenue decreased $242,042 or 5% to $4,342,010, due primarily to lower new customer orders. We expect do not expect this trend to continue into 2024.
Hardware sales increased by $547,524, or 85%, to $1,194,010 in 2023 from $646,486 in 2022. The increase was attributable largely to fourth quarter 2023 sales to an international defense agency.
Costs of goods sold
For the year ended December 31, 2023, cost of services increased approximately 19% to $861,936, due to the increased costs to support Swivel Secure deployments.
License fees for the year ended December 31, 2023 increased $268,502, or approximately 30%, to $1,174,919 due primarily to increased license revenue and related license fees payable for third-party software distributed by Swivel Secure.
Hardware costs for the year ended December 31, 2023 increased $289,230, or approximately 70%, to $700,231 from $411,001 in 2022. The increase was associated with the increased hardware sales and hardware mix described above. Hardware reserve costs for the year ended December 31, 2023 increased $3,186,500 due to a complete reserve of slow moving inventory purchased for projects in Nigeria, and for other older inventory. We are continuing to explore other markets and opportunities to sell this inventory.
22
Table of Contents
Selling, general and administrative
Selling, general and administrative costs for year ended December 31, 2023 were $7,862,710 representing a 16% decrease from 2022. The decrease included lower sales and marketing expenses related to show participation and personnel costs, offset by an increase in allowance for doubtful accounts ofr $750,000 compared to $360,000 in 2022.
Research, development and engineering
For the year ended December 31, 2023, research, development and engineering costs were $2,394,926 representing a 26% decrease from 2022. Included in the decrease were lower personnel costs associated with wages and benefits for engineering employees.
Reversal of earnout payable – Swivel Secure acquisition
For the year ended December 31, 2022, we recognized income on the elimination of the earnout payable on the acquisition of Swivel Secure as the requirements for the payout were not achieved.
Impairment of goodwill
For the year ended December 31, 2022, we recognized an impairment of our goodwill balances due to the decrease in market value of our common stock compared to the carrying value of our net assets.
Other income (expense)
The amounts for other income (expense) for the year ended December 31, 2023 consisted of interest income of $11,533, a gain from the sale of a PistolStar domain asset, change in loan transactions costs for payment of the convertible note payable as we elected to value the convertible note under the fair value option, and interest expense of $218,270 on the convertible note payable and the government loan through the BBVA bank. The amounts for the year ended December 31, 2022, consisted of interest income of $233, a write-off of the investment-debt security as we received the proceeds and the bond issuer defaulted on repayment, loan transactions costs expensed for the convertible note payable as we elected to value the convertible note payable under the fair value option, the change in the fair value of the convertible note, and interest expense of $10,462 on the convertible note and the government loan through the BBVA bank.
23
Table of Contents
LIQUIDITY AND CAPITAL RESOURCES
Operating activities overview
Net cash used for operations during the year ended December 31, 2023 was $3,793,456. Items of note included:
Investing activities overview
Net cash used in investing activities during the year December 21, 2023 was $1,000 for capital expenditures.
Financing activities overview
Approximately $4,297,000 was provided by financing activities during the year ended December 31, 2023 consisting of the issuance of common stock and warrants in public and private securities offerings, and exercise of warrants. These amounts were offset by repayment of convertible note payable, costs associated with the issuance of our securities, and proceeds of $17,478 from sales of common stock under the employee stock purchase plan.
Sources of Liquidity
Since our inception, our capital needs have been principally met through proceeds from the sale of equity and debt securities. We expect capital expenditures to be less than $100,000 during the next twelve months.
The following sets forth our primary sources of capital during the previous two years:
On November 20, 2023, we completed a private placement of shares of common stock and warrants resulting in net proceeds of approximately $435,000, after deducting placement agent fees and estimated offering expenses.
On October 30, 2023, we completed a public offering of shares of common stock and warrants resulting in net proceeds of approximately $3.3 million, after deducting placement agent fees and estimated offering expenses. We used approximately $2.2 million of the net proceeds to repay the outstanding amount due under outstanding convertible note payable.
In December 2022, we entered into and closed a securities purchase agreement (the “Purchase Agreement”) with AJB Capital Investments, LLC under which we issued a $2,200,000 principal amount senior secured promissory note (the “Note”). The principal amount of the Note was due six months following the date of issuance, subject to one six-month extension. Interest under the Note accrued at a rate of 10% per annum, payable monthly through month six and at 12% per annum in months seven through twelve, payable monthly. The Note was secured by a lien on substantially all of our assets and properties. The Note was repaid in December 2022.
In March 2022, in connection with the acquisition of Swivel Secure, we assumed a €500,000 government loan that was issued through BBVA Bank during the COVID-19 pandemic. The loan bears interest at the rate of 1.75% per annum and is payable in monthly installments of approximately $11,900 inclusive of interest from May 2022 through maturity in April 2026. Upon closing of the acquisition, Swivel Secure had cash equal to the outstanding balance.
We entered into an accounts receivable factoring arrangement with a financial institution (the “Factor”) which has been extended to October 31, 2024 and may be discontinued at that time. Pursuant to the terms of the arrangement, from time to time, we sell to the Factor a minimum of $150,000 per quarter of certain of our accounts receivable balances on a non-recourse basis for credit approved accounts. The Factor remits 35% of the foreign and 75% of the domestic accounts receivable balance to us (the “Advance Amount”), with the remaining balance, less fees, forwarded to us once the Factor collects the full accounts receivable balance from the customer. In addition, from time to time, we receive over advances from the Factor. Factoring fees range from 2.75% to 15% of the face value of the invoice factored and are determined by the number of days required for collection of the invoice. We expect to continue to use this factoring arrangement periodically to assist with our general working capital requirements due to contractual requirements.
Liquidity Outlook
At December 31, 2023, our total cash and cash equivalents were approximately $511,000, as compared to $2,600,000 at December 31, 2022. At December 31, 2023, we had working capital of approximately $(777,000) as a result of the allowance for doubtful accounts and reserve on inventory.
As discussed above, we have historically financed our operations through access to the capital markets by issuing secured and convertible debt securities, convertible preferred stock, common stock, and through factoring receivables. We currently require approximately $732,000 per month to conduct our operations, a monthly amount that we have been unable to consistently achieve through revenue generation. During 2023, we generated approximately $7,755,000 of revenue, which did not generate enough cash to fully fund our average monthly cash requirements. We expect that Swivel Secure Europe will continue to generate positive cash flow in 2024. We also have approximately $3.6 million of inventory (currently reserved) purchased for projects in Nigeria. We continue to explore other markets and opportunities to sell or return the product to generate additional cash.
If we are unable to generate sufficient revenue and positive cash flow from operations or liquidation of existing inventory to fund current operations and execute our business plan, we will need to obtain additional third-party financing during the next twelve months.
Our long-term viability and growth will depend upon the successful commercialization of our technologies and our ability to obtain adequate financing. To the extent that we require such additional financing, no assurance can be given that any form of additional financing will be available on terms acceptable to us, if at all, that adequate financing will be obtained to meet our needs, or that such financing would not be dilutive to existing stockholders. If available financing is insufficient or unavailable or we fail to continue to generate sufficient revenue, we may be required to further reduce operating expenses, delay the expansion of operations, be unable to pursue merger or acquisition candidates, or in the extreme case, not continue as a going concern.
24
Table of Contents
CRITICAL ACCOUNTING POLICIES AND ESTIMATES
Our financial statements are prepared in accordance with accounting principles generally accepted in the United States. The preparation of these financial statements requires that we make estimates and assumptions that affect the reported amounts of assets and liabilities and disclosure of contingent assets and liabilities at the date of the financial statements and the reported amounts of revenue and expenses during the reporting periods. We base our estimates on historical experience and on various other assumptions that we believe to be reasonable under the circumstances. We evaluate our estimates and assumptions on an ongoing basis. Our actual results may differ significantly from these estimates under different assumptions or conditions.
We believe that of our significant accounting policies, which are described in Note A of the notes to our consolidated financial statements included in this Annual Report on Form 10-K, the following accounting policies involve a greater degree of judgment and complexity. Accordingly, these are the policies we believe are the most critical to aid in fully understanding and evaluating our financial condition and results of operations, as listed below:
1. Revenue Recognition
2. Impairment or Disposal of Long Lived Assets, including Intangible Assets
3. Allowances for Accounts Receivable
ITEM 7A. QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK.
Not Applicable.
ITEM 8. FINANCIAL STATEMENTS AND SUPPLEMENTARY DATA
See financial statements appearing at pages 37-64 of this Annual Report on Form 10-K.
ITEM 9. CHANGES IN AND DISAGREEMENTS WITH ACCOUNTANTS ON ACCOUNTING AND FINANCIAL DISCLOSURE
None.
25
Table of Contents
ITEM 9A.CONTROLS AND PROCEDURES
Disclosure Controls and Procedures
Our management, with the participation of our Chief Executive Officer (“CEO”) and Chief Financial Officer (“CFO”), evaluated the effectiveness of our disclosure controls and procedures as of December 31, 2023. The term “disclosure controls and procedures,” as defined in Rules 13a-15(e) and 15d-15(e) under the Securities Exchange Act of 1934, as amended (the “Exchange Act”), means controls and other procedures of a company that are designed to ensure that information required to be disclosed by a company in the reports that it files or submits under the Exchange Act is recorded, processed, summarized and reported, within the time periods specified in the SEC’s rules and forms. Disclosure controls and procedures include, without limitation, controls and procedures designed to ensure that information required to be disclosed by a company in the reports that it files or submits under the Exchange Act is accumulated and communicated to the Company’s management, including its principal executive and principal financial officers, as appropriate to allow timely decisions regarding required disclosure. Based on the evaluation of our disclosure controls and procedures as of December 31, 2023, our CEO and CFO concluded that, as of such date, our disclosure controls and procedures were ineffective.
Management’s Annual Report on Internal Control Over Financial Reporting
Our management is responsible for establishing and maintaining adequate internal control over financial reporting, as such term is defined in Exchange Act Rule 13a-15(f) and 15d-15(f). Internal control over financial reporting cannot provide absolute assurance of achieving financial reporting objectives because of its inherent limitations. Internal control over financial reporting is a process that involves human diligence and compliance and is subject to lapses in judgment and breakdowns resulting from human failures. Internal control over financial reporting can also be circumvented by collusion or improper management override. Because of such limitations, there is a risk that material misstatements may not be prevented or detected on a timely basis. However, these inherent limitations are known features of the financial reporting process. Therefore, it is possible to design into the process safeguards to reduce, though not eliminate, the risk. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
Under the supervision and with the participation of our management, including our CEO and CFO, we have conducted an evaluation of the effectiveness of our internal control over financial reporting as of December 31, 2023, based upon the framework in Internal Control-Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission. Based on this evaluation, management has concluded that our internal control over financial reporting was not effective as of December 31, 2023 as a result of certain material weaknesses discovered during the course of their review.
In particular, in connection with the audit of our financial statements as of and for the year ended December 31, 2023, our management identified a lack of control over properly assessing revenue, allowances for accounts receivable and certain reserves for inventory. This resulted in certain errors in the manner in which we recognized revenue generated by our European subsidiary, Swivel Secure Europe, SA, in the first quarter of 2023. In addition, certain allowances for accounts receivable and certain reserves for inventory were understated.
We are currently working to implement appropriate corrective actions to remediate the material weakness to strengthen our internal controls over the recording of revenues.
Each of the material weaknesses noted will only be deemed to have been remediated after the new controls and procedures have been in place for a sufficient period and management has concluded through appropriate testing that the controls are operating effectively. However, we cannot assure you that these or other measures will fully remediate the material weaknesses in a timely manner.
As we are a smaller reporting company, this annual report does not include an attestation report of our registered public accounting firm regarding internal control over financial reporting. Management’s report was not subject to attestation by our registered public accounting firm pursuant to rules of the SEC that permit the Company to provide only management’s report in this Annual Report on Form 10-K.
Changes in Internal Control Over Financial Reporting
Going forward, we will change our internal control over financial reporting for the year ended December 31, 2023 to thoroughly access all accounts for potential adjustments required for proper presentation of the value of the accounts.
ITEM 9B.OTHER INFORMATION
None.
ITEM 9C. DISCLOSURE REGARDING FOREIGN JURISDICTIONS THAT PREVENT INSPECTIONS
Not Applicable.
26
Table of Contents
PARTIII
ITEM 10.DIRECTORS, EXECUTIVE OFFICERS AND CORPORATE GOVERNANCE
The following sets forth certain information about each director and executive officer of the Company.
NAME AGE POSITIONS HELD
Cameron Williams (a)* (b) (c) 77 Director
Robert J. Michel (a) (b)*(c) 67 Director
Wong Kwok Fong (Kelvin) 60 Director and Vice-Chairman of the Board of Directors
Emmanuel Alia (b) (c)* 59 Director
Cecilia C. Welch 64 Chief Financial Officer
Mira K. LaCous 62 Chief Technology Officer
(a) Compensation Committee Member
(b) Audit Committee Member
(c) Nominating Committee Member
* Indicates chair of committee
Set forth below is a brief description of the background and business experience of our directors and executive officers for the past five years.
Directors
Michael W. DePasquale has served as our Chief Executive Officer and a Director since January 3, 2003, and Chairman of the Board since January 29, 2014. He served as Co-Chief Executive Officer of the Company from July 2005 to August 2006. Mr. DePasquale brings more than 30 years of executive management, sales and marketing experience to the Company. Mr. DePasquale has held executive management positions with McGraw-Hill, Digital Equipment Corporation, and other companies in the software and professional services industries. Mr. DePasquale earned a Bachelor of Science degree from the New Jersey Institute of Technology. He serves as the Vice Chairman on the Board of Directors of the International Biometrics and Identification Industry Association. We believe Mr. DePasquale’s qualifications to sit on the board of directors include his extensive executive management experience in the technology sector and biometric industry expertise which strengthen the board’s collective qualifications, skills and experience.
Cameron E. Williams was appointed Director of the Company on June 2, 2023. Mr. Williams has over 40 years of financial and executive management experience. Since 2014, he has served as the principal of CEW Advisory Services, a consulting firm he founded which provides strategic planning and related services to the consumer lending industry. He previously founded CEW Solutions which provided fraud investigation services to insurance companies, law firms, and third-party administrators. From 2007 to 2009, Mr. Williams served as COO of Asta Funding, Inc., a publicly traded diversified financial services company where he was responsible for the sourcing and financial analysis of distressed consumer assets. From 1998 to 2007, Mr. Williams served as President of Popular Financial Holdings, an affiliate of Popular, Inc., a $36 billion banking organization. Mr. Williams began his career in the banking industry holding financial management positions with Security Pacific Financial Services, BankAmerica Financial, Inc., and Security Pacific Financial Services System, Inc. Mr. Williams earned a Bachelor’s in Accounting and completed graduate coursework at San Diego State University. We believe Mr. Williams’ extensive financial and executive management experience in a variety of industries strengthens the Board’s collective qualifications, skills, and experience.
27
Table of Contents
Robert J. Michel has served as a Director of the Company since April 10, 2017. He has over 30 years of accounting and financial management experience. Since September, 2018, he has served as the Chief Financial Officer of Daxor Corporation (Nasdaq: DXR), a medical device manufacturing company specializing in blood volume analysis. Prior to Daxor, from November, 2017 until September 2018, Mr. Michel served as the CFO of Roadway Moving, Inc., a transportation, moving and storage company located in New York City. Mr. Michel spent 15 years at Asta Funding, Inc. (Nasdaq: ASFI), a diversified financial services company, including serving as its Chief Financial Officer from 2009 until 2017 where he was responsible for all financial matters and SEC reporting. Mr. Michel is a certified public accountant, earned an MBA in Taxation from St. John’s University, and a BS in Business Administration from Villanova University. We believe Mr. Michel’s qualifications to sit on the board of directors include his substantial experience in accounting and financial management for public companies which provide the board with a deep knowledge of financial and SEC reporting and strengthen the board’s collective qualifications, skills, and experience.
Wong Kwok Fong (Kelvin) has served as a Director of the Company since December 4, 2015, as Managing Director of our Hong Kong Subsidiary since August 2016, and as Vice-Chairman of the Board of Directors since March 2019. He is the co-founder of China Goldjoy Group (previously World Wide Touch Technology Holdings Limited), a company listed on The Stock Exchange of Hong Kong. From 1997 until August, 2015, Mr. Wong served as the Chairman of China Goldjoy Group and served as its Chief Technology Officer through October 2016. During this time, Kelvin played a significant role in the substantial growth of the business. Kelvin brings over 25 years of senior management experience in manufacturing, supply chain, and marketing functions in the electronics and technology industries, including establishing manufacturing plants in Hong Kong and China, and building an extensive network in the electronics and technology industries. We believe Kelvin’s qualifications to sit on the board of directors include his substantial experience in the technology industry, including biometrics and payment systems, and serving the Asian markets, which broaden and strengthen the board’s collective qualifications, skills, and experience.
Emmanuel Alia was appointed Director of the Company on April 3, 2020. Since 2018, Mr. Alia has been providing management consulting services as an advisor to businesses seeking market entry strategies to emerging markets such as Africa and the Caribbean. From 2011 to 2018, Mr. Alia served as an Executive Director at the Corporate and Investment division of JPMorgan, and as a Senior Vice-President at CHASE Bank’s Consumer and Community Banking specializing in the financial and banking services industry and opportunities in Africa. During Mr. Alia’s tenure with JPMorgan, he served as head of Wholesale Operations in the Receivables Operations of the Global banking operations in the US and Canada, head of Retail Banking in the Greater Detroit area, and head of branches in the New York and New Jersey areas. For two years Mr. Alia was co-chair of the Black Organizational Leadership Development, an employee networking group in JPMorgan that works with firm’s leadership to strengthen the firm’s message, strategies and community outreach globally. Mr. Alia received a Bachelor of Arts in Accounting from Southeastern University and a Master’s of Business Administration (MBA) from Cornell University. We believe Mr. Alia’s qualifications to sit on the board of directors include his extensive industry experience and connection and networking abilities in the African communities and markets which further broaden and strengthen the board’s collective qualifications, skills, and experience.
Executive Officers
Cecilia C. Welch has served as the Chief Financial Officer of the Company since December 21, 2009. Ms. Welch joined the Company in 2007 as Corporate Controller. Prior to joining the Company, Ms. Welch has held senior financial management positions in various industries, including software and manufacturing. Ms. Welch has a bachelor’s degree in accounting from Franklin Pierce University.
Mira K. LaCous has served as Chief Technology Officer of the Company since March 13, 2014, as Senior Vice President of Technology & Development since 2012, and as our Vice President of Technology and Development since 2000. Ms. LaCous has over 35 years of product/project management, solution architecture, software development, team leadership and customer relations experience, with a background that includes successfully bringing numerous innovative products and technologies to market, including automated voice response systems, automated building control systems, software piracy protection, internet training materials and testing, WYSIWYG page layout and design software, image scanning / recognition software and systems, biometric security systems and algorithms, automated national ID systems using biometrics, and mobile applications with secure frameworks. Ms. LaCous has been a speaker at multiple events/conferences and has worked with teams around the globe bringing biometric technology deployments to life. Ms. LaCous is the author of eight (8) US patented technologies, multiple international patents and lead the engineering team in developing other patents and inventive technologies. Ms. LaCous earned a bachelor’s degree in Computer Science, with mathematics and physics from North Dakota State University.
28
Table of Contents
James D. Sullivan has served as BIO-key’s Senior Vice President of Strategy and Compliance and BIO-key’s Chief Legal Officer since February 2020, as Senior Vice President of Strategy and Business Development from April 2012 through December 2018, and the dual role as Senior Vice President of Global Sales from August 2015 through December of 2016. Mr. Sullivan is a recognized expert in privacy, cybersecurity, and biometric authentication for workforce and consumer applications. During his twenty years with the Company, Mr. Sullivan has directly worked with dozens of the Company’s customers, including AT&T, Israel Defense Forces, LexisNexis, NCR and Omnicell, as well as large-scale biometric-centered identity management projects that interface daily with millions of corporate and consumer users. Mr. Sullivan earned a Juris Doctor with Honors from Georgia State University College of Law, is a member of the Georgia Bar, and enrolled to practice before the IRS. Mr. Sullivan has an undergraduate degree in Computer Science from Brown University and has over 26 years of experience in IT projects and implementation, including directly working with security and identity management solutions at the Company, Computer Associates, Platinum Technology, and Memco Software.
Committees of the Board of Directors
Audit Committee
Our audit committee is comprised of Robert J. Michel (Chair), Cameron Williams, and Emmanuel Alia each of whom meets the independence standards for purposes of serving on an audit committee established by NASDAQ and under the Exchange Act. Our audit committee (i) assists the board of directors in its oversight of the integrity of our financial statements, compliance with legal and regulatory requirements, and corporate policies and controls, (ii) has the sole authority to retain and terminate our independent registered public accounting firm, approve all auditing services and related fees and the terms thereof, and pre-approve any non-audit services to be rendered by our independent registered public accounting firm, and (iii) is responsible for confirming the independence and objectivity of our independent registered public accounting firm. Our independent registered public accounting firm has unrestricted access to our audit committee. Our board of directors has determined that Robert J. Michel qualifies as an “audit committee financial expert,” as such term is defined in Item 407 of Regulation S-K.
Our audit committee operates under a written charter that is reviewed annually. The charter is available on our website at www.bio-key.com.
Compensation Committee
Our compensation committee is comprised of Cameron Williams (Chair) and Robert Michel, both of whom meet the independence standards established by NASDAQ and under the Exchange Act. The compensation committee’s duties include overseeing our overall compensation philosophy, policies and programs. This includes reviewing and analyzing the design and function of our various compensation components, establishing salaries, incentives and other forms of compensation for officers and non-employee directors, and administering our equity incentive plan. In fulfilling its responsibilities, the compensation committee has the authority to delegate any or all of its responsibilities to a subcommittee of the compensation committee.
Our compensation committee operates under a written charter that is reviewed annually. The charter is available on our website at www.bio-key.com.
Code of Ethics
We have adopted a Code of Ethics that applies to our principal executive officer, principal financial officer, principal accounting officer or controller, and persons performing similar functions. Our Code of Ethics is designed to deter wrongdoing and promote: (i) honest and ethical conduct, including the ethical handling of actual or apparent conflicts of interest between personal and professional relationships; (ii) full, fair, accurate, timely and understandable disclosure in reports and documents that we file with, or submit to, the SEC and in our other public communications; (iii) compliance with applicable governmental laws, rules, and regulations; (iv) the prompt internal reporting of violations of the code to an appropriate person or persons identified in the code; and (v) accountability for adherence to the code. We intend to disclose amendments or waivers of the Code of Ethics on our website within four business days. Any person may obtain a copy of our Code of Ethics free of charge by sending a written request for such to the attention of the Chief Financial Officer of the Company, 101 Crawfords Corner Road, Suite 4116, Holmdel, NJ 07733.
29
Table of Contents
Term of Office
Our directors are elected at the annual meeting of stockholders and hold office until the annual meeting of the stockholders next succeeding his or her election, or until his or her prior death, resignation or removal in accordance with our bylaws. Our officers are appointed by the Board and hold office until the annual meeting of the Board next succeeding his or her election, and until his or her successor shall have been duly elected and qualified, subject to earlier termination by his or her death, resignation or removal.
Delinquent Section 16(a) Reports
Reports of all transactions in our common stock by officers, directors and ten percent (10%) stockholders are required to be filed with the SEC pursuant to Section 16(a) of the Exchange Act. Based solely on our review of copies of the reports received, or representations of such reporting persons, we believe that during the year ended December 31, 2023, all Section 16(a) filing requirements applicable to our officers, directors and ten percent (10%) stockholders were satisfied in a timely fashion,
ITEM 11.EXECUTIVE COMPENSATION
The following table sets forth a summary of the compensation paid to or accrued by our chief executive officer and the two most highly compensated executive officers other than our chief executive officer, for the fiscal years ended December 31, 2023 and 2022:
SUMMARY COMPENSATION TABLE
Stock All Other
Name and Principal Salary Awards Compensation Total
Position Year ($) ($) (1) ($) (2) ($)
Narrative Disclosure to Summary Compensation Table
Compensation for our executives is comprised of three main components: base salary, annual performance-based cash bonus, and long-term equity awards. We do not target a specific weighting of these three components or use a prescribed formula to establish pay levels. Rather, the board of directors and compensation committee considers changes in the business, external market factors and our financial position each year when determining pay levels and allocating between long-term and current compensation for the named executive officers.
Cash compensation is comprised of base salary and an annual performance-based cash bonus opportunity. The compensation committee generally seeks to set a named executive officer’s targeted total cash compensation opportunity within a range that is the average of the applicable peer company and/or general industry compensation survey data, adjusted as appropriate for individual performance and internal pay equity and labor market conditions.
In setting cash compensation levels, we favor a balance in which base salaries are generally targeted at slightly below the peer average and a bonus opportunity that is targeted at slightly above the average. Effective January 16, 2023, we decreased the base compensation of Mr. DePasquale, Mr. Sullivan and Ms. Welch as part of the revised budget for the year. Effective March 1, 2022, we increased the base compensation of Mr. DePasquale, Mr. Sullivan and Ms. Welch.
Performance-based bonuses have historically been based upon the achievement of certain revenue milestones established by the compensation committee. The committee believes that this higher emphasis on performance-based cash bonuses places an appropriate linkage between a named executive officer’s pay, his or her individual performance, and the achievement of specific business goals by placing a higher proportion of annual cash compensation at risk, thereby aligning executive opportunity with the interests of stockholders.
30
Table of Contents
We also include an equity component as part of our compensation package because we believe that equity-based compensation aligns the long-term interests of our named executive officers with those of stockholders. In 2022 and 2023, we issued restricted stock awards to each of our named executive officers in recognition of the revenue growth of the Company in 2021 and successful integration of Portal Guard, and revenue growth of the Company in 2022 and successful integration of Swivel Secure, respectively.
These cash and equity compensation components of pay are supplemented by various benefit plans that provide health, life, accident, disability and severance benefits, most of which are the same as the benefits provided to all of our US based employees.
Employment Agreements
On March 26, 2010, we entered into an employment agreement, effective as of March 25, 2010, with Michael W. DePasquale to serve as our Chief Executive Officer until March 24, 2011. The agreement automatically renews for subsequent one-year terms, unless the employment relationship is terminated by either party, or modified in accordance with the terms and conditions of the agreement. Since 2018, Mr. DePasquale’s annual base salary has been $275,000, subject to adjustment by the compensation committee. In addition to the base salary, a “Performance Bonus” may be awarded to Mr. DePasquale on the basis of the Company achieving certain corporate and strategic performance goals, as determined by the compensation committee in its sole discretion. The employment agreement contains standard and customary confidentiality, non-solicitation and “work made for hire” provisions as well as a covenant not to compete which prohibits Mr. DePasquale from doing business with any current or prospective customer of the Company or engaging in a business competitive with that of the Company during the term of his employment and for the one-year period thereafter. This agreement also contains a number of termination and change in control provisions as described under the captions “Termination Arrangements” and “Change in Control Arrangements” below.
On April 5, 2017, we entered into an employment agreement with James Sullivan. The agreement automatically renews for subsequent one-year terms, unless terminated by the Company upon at least two months prior written notice which is treated as termination without cause. Since 2021, Mr. Sullivan’s annual base salary has been $225,000, subject to adjustment by the compensation committee. The agreement contains standard and customary confidentiality, technical invention provisions as well as non-competition and non-solicitation covenants which prohibit Mr. Sullivan from doing business with any current or prospective customer of the Company or engaging in any business competitive with that of the Company during the term or his employment and for the one-year period thereafter. The agreement also contains a number of termination provisions as described under the caption “Termination Agreements” below.
On May 15, 2013, we entered into an employment agreement with Cecilia Welch to serve as the Chief Financial Officer of the Company until May 2014. The agreement automatically renews for subsequent one-year terms, unless the employment relationship is terminated by either party, or modified in accordance with the terms and conditions of the agreement. The employment agreement contains standard and customary confidentiality, technical invention provisions, as well as a covenant not to compete, which prohibits Ms. Welch from doing business with any current or prospective customer of the Company or engaging in a business competitive with that of the Company during the term of her employment and for the one-year period thereafter. This agreement also contains a number of termination provisions as described in “Termination and Change in Control Arrangements” in this Item.
Stock Option Grants and Restricted Stock Awards
In the event of any change in the outstanding shares of our common stock by reason of a stock dividend, stock split, combination of shares, recapitalization, merger, consolidation, transfer of assets, reorganization, conversion or what the board deems to be similar circumstances, the number and kind of shares subject to outstanding options and restricted stock awards, and the exercise price of such options shall be appropriately adjusted. Restricted Furthermore, option agreements and restricted stock award agreements contain change of control provisions as described under the caption “Change in Control Provisions” below.
31
Table of Contents
OUTSTANDING EQUITY AWARDS AT FISCAL YEAR END