idai-20241231
Table of Contents
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
FORM 10-K
x Annual Report pursuant to Section 13 or 15(d) of the Securities Exchange Act of 1934
For the fiscal year endedDecember 31, 2024
oTRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE
ACT OF 1934
For the transition period from ______________ to _____________
Commission file number: 001-41252
T Stamp Inc. (D/B/A Trust Stamp)
(Exact name of registrant as specified in its charter)
3017 Bolling Way NE, Floor 2, Atlanta, Georgia30305
(Address of registrant’s principal executive offices) (Zip code)
Registrant’s telephone number, including area code (404) 806-9906
Securities registered under Section 12(b) of the Act:
Title of each class TradingSymbol(s) Name of each exchange on which registered
Class A Common Stock, $0.01 par value per share IDAI The NASDAQ Stock Market LLC
Securities registered pursuant to Section 12(g) of the Act: None.
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes oNox
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes oNox
Indicate by check mark whether the issuer (1) has filed reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yesx No o
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yesx No o
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
Large accelerated filer o Accelerated filer o
Non-accelerated filer x Smaller reporting company x
Emerging growth company x
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. o
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 USC. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. o
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. o
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). o
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes o No x
As of June 30, 2024, the aggregate market value held by non-affiliates of the registrant, computed by reference to the price at which the registrant’s Class A Common Stock was last sold on the NASDAQ Stock Exchange on such date was $4,668,599(669,506 at a closing price per share of $6.97 on June 30, 2024). As of March 28, 2025, there were 2,487,052 shares of Class A Common Stock, par value $0.01 per share, of the registrant outstanding.
Table of Contents
Documents Incorporated by Reference
None
Auditor Name: Auditor Location: Auditor Firm ID:
Marcum LLP Marlton, New Jersey 688
Table of Contents
T STAMP INC.
TABLE OF CONTENTS
Page
PART I 4
Item 1 Business 4
Item 1A Risk Factors 19
Item 1B. Unresolved Staff Comments 26
Item 1C Cybersecurity 26
Item 2 Properties 27
Item 3 Legal Proceedings 27
Item 4 Mine Safety Disclosures 27
Item 6 Reserved 30
Item 7A Quantitative and Qualitative Disclosures About Market Price 47
Item 8 Financial Statements and Supplementary Data F-1
Report of Independent Registered Public Accounting Firm F-2
Consolidated Balance Sheets as of December 31, 2024 and 2023 F-3
Item 9A Controls and Procedures 43
Item 9B Other Information 44
Item 9C Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 44
PART III 45
Item 10 Directors, Executive Officers, and Corporate Governance 45
Item 11 Executive Compensation 51
Item 14 Principal Accounting Fees and Services 55
Item 15 Exhibits, Financial Statement Schedules 56
Signatures 60
2
Table of Contents
Statement Regarding Forward-Looking Statements
This Form 10-K contains “forward-looking statements” within the meaning of Section 27A of the Securities Act of 1933, as amended (the “Securities Act”) and Section 21E of the Securities and Exchange Act of 1934, as amended (the “Exchange Act”), that involve risks and uncertainties, as well as assumptions that, if they never materialize or prove incorrect, could cause our results to differ materially and adversely from those expressed or implied by such forward-looking statements. Forward-looking statements may include, but are not limited to, statements relating to our outlook or expectations for earnings, revenues, expenses, asset quality or other future financial or business performance, strategies, expectations or business prospects, or the impact of legal, regulatory or supervisory matters on our business, results of operations, or financial condition. Specifically, forward-looking statements may include statements relating to our future business prospects, revenue, income, and financial condition.
Forward-looking statements can be identified by the use of words such as “estimate,” “plan,” “project,” “forecast,” “intend,” “expect,” “anticipate,” “believe,” “seek,” “target,” or similar expressions. Forward-looking statements reflect our judgment based on currently available information and involve a number of risks and uncertainties that could cause actual results to differ materially from those described in the forward-looking statements.
In addition to those factors discussed under Item 1A—“Risk Factors,” important factors could cause actual results to differ materially from our expectations. These factors include, but are not limited to:
•adverse economic conditions;
•general decreases in demand for our products and services;
•changes in timing of introducing new products into the market;
•intense competition (including entry of new competitors), including among competitors with substantially greater resources than us;
•inadequate capital;
•unexpected costs;
•revenues and net income lower than anticipated;
•litigation;
•becoming delisted from Nasdaq;
•the possible fluctuation and volatility of operating results and financial conditions;
•the impact of legal, regulatory, or supervisory matters on our business, results of operations, or financial condition;
•inability to carry out our marketing and sales plans; and
•the loss of key employees and executives.
All forward-looking statements included in this Form 10-K speak only as of the date of this Form 10-K and you are cautioned not to place undue reliance on any such forward-looking statements. Except as required by law, we undertake no obligation to publicly update or release any revisions to these forward-looking statements to reflect any events or circumstances that arise after the date of this Form 10-K or to reflect the occurrence of unanticipated events. The above list is not intended to be exhaustive and there may be other factors that could preclude us from realizing the predictions made in the forward-looking statements. We operate in a continually changing business environment and new factors emerge from time to time. We cannot predict such factors or assess the impact, if any, of such factors on our financial position or results of operations.
In this Annual Report on Form 10-K, unless the context indicates otherwise, the terms “Trust Stamp”, the “Company”, “we”, “us”, and “our” refer to T Stamp Inc., a Delaware corporation.
3
Table of Contents
PART I.
Item 1. Our Business
Overview
Trust Stamp was incorporated under the laws of the State of Delaware on April 11, 2016 as “T Stamp Inc.” T Stamp Inc. and its subsidiaries (“Trust Stamp”, “we”, or the “Company”) develop and market identity authentication software for enterprise and government partners and peer-to-peer markets.
Trust Stamp primarily develops proprietary artificial intelligence-powered solutions, researching and leveraging machine learning artificial intelligence, including computer vision, cryptography, and data mining, to process and protect data and deliver insightful outputs that identify and defend against fraud, protect sensitive user information, facilitate automated processes, and extend the reach of digital services through global accessibility. We utilize the power and agility of technologies such as GPU processing, edge computing, neural networks, and large language models to process and protect data faster and more effectively than historically possible to deliver results at a disruptively low cost for usage across multiple industries.
Our team has substantial expertise in the creation and development of AI-enabled software products. We license our technology and expertise in numerous fields, with an increasing emphasis on addressing diverse markets through established partners who will integrate our technology into field-specific applications.
Over the last twelve months, while maintaining our strong emphasis on identity authentication for financial services, the Company has undertaken a multi-pronged process to position itself better to leverage the growing opportunities offered by the expanded capabilities, use, and acceptance of AI technologies. This process has included:
• Reducing the size of the non-production-focused executive and consulting teams to reduce overhead.
• Releasing sales staff that did not meet their targets.
•Negotiating a services contract to offset the cost of the technical team members while maintaining significant R&D and product development capabilities.
•Refocusing go-to-market strategies on joint ventures with proven industry partners with access to target markets.
•Expanding our IP portfolio to strengthen our existing position related to presentation attack detection and tokenization and include implementations such as:
i.Embedded ownership verification for cryptographic assets, a technology that we believe to have significant potential with the expansion in the ownership of crypto-assets including potential deregulation (or loosening or clarification of regulation) in the United States together with the global growth of stable coins including Central Government Digital Currencies.
ii.A simple user interaction utility called “Shape Overlay” that augments biometric verification and combats deepfakes and injection attacks by having the user interact in real-time with their captured image.
iii.Stable Key (or “Stable IT2”) which is an innovative technology that generates a “key” directly from the biometric of the user which key has a mathematical correlation to all of the user's passwords, PINS, and other “secrets” for every account and use case meaning that those secrets never need to be stored in their entirety.
iv.A patent for “Interoperable Biometric Representations” that potentially breaks vendor lock-in by allowing users of biometric technologies to compare like-modality templates from different sources.
•Strengthening our international 3rd party cybersecurity and data handling certifications by adding SOC2 certification to our NCSC Cyberessentials Plus certification and obtaining a renewed D-Seal certification (the world’s first certification that includes not just data security but also the ethical and responsible use of data).
•Opening an office in Tokyo (with funding from the City of Tokyo and the Japanese government) to pursue opportunities in the APAC region.
•Retaining an investment bank to explore strategic partnership and M&A opportunities across multiple sectors.
4
Table of Contents
Markets
Trust Stamp has evaluated the market potential for its services in part by reviewing the following reports, articles, and data sources, none of which were commissioned by the Company, and none of which are to be incorporated by reference:
Data Security and Fraud
•According to the “2021 Year End Report: Data Breach QuickView” published by Flashpoint, 4,145 publicly disclosed breaches exposed over 22 billion records in 2022.
•The cumulative merchant losses to online payment fraud between 2023 and 2027 will exceed $343 billion globally according to a 2022 report titled “Fighting Online Payment Fraud in 2022 & Beyond” published by Juniper Research.
Financial and Societal Inclusion
•According to the “Global Findex Database 2021,” published by the World Bank, 1.4 billion people were unbanked as of 2021.
•131 million small and medium-sized enterprises in emerging markets lack access to finance, limiting their ability to grow and thrive (UNSGSA Financial Inclusion Webpage, Accessed March 2023).
•The global market for Microfinance is estimated at $157 Billion in the year 2020 and is projected to reach $342 billion by 2026 according to the 2022 report titled “Microfinance - Global Market Trajectory & Analytics” published by Global Industry Analysts, Inc. To accelerate our work in this market, the Company has joined the Mastercard Lighthouse MASSIV program designed to empower sustainability and social impact through strategic partnerships aiming to assist participants to scale on a global level.
Trust Stamp’s biometric authentication, liveness detection, and information tokenization enable individuals to verify and establish their identities using data derived from biometrics. While individuals in this market lack traditional means of identity verification, Trust Stamp provides a means to authenticate identity that preserves an individual’s privacy and control over that identity.
Alternatives to Detention (“ATD”)
•The ATD market includes Federal, State, and Municipal agencies for both criminal justice and immigration purposes. Trust Stamp addresses the ATD market with applications built on Trust Stamp’s privacy-preserving solutions allowing individuals to comply with ATD requirements using ethical and humane technology methodologies. Trust Stamp has developed innovative patented technologies for use in the ATD market encompassing biometrics, geolocation, and tokenization as well as a proprietary, tamper-resistant, battery-free “Tap-In-Band” that can complement or replace biometric check-in requirements and provide a lower-cost and more humane alternative to traditional “ankle bracelet” technology.
In December 2024 we announced a go-to-market agreement with a leading provider of software solutions to the U.S. Federal Government and we are currently pursuing a revised go-to-market strategy based on the priorities of the administration.
Other Markets
The Company is developing products and working with partners and industry organizations in other sectors that offer significant market opportunities for our existing and pipeline IP and has entered into go-to-market or licensing agreements, including global data location services, healthcare, IoT, access control, smart home systems, and computer vision for UAV operations. We anticipate licensing our technology in numerous fields, typically through established partners who will integrate our technology into field-specific applications.
Africa
The African Continental Free Trade Area (AfCFTA) is a landmark agreement that binds 54 African nations and an estimated 1.47 billion people into the world’s largest free trade area. AfCFTA has significant economic potential for Africa, as it aims to create a single market for goods and services across 55 countries, representing over 1.3 billion people with a combined GDP of approximately $3.4 trillion. By reducing trade barriers, the agreement could contribute an
5
Table of Contents
additional $450 billion to Africa’s GDP by 2035, lifting 30 million people out of extreme poverty and increasing the incomes of 68 million people, according to the World Bank. Over the next decade, Africa’s share of the world population is projected to reach 21%, up from 13% in 2000. More than 50% of young people entering the workforce will be in sub-Saharan Africa. By 2050, the region’s working-age population will still be rising while it is falling virtually everywhere else, and Africa will be home to an estimated 2.5 billion people, or 25% of all humanity.
Globally, 850 million people did not have identity documents in 2023, with 542 million in Africa. Of that 542 million, 95 million are children who have never had their birth recorded, and 120 million are children without a birth certificate. The single initiative of implementing universal tokenized identity in African countries has the potential to significantly boost the implementing countries' economies. According to the United Nations Economic Commission for Africa (UNECA), countries adopting digital ID programs could unlock economic value equivalent to 3% and 13% of their GDP by 2030.
A transition to digital records for births, marriages, deaths, and electronic identity documents represents a transformative opportunity for developing nations and builds a foundation for economic growth. Establishing a robust digital infrastructure for vital records enhances administrative efficiency, fosters inclusive development, strengthens governance, and unlocks economic potential. Yet, developing African countries are often unable or unwilling to fund the initial capital expenditure required to make the transition.
Trust Stamp has participated in financial inclusion projects in Africa for a number of years through Mastercard’s implementation of our technology and we established a regional R&D center in Rwanda in 2021 to focus on ensuring equity in the development and implementation of biometric technology in Africa. In 2023 we started direct outreach to African countries to initiate national-level digital identity programs and we are in serious and extended dialog with two countries as well as a pilot with Africa’s largest provider of mobile telecommunications services. With the assistance of the Mastercard Lighthouse MASSIV program, we intend to build upon this work to maximize the opportunities to meet the critical need for secure identity programs for both governments and NGOs.
Principal Products and Services
We adhere to the best practices outlined in the National Institute of Standards and Technology (“NIST”) and International Organization for Standardization (“ISO”) frameworks, and our policies and procedures in managing personally identifiable information (“PII”) comply with General Data Protection Regulation (“GDPR”) requirements wherever such requirements are applicable.
The IT2 replaces biometric templates and scans with meaningless numbers, letters, and symbols to remove sensitive data from the reach of criminals using a proprietary process by which a deep neural network irreversibly converts biometric and other identifying data, from any source, into the secure tokenized identity. This IT2 is unique to the user, is different every time it is generated from a live subject, and cannot be reverse-engineered and rebuilt into the user’s face or other original identity data.
6
Table of Contents
Each token can be stored and compared to all other tokens from the same modality, allowing the Company’s AI-powered analytics to predict if a single subject has generated two or more tokens, even if the subject has passed conventional KYC with, e.g., falsified identity documents. Using this technology, an IT2 can be employed for re-authentication purposes, including account recovery, password-less login, new account creation, and more, across the organization or even within a consortium of organizations, all in a low-cost and low-friction delivery that is fast and secure.
Our technology is being used for enhanced due diligence, KYC/AML compliance, synthetic identity fraud reduction and “second chance” approval for customer onboarding and account access, together with the delivery of humanitarian and development services. The solution allows organizations to approve more users, keep bad actors from accessing systems and services, and retain existing users with a superior user experience.
Our hashing and matching technology can maximize the effectiveness of all types of identity data while rendering it safer to use, store, and share. Whatever the source of identity data, it can be stored and compared as an IT2. See the chart below for examples.
Distribution
Through licensing we allow customers to utilize our technology in a wide variety of applications. Uses can include (e.g.):
•The provision of services and hashing to enterprises, NGOs, and government, to overlay on third-party biometric and identity data.
•Hash licensing, translation, and certification services for biometric vendors.
•Management of zero-knowledge-proof services, whether as a tributary between Identity Lakes or operating consortium lakes.
•Tokenized identity creation for large scale deployments, such as humanitarian and government identity programs.
LicensingAgreements
License agreements are typically a hosted offering, on-premise solution, or both pursuant to which the customer pays for the initial product development plus a license fee for the use of Trust Stamp’s technologies on a periodic and/or volume-based basis. In addition to consuming and paying for Trust Stamp’s services for their own use, some key customers also serve as channel partners by offering Trust Stamp products to their own customer base, whether as stand-alone products, or integrated into their own services as upgraded product offerings.
SaaS Agreements
7
Table of Contents
Software-as-a-Service ("SaaS") agreements are typically serviced through the Company’s Orchestration Layer platform, which is being utilized in new global identity authentication system with Fidelity Information Services, LLC ("FIS"). The platform includes our proprietary tokenization technology and is designed to provide easy integration with and access to, Trust Stamp’s products, chargeable on a per-use basis. The Orchestration Layer facilitates no-code and low-code implementations, making adoption faster and even more cost-effective for a broader range of potential customers. It is expected to accelerate the Company’s evolution, from being exclusively a custom solutions provider, to also offering a modular and highly scalable SaaS model with low-code implementation.
Competition
We can potentially work with any identity data from any source, potentially breaking vendor and modality lock-in, but our primary market target is the biometric service industry, which is growing exponentially while being threatened by a consumer, media, and legislative backlash against storing biometric data. The IT2 can potentially be overlaid on any biometric or other identity data provider.
In general, we compete for customer budget with any company in the identity authentication industry. Major competitors in this space include companies such as NEXT Biometrics, IDEMIA, Synaptics, Cognitec, Innovatrics, Suprema, FaceTec, Rank One Computing, Acuant, Jumio, Onfido, Ping, and Mitek. However, we believe that, due to the uniqueness of our technology solution, the Company does not currently have any direct competitors for the core IT2 solutions upon which the growth in our business plan is focused.
The commercial advantage of our solution is our ability to work across providers and modalities and we continue to pursue a first-mover advantage including our global–scale partnership which is achieving a network effect in the global Humanitarian and Development market. We believe that this combination will make it unattractive for a potential competitor to replicate the six-years and multi-million dollars that we have already expended, to try and circumvent our multiple (and continuing) patent filings and/or offer a parallel product based upon a different technology.
We believe that given sufficient time and resources, we can augment any biometric modalities including face, hand, iris, voice, gait, and behavior, together with any other identifying data which places us in a unique position versus providers of biometric services.
We are unaware of any other provider being able to offer or support a proliferation of authentication modalities in this fashion, and therefore we believe there are no other companies that directly compete with us in this space. If our go-to-market strategy is successful, biometric service providers can be channel distributors, and not necessarily competitors.
Growth Strategy
Our strategy is to:
•Expand the scope and range of services that we provide to and through our existing clients.
•Continue to add significant new clients for our current and future services.
•Offer our services via channel partners with substantial distribution networks.
•Offer our technology on a “low code” basis, providing access via an orchestration layer and/or open-APIs to enable implementation by a broader range of clients.
•The addition of alternate authentication tools including non-facial-biometric options and non-biometric-knowledge and device-based tools facilitating two and multi-factor authentication.
•Offer our IT2 technology for use by other biometric and data services providers to protect and extend the usability of their data.
•Provide ready-to-use / customizable platforms that leverage our IT2 technology in specialized markets.
Human Capital
Given the geographic diversity of its team, and to facilitate cost-effective administration, Trust Stamp secures the services of its permanent team members through a variety of administrative structures that include wholly owned subsidiaries, professional employer organizations, and consulting contracts. As of December 31, 2024, the Company had 7 full-time and 2 part-time team members that work out of the United States, 25 full-time members that work out of Malta, 10 full-time
8
Table of Contents
team members in Poland and Central Europe, 1 full-time and 1 part-time team members in the United Kingdom, 1 full-time team member in the Isle of Man, 14 full-time team members and 2 part-time team members working in the Philippines, 11 full-time team members working in Rwanda, 2 full-time team members in Denmark, and 1 full-time team member working in India. Our permanent team is augmented as needed by contract development and other staff on both a long and short-term basis.
Outsourcing
We design and develop our own products. We use an outsourcing company, 10Clouds, for additional development staff as needed. 10Clouds is considered a related party. In addition, we also utilize SourceFit, a company in the Philippines, for PEO services, representing approximately 2% of our operating expenses during the year ended December 31, 2024. Amazon Web Services provides cloud hosting and processing services, representing approximately 4% of our operating expenses during the year ended December 31, 2024.
Key Customers
The Company’s initial business consisted of developing proprietary privacy-first identity solutions and implementing them through custom applications built and maintained for a few key customers. In the fourth quarter of 2022, the Company added to its product offerings a modular SaaS model intended for low-code or no implementation (“the Orchestration Layer”). The Orchestration Layer has been successful in attracting interested customers with over sixty financial institutions onboarded as of the date of this report, but those institutions have been slow to go into full production which has impacted revenue expectations. An analysis of the slow adoption revealed that many of the institutions would need some level of customization and in fourth quarter of 2024 and first quarter of 2025 the company has invested in modification of the modules to meet the broader range of needs and preferences identified by the enrolled institutions. Orchestration Layer 2.0 will be “relaunched” in the second quarter of 2025.
Historically, the Company generated most of its income through two long-term partnerships, comprising a relationship with an S&P 500 bank with services provided pursuant to a Master Software Agreement entered into in 2017, together with a relationship with Mastercard International (“Mastercard”) with services provided under the terms of a ten-year technology services agreement entered into in March 2019 (the "TSA”). Both of those relationships remain strong, and the Company anticipates future revenue growth from the two relationships.
Under the TSA, IT2 TM technology is being implemented by Mastercard for Humanitarian & Development purposes as a core element of its Community Pass and Inclusive Identity offerings. Use cases include not only financial services for individuals and businesses but also empowering people and communities to meet basic needs, such as nutritious food, clean water, housing, education, and healthcare. The Company is paid to develop and host software solutions utilizing the IT2 and to support Mastercard’s implementations. In addition, the Company is paid on a “per user per year” basis for all transactions utilizing its technology. In December of 2022, the Company entered into a modification of the agreed pricing schedule with Mastercard to move from a per-use to a per-user-year model to broaden the range of potential use cases. The TSA may be terminated by either party in the event of a material breach by the other party that remains uncured within thirty days after notice is received of such a breach. Either party may terminate the TSA if the other party becomes, including, but not limited to, insolvent, subject to bankruptcy, dissolved, or liquidated. Unless the TSA is terminated, the TSA will automatically renew for additional one year-periods in perpetuity unless either party provides ninety days written notice of intent not to renew. To date, the Company has received guaranteed minimum annual payments on account of usage. According to the October 2023 interview of Mastercard Executive Vice President and Founder of the Community Pass from the article titled “Mastercard’s Community Pass founder says digital ID platform improving lives, digital inclusion” published by Biometric Update. Mastercard’s Community Pass program currently serves approximately 3.5 million users and is targeting 30 million users by 2027.
In 2022, the Company expanded its key customer base to include a relationship with FIS, a relationship-focused upon the implementation of our Orchestration Layer and underlying technologies in FIS’ Global KYC product offering.
The Orchestration Layer is a low-code platform that is designed to be a one-stop shop for Trust Stamp services and provides easy integration to our products; chargeable on a per-use basis. The Orchestration Layer utilizes the Company’s next-generation identity package, offering rapid deployment across devices and platforms, with custom workflows that seamlessly orchestrate trust across the identity lifecycle for a consistent user experience in processes for onboarding and KYC/AML, multi-factor authentication, account recovery, fraud prevention, compliance, and more. The Orchestration
9
Table of Contents
Layer facilitates no-code and low-code implementations of the Company’s technology making adoption and updating faster and cost-effective for a broader range of potential customers.
As of December 31, 2024, a total of 66 financial institutions with over $348 billion in assets have been onboarded via FIS, bringing the total number of (FIS and non-FIS) customers either fully implemented or are currently implementing the Orchestration Layer to 79. The first (non-FIS) client onboarded to the Orchestration Layer in the third quarter of 2022 has generated $426 thousand of revenue for the Company to date including $193 thousand during the year ended December 31, 2024.
Regulation
Our business is not currently subject to any licensing requirements in any jurisdiction in which we operate, other than the requirement to hold a business license in the City of Atlanta (with which we are in compliance), and the requirement to hold a trading license in Rwanda (with which we are in compliance). Given the significant focus on the use of biometrics in many countries, we do anticipate additional regulation being introduced in one or more jurisdictions in which we operate, and such requirements could be burdensome and/or expensive or even impose requirements that we are unable to meet.
We are subject to substantial governmental regulation relating to our technology and will continue to be for the lifetime of our Company. By virtue of handling sensitive PII and biometric data, we are subject to numerous statutes related to data privacy, and additional legislation and given the current focus on the collection, storage, and use of biometrics, additional regulation should be anticipated in every jurisdiction in which we operate. Examples of regulations we could be subject to are:
•Health Insurance Portability and Accountability Act (HIPAA)
•Health Information Technology for Economic and Clinical Health Act (HITECH)
•The General Data Protection Regulation 2016/679 (GDPR)
•ePrivacy Privacy Directive
•The California Privacy Rights Act (CPRA)
•The California Consumer Privacy Act (CCPA)
•Biometric Information Privacy Act (BIPA)
•Act on the Protection of Personal Information (APPI)
•United Kingdom General Data Protection Regulation (UK GDPR)
HIPAA and HITECH
Under the administrative simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act “HITECH”), the U.S. Department of Health and Human Services (“HHS”) issued regulations that establish uniform standards governing the conduct of certain electronic healthcare transactions and requirements for protecting the privacy and security of protected health information (“PHI”), used or disclosed by covered entities and business associates. Covered entities and business associates are subject to HIPAA and HITECH. Our subcontractors that create, receive, maintain, transmit, or otherwise process PHI on behalf of us are HIPAA “business associates” and must also comply with HIPAA as a business associate.
HIPAA and HITECH include privacy and security rules, breach notification requirements, and electronic transaction standards.
The privacy rules cover the use and disclosure of PHI by covered entities and business associates. The privacy rules generally prohibit the use or disclosure of PHI, except as permitted under certain limited circumstances. The privacy rules also set forth individual patient rights, such as the right to access or amend certain records containing his or her PHI, or to request restrictions on the use or disclosure of his or her PHI.
The security rules require covered entities and business associates to safeguard the confidentiality, integrity, and availability of electronically transmitted or stored PHI by implementing administrative, physical, and technical safeguards. Under HITECH’s Breach Notification Rule, a covered entity must notify individuals, the Secretary of the HHS, and in some circumstances, the media of breaches of unsecured PHI.
10
Table of Contents
In addition, we may be subject to state health information privacy and data breach notification laws, which may govern the collection, use, disclosure, and protection of health-related and other personal information. State laws may be more stringent, broader in scope, or offer greater individual rights with respect to PHI than HIPAA, and state laws may differ from each other, which may complicate compliance efforts.
Entities that are found to be in violation of HIPAA as the result of a failure to secure PHI, a complaint about our privacy practices, or an audit by HHS, may be subject to significant civil and criminal fines and penalties and additional reporting and oversight obligations if such entities are required to enter into a resolution agreement and corrective action plan with HHS to settle allegations of HIPAA non-compliance.
GDPR
The European Union's General Data Protection Regulation ("GDPR") imposes onerous accountability obligations requiring data controllers and processors to maintain a record of their data processing and policies. It requires data controllers to implement more stringent operational requirements for processors and controllers of personal data, including, for example, transparent and expanded disclosure to data subjects (in a concise, intelligible, and easily accessible form) about how their personal information is being used, imposes limitations on retention of information, increases requirements pertaining to health data and pseudonymized (i.e., key-coded) data, introduces mandatory data breach notification requirements, and sets higher standards for data controllers to demonstrate that they have obtained valid consent for certain data processing activities. Fines for non-compliance with the GDPR will be significant—the greater of €20 million or 4% of global turnover. The GDPR provides that European Union member states may introduce further conditions, including limitations, to make their own further laws and regulations limiting the processing of genetic, biometric, or health data.
ePrivacy Directive
The ePrivacy directive sets out the rules relating to the processing of personal data across public communications networks. This directive requires businesses to ensure consent requests are made and that consent is received from the user before the use of cookies is made. Businesses must communicate the privacy rules with accurate and specific information regarding the data contained in the cookie. Information must be communicated before the consent requests are made, in plain language. Organizations must ensure that users are able to withdraw consent in the same simple manner as the initial consent request.
CPRA and CCPA
The California Privacy Rights Act ("CPRA") and the California Consumer Privacy Act ("CCPA") define and establish various rights that consumers residing in California have over the privacy of their data along with the responsibilities of businesses when collecting personal information. It requires businesses that control the collection of consumers’ personal information to inform them of the category, purpose, and duration the business intends to retain such information. It lists the consumers’ right to correct their data and have their data deleted. Customers may also exercise their right to limit the sale or sharing of their personal or sensitive personal information. Fines for non-compliance can range from $100 to $750 per consumer per incident. Additionally, in certain cases, the California Privacy Protection Agency may impose administrative fines ranging from $2,500 to $7,500 for each violation.
BIPA
The Biometric Information Privacy Act ("BIPA"), which was enacted in 2008, addresses the collection, use, and retention of biometric information by private entities. Under the law, a private entity must inform an individual, or their legally authorized individual, that the biometric information is being collected and stored, and the specific purpose and the length of time for the collection, storage, and use of the biometric information, before obtaining or possessing their biometric information for the purposes of capturing, storing or sharing it. In addition, prior to collecting any biometric information, the regulation required businesses to obtain a written release for the collection of the biometric information from the individual, or the individual’s legally authorized representative after notice has been given. BIPA provides statutory damages of up to $1,000 for each negligent violation, and up to $5,000 for each intentional or reckless violation.
APPI
The Act on the Protection of Personal Information (APPI) is Japan’s primary data protection law, first enacted in 2003 and significantly amended in 2016 and 2020 to align with global standards like the EU’s GDPR. It applies to businesses
11
Table of Contents
handling personal data, regardless of nationality or residency. The APPI defines personal data as any information that can identify an individual and classifies sensitive data to include details such as race, medical history, and criminal records. While consent is generally required for data collection, other legal bases exist, such as contractual necessity or compliance with legal obligations. Individuals are granted rights to access, correct, delete, and cease the use of their personal data. The Personal Information Protection Commission (PPC) enforces compliance, though penalties under the APPI are lower than those under GDPR, with a maximum fine of JPY 1 million.
UK GDPR
The United Kingdom General Data Protection Regulation (UK GDPR) applies to all organizations processing personal data of UK residents, regardless of where the organization is based. It defines personal data as any information that can identify an individual and includes special categories of sensitive data, such as health, race, and biometric data. Businesses must have a legal basis for processing data, such as consent, contractual necessity, or legal obligation. Individuals have rights over their data, including access, correction, deletion (right to be forgotten), and data portability. The Information Commissioner's Office (ICO) oversees compliance and can impose severe fines for breaches, reaching up to £17.5 million or 4% of global turnover. The UK also has additional rules for law enforcement and national security-related data processing.
Intellectual Property
Patents
A summary of the Company’s issued patents and pending patent applications on March 31, 2025 is provided in the table below.
12
Table of Contents
13
Table of Contents
14
Table of Contents
15
Table of Contents
Trademarks
The following is a summary of Trust Stamp’s issued and pending Trademarks as of March 31, 2025.
Serial / Registration Number Filing Date Trademark Country Status
16
Table of Contents
The Company added 6 patents and 1 trademark during the year ended December 31, 2024. The patents issued during the year ended December 31, 2024 increased our total number of patents to 23 and include:
•On January 2, 2024, the Company received Notice of Issuance for a patent that is a continuation of “Systems and Processes for Lossy Biometric Representation.” This patent is a continuation addresses a long-felt but unresolved need for a system or process that can transform size-variant, personally-identifying biometric templates into fixed-size, privacy-secured representations, while maintaining sufficiently accurate biometric matching capabilities.
•On January 30, 2024, the Company received Notice of Issuance for a patent that is a continuation of “Systems and Processes for Lossy Biometric Representation.” This technology provides a system or process that can transform size-variant, personally-identifying biometric templates into fixed-size, privacy-secured representations, while maintaining sufficiently accurate biometric matching capabilities.
•On March 19, 2024, the Company received Notice of Issuance for a patent entitled “Systems and Methods for Enhanced Hash Transforms.” Conventional cryptographic hashing techniques generally include functions that generate unique signatures given a piece of data, accepting binary strings of characters as an input, and producing a string (e.g., a digital signature) as an output. Our new patent addresses the need for improved techniques for securely handling sensitive data.
•On April 23, 2024, the Company received Notice of Issuance for a patent entitled “Face Cover-compatible Biometrics and Processes for Generating and Using Same.” which allows for enrollment of biometric information from individuals wearing face coverings such that subsequent biometric identification and verification processes may not require the individuals to remove their face coverings.
•On April 30, 2024, the Company received Notice of Issuance for a patent entitled “Systems and Methods for Liveness-verified, Biometric-based Encryption.” This patent fulfills a long-felt but unresolved need for a system or method that permits encryption/decryption based on liveness-verified biometric data that cannot be stolen or spoofed.
•On September 3, 2024, the Company received Notice of Issuance by the US Patent of Trademark Office of Patent No. 17/719,975 entitled, “Personal Identifiable Information Encoder." This technology provides the means to maintain the essential utility of PII without storing highly sensitive data. Anyone processing or storing PII should embrace this technology to fulfill their data protection obligations and mitigate damage and losses in the event of a data breach.”
17
Table of Contents
Subsidiaries and Affiliates
Given the geographic diversity of our team and to facilitate cost-effective administration, Trust Stamp conducts various aspects of its operations through subsidiaries. All subsidiaries share resources across the entire Trust Stamp organization. The officers and directors of Trust Stamp have influence over the operations of all subsidiaries and employees across jurisdictions. Only one of our subsidiaries, Biometric Innovations Limited, has its own management team.
T Stamp Inc. Corporate Structure Chart
Operational Subsidiaries
Biometric Innovations Limited. (formerly “Trust Stamp Fintech Limited”). Biometric Innovations Limited is our Company’s United Kingdom ("UK") operating subsidiary. It was established to act as the contracting entity for development contractors in the UK, and it has its own board and management team. The purpose of this entity was to establish beachhead operations in the country to service a contract entered by the Company with the National Association of Realtors and Property Mark. This entity serves as a sales and marketing function for the product “NAEA” which was developed for the contract between the listed parties. On June 11, 2020, the Company entered into a stock exchange transaction with Biometric Innovations Limited, becoming a 100% owner of the entity. The stock exchange transaction was not pursuant to any formal written agreement.
Trust Stamp Malta Limited. Trust Stamp Malta Limited is a wholly owned subsidiary of T Stamp Inc. It operates an R&D campus in the Republic of Malta, for which it has entered into a lease with a local commercial landlord in Malta, Vassallo Group Realty Ltd. The goal of Trust Stamp Malta Limited is to advance our biometric authentication technology. As part of the creation of this entity, we entered into an agreement with the government of Republic of Malta for a repayable advance of up to €800,000 to cover 75% of the first 24 months of payroll costs for any employee who begins 36 months from the execution of the agreement on July 8, 2020.
Trust Stamp Rwanda Limited. Trust Stamp Malta Limited established Trust Stamp Rwanda Limited and in April 2021 opened an office in Kigali, Rwanda. It operates as an R&D campus together with a back-office facility for the purpose of the Company's expansion into Africa.
Trust Stamp Denmark ApS. Trust Stamp established Trust Stamp Denmark ApS on June 6, 2021 as a wholly owned subsidiary in Copenhagen, Denmark. Trust Stamp Denmark ApS focuses on developing and marketing GDPR compliant products in the European Union from a strategic Danish base that can passport authorized products throughout the European Union. In furtherance of that goal, Trust Stamp Denmark ApS has obtained D-Seal Certification.
Quantum Foundation.Trust Stamp Malta Limited established Quantum Foundation on October 13, 2022 as a wholly-owned subsidiary in the Republic of Malta. The purpose of the entity is to support the development of early-stage leading edge technology companies in the Republic of Malta.
18
Table of Contents
Non-Operational Subsidiaries
Tstamp Incentive Holdings. On April 9, 2019, management created a new entity, Tstamp Incentive Holdings (“TSIH”) to which the Company issued 21,368 shares of Class A Common Stock that the Board of Directors of TSIH could use for employee stock awards in the future. The purpose of the entity was to provide an analogous structure to a traditional stock incentive plan. As of December 31, 2024 and the date of this report, no shares of Class A Common Stock are held by TSIH as all shares have been issued pursuant to employee Restricted Stock Units. The Company has completed the process of administratively dissolving TSIH with the dissolution was effective February 13, 2025.
Trusted Mail Inc. The Company established Trusted Mail Inc. for development of an encrypted e-mail product (Trusted Mail ®) using the Company’s facial recognition technology. Trusted Mail technology is held by Trusted Mail, Inc., which is a majority-owned subsidiary of Trust Stamp Inc.. The remainder of Trust Mail Inc. is owned by FSH Capital, LLC and Second Century Ventures, which are related parties of the Company. As of the date of this report, this entity has no operations, and is essentially dormant.
Cheltenham AI LTD. The Company established Chelthenham AI LTD on July 29, 2019 as a UK private limited company to provide AI services in the UK. As of the date of this report, this entity has no operations and is essentially dormant.
Finnovation LLC. The Company established Finnovation LLC to provide an innovative FinTech, Blockchain and Digital Identity innovation incubator. As of the date of this report, this entity has no operations and is essentially dormant.
TSI GovTech Corporation. Trust Stamp established TSI GovTech Corporation to contract for data management and server operations in Canada. As of the date of this report, this entity has no operations and is essentially dormant.
Global Server Management Inc. The Company established Global Server Management Inc. to contract for data management and server operations in Canada. As of the date of this report, this entity has no operations and is essentially dormant.
Trust Stamp Nigeria Limited. Trust Stamp Malta Limited established Trust Stamp Nigeria Limited on January 31, 2024 as a wholly-owned subsidiary in Lagos, Nigeria. The establishment of the entity is aimed at exploring business opportunities and conducting operations in Nigeria. As of the date of this report, this entity has no operations and is essentially dormant.
Available Information
Our website is www.truststamp.ai. As soon as reasonably practicable after such material is electronically filed or furnished to the Securities and Exchange Commission ("SEC"), our annual reports, quarterly reports, and current reports on form 8-K and all amendments to those reports are available on this website, free of charge.
Alternatively, you may access these reports at the SEC’s website at www.sec.gov.
Item 1A. Risk Factors
The SEC requires the Company to identify risks that are specific to its business and its financial condition. The Company is still subject to all the same risks as companies in its business, and all companies in the economy. These include risks relating to economic downturns, political and economic events, and technological developments (such as cyber-attacks and the ability to prevent such attacks). Additionally, early-stage companies are inherently riskier than more developed companies, and the risk of business failure and complete loss of your investment capital is present. You should consider general risks as well as specific risks when deciding whether to invest.
Below is a summary of material risks, uncertainties and other factors that could have a material effect on the Company and its operations:
•We are a comparatively early-stage company that has incurred operating losses in the past, expect to incur operating losses in the future, and may never achieve or maintain profitability.
•Our technology continues to be developed, and there is no guarantee that we will ever successfully develop the technology that is essential to our business to a point at which no further development is needed.
•We may be subject to numerous data protection requirements and regulations.
19
Table of Contents
•We operate in a highly competitive industry that is dominated by a number of exceptionally large, well-capitalized market leaders and the size and resources of some of our competitors may allow them to compete more effectively than we can.
•We rely on third parties to provide services essential to the success of our business.
•We currently have three customers that account for substantially all of our revenues.
•We expect to raise additional capital through equity and/or debt offerings to support our working capital requirements and operating losses.
•Our auditor has included an “Emphasis of Matter Regarding Liquidity” note in its report on our consolidated financial statements for the year ended December 31, 2024. Our consolidated financial statements do not include any adjustments that may result from the outcome of this uncertainty.
•As the vast majority of our revenue is US Dollar denominated and a significant percentage of our expenses are incurred in other currencies, we are subject to risks relating to foreign currency fluctuations.
Risks Related to Our Company
We have a limited operating history upon which you can evaluate our performance and have not yet generated profits. Accordingly, our prospects must be considered in light of the risks that any new company encounters. Our Company was incorporated under the laws of the State of Delaware on April 11, 2016, and we have not yet generated profits. The likelihood of our creation of a viable business must be considered in light of the problems, expenses, difficulties, complications, and delays frequently encountered in connection with the growth of a business, operation in a competitive industry, and the continued development of our technology and products. We anticipate that our operating expenses will increase for the near future, and there is no assurance that we will be profitable in the near future. You should consider our business, operations, and prospects in light of the risks, expenses and challenges faced as an emerging growth company.
We have historically operated at a loss, which has resulted in an accumulated deficit. For the fiscal year ended December 31, 2024, we incurred a net loss of $12.54 million, compared to a net loss of $7.64 million for the fiscal year ended December 31, 2023. There can be no assurance that we will ever achieve profitability. Even if we do, there can be no assurance that we will be able to maintain or increase profitability on a quarterly or annual basis. Failure to do so would continue to have a material adverse effect on our accumulated deficit, would affect our cash flows, would affect our efforts to raise capital and is likely to result in a decline in our Class A Common Stock price.
Our consolidated financial statements for the fiscal year ended December 31, 2024 have been prepared on a going concern basis. We have not yet generated profits and have an accumulated deficit of $61.46 million as of December 31, 2024. We may not have enough funds to sustain the business until it becomes profitable. Even if we raise additional funding through future financing efforts, we may not accurately anticipate how quickly we may use such funds and whether such funds would be sufficient to bring the business to profitability. The Company’s ability to continue as a going concern in the next twelve months following the date of the consolidated financial statements is dependent upon its ability to produce revenues and/or obtain financing sufficient to meet current and future obligations and deploy such to produce profitable operating results.
Our cash could be adversely affected if the financial institutions in which we hold our cash fail. The Company maintains domestic cash deposits in Federal Deposit Insurance Corporation (“FDIC”) insured banks. The domestic bank deposit balances may exceed the FDIC insurance limits. In addition, given the foreign markets we serve, we maintain cash deposits in foreign banks, some of which are not insured or partially insured by the FDIC or other similar agency. These balances could be impacted if one or more of the financial institutions in which we deposit monies fails or is subject to other adverse conditions in the financial or credit markets.
Our technology continues to be developed, and it is unlikely that we will ever develop our technology to a point at which no further development is required. Trust Stamp is developing complex technology that requires significant technical and regulatory expertise to develop, commercialize and update to meet evolving market and regulatory requirements. While we constantly monitor and adapt our products and technology as criminal methods of breaching cybersecurity advance, there is no guarantee we will consistently be able to develop technology that can effectively counteract such criminal efforts. If we are unable to successfully develop and commercialize our technology and products, it will significantly affect our viability as a company.
20
Table of Contents
If our security measures are breached or unauthorized access to individually identifiable biometric or other personally identifiable information is otherwise obtained, our reputation may be harmed, and we may incur significant liabilities. In the ordinary course of our business, we may collect and store sensitive data, including protected health information (“PHI”) and personally identifiable information (“PII”), that is owned or controlled by ourselves or our customers, and other parties. We communicate sensitive data, including patient data, electronically, and through relationships with multiple third-party vendors and their subcontractors. These applications and data encompass a wide variety of business-critical information, including research and development information, patient data, commercial information, and business and financial information. We face a number of risks relative to protecting this critical information, including loss of access risk, inappropriate use or disclosure, inappropriate modification, and the risk of our being unable to adequately monitor, audit, and modify our controls over our critical information. This risk extends to the third-party vendors and subcontractors we use to manage this sensitive data. As a custodian of this data, Trust Stamp therefore inherits responsibilities related to this data, exposing itself to potential threats. Data breaches occur at all levels of corporate sophistication (including at companies with significantly greater resources and security measures than our own) and the resulting fallout stemming from these breaches can be costly, time-consuming, and damaging to a company’s reputation. Further, data breaches need not occur from malicious attack or phishing only. Often, employee carelessness can result in sharing PII with a much wider audience than intended. Consequences of such data breaches could result in fines, litigation expenses, costs of implementing better systems, and the damage of negative publicity, all of which could have a material adverse effect on our business operations and financial condition.
We are subject to substantial governmental regulation relating to our technology and will continue to be for the lifetime of our Company. By virtue of handling sensitive PII and biometric data, we are subject to numerous statutes related to data privacy and additional legislation and regulation should be anticipated in every jurisdiction in which we operate. Examples of federal (US) and European statutes we could be subject to are:
•Health Insurance Portability and Accountability Act (HIPAA)
•Health Information Technology for Economic and Clinical Health Act (HITECH)
Any such access, breach, or other loss of information could result in legal claims or proceedings, liability under federal or state laws that protect the privacy of personal information under HIPAA and/or “HITECH”. Notice of breaches must be made to affected individuals, the Secretary of the Department of Health and Human Services (“HHS”), and for extensive breaches, notice may need to be made to the media or state attorneys general. Penalties for violations of these laws vary. For instance, penalties for failure to comply with a requirement of HIPAA and HITECH vary significantly, and include significant civil monetary penalties and, in certain circumstances, criminal penalties with fines up to $250,000 per violation and/or imprisonment. A person who knowingly obtains or discloses individually identifiable health information in violation of HIPAA may face a criminal penalty of up to $50,000 and up to one-year imprisonment. The criminal penalties increase if the wrongful conduct involves false pretenses or the intent to sell, transfer or use identifiable health information for commercial advantage, personal gain, or malicious harm.
Further, various states, such as California, have implemented similar privacy laws and regulations, such as the California Confidentiality of Medical Information Act, that impose restrictive requirements regulating the use and disclosure of health information and other personally identifiable information. Where state laws are more protective, we have to comply with the stricter provisions. In addition to fines and penalties imposed upon violators, some of these state laws also afford private rights of action to individuals who believe their personal information has been misused. California’s patient privacy laws, for example, provide for penalties of up to $250,000 and permit injured parties to sue for damages. The interplay of federal and state laws may be subject to varying interpretations by courts and government agencies, creating complex compliance issues for us and data we receive, use and share, potentially exposing us to additional expense, adverse publicity, and liability. Further, as regulatory focus on privacy issues continues to increase and laws and regulations concerning the protection of personal information expand and become more complex, these potential risks to our business could intensify. Changes in laws or regulations associated with the enhanced protection of certain types of sensitive data, such as PII or PHI, along with increased customer demands for enhanced data security infrastructure, could greatly increase our cost of providing our services, decrease demand for our services, reduce our revenues and/or subject us to additional liabilities.
Compliance with U.S. and international data protection laws and regulations could cause us to incur substantial costs or require us to change our business practices and compliance procedures in a manner adverse to our business. Moreover, complying with these various laws could require us to take on more onerous obligations in our contracts, restrict our ability to collect, use and disclose data, or in some cases, impact our ability to operate in certain jurisdictions. We rely on our customers to obtain valid and appropriate consents from data subjects whose biometric samples and data we process on
21
Table of Contents
such customers’ behalf. Given that we do not obtain direct consent from such data subjects and we do not audit our customers to ensure that they have obtained the necessary consents required by law, the failure of our customers to obtain consents that are in compliance with applicable law could result in our own non-compliance with privacy laws. Such failure to comply with U.S. and international data protection laws and regulations could result in government enforcement actions (which could include civil or criminal penalties), private litigation and/or adverse publicity and could negatively affect our operating results and business. Claims that we have violated individuals’ privacy rights, failed to comply with data protection laws, or breached our contractual obligations, even if we are not found liable, could be expensive and time consuming to defend, could result in adverse publicity and could have a material adverse effect on our business, financial condition and results of operations.
We anticipate sustaining operating losses for the foreseeable future. It is anticipated that we will sustain operating losses into 2025 as we continue with research and development, and strive to gain new customers for our technology and market share in our industry. Our ability to become profitable depends on our ability to expand our customer base, consisting of companies willing to license our technology. There can be no assurance that this will occur. Unanticipated problems and expenses are often encountered in offering new products which may impact whether the Company is successful. Furthermore, we may encounter substantial delays and unexpected expenses related to development, technological changes, marketing, regulatory requirements, and changes to such requirements or other unforeseen difficulties. There can be no assurance that we will ever become profitable. If the Company sustains losses over an extended period of time, it may be unable to continue in business.
If our products do not achieve broad acceptance both domestically and internationally, we will not be able to achieve our anticipated level of growth. Our revenues are derived from licensing our identity authentication solutions. We cannot accurately predict the future growth rate or the size of the market for our technology. The expansion of the market for our solutions depends on a number of factors, such as
•the cost, performance and reliability of our solutions and the products and services offered by our competitors;
•customers’ perceptions regarding the benefits of biometrics and other authentication solutions;
•public perceptions regarding the intrusiveness of these solutions and the manner in which organizations use biometric and other identity information collected;
•public perceptions regarding the confidentiality of private information;
•proposed or enacted legislation related to privacy of information;
•customers’ satisfaction with biometrics solutions; and
•marketing efforts and publicity regarding biometrics solutions.
Even if our technology gains wide market acceptance, our solutions may not adequately address market requirements and may not continue to gain market acceptance. If authentication solutions generally or our solutions specifically do not gain wide market acceptance, we may not be able to achieve our anticipated level of growth and our revenues and results of operations would suffer.
We operate in a highly competitive industry that is dominated by multiple very large, well-capitalized market leaders and is constantly evolving. New entrants to the market, existing competitor actions, or other changes in market dynamics could adversely impact us. The level of competition in the identity authentication industry is high, with multiple exceptionally large, well-capitalized competitors holding a majority share of the market. Currently, we are not aware of any direct competitors of the Company able to offer our main technological offering. Nonetheless, many of the companies in the identity authentication market have longer operating histories, larger customer bases, significantly greater financial, technological, sales, marketing, and other resources than we do. At any point, these companies may decide to devote their resources to creating a competing technology solution which will impact our ability to maintain or gain market share in this industry. Further, such companies will be able to respond more quickly than we can to new or changing opportunities, technologies, standards, or client requirements, more quickly develop new products or devote greater resources to the promotion and sale of their products and services than we can. Likewise, their greater capabilities in these areas may enable them to better withstand periodic downturns in the identity management solutions industry and compete more effectively on the basis of price and production. In addition, new companies may enter the markets in which we compete, further increasing competition in the identity management solutions industry.
We believe that our ability to compete successfully depends on a number of factors, including the type and quality of our products and the strength of our brand names, as well as many factors beyond our control. We may not be able to compete
22
Table of Contents
successfully against current or future competitors, and increased competition may result in price reductions, reduced profit margins, loss of market share and an inability to generate cash flows that are sufficient to maintain or expand the development and marketing of new products, any of which would adversely impact our results of operations and financial condition.
We face competition from companies with greater financial, technical, sales, marketing, and other resources, and, if we are unable to compete effectively with these competitors, our market share may decline, and our business could be harmed. We face competition from well established companies. Many of our competitors have longer operating histories, larger customer bases, significantly greater financial, technological, sales, marketing, and other resources than we do. As a result, our competitors may be able to respond more quickly than we can to new or changing opportunities, technologies, standards, or client requirements, more quickly develop new products or devote greater resources to the promotion and sale of their products and services than we can. Likewise, their greater capabilities in these areas may enable them to better withstand periodic downturns in the identity management solutions industry and compete more effectively on the basis of price and production. In addition, new companies may enter the markets in which we compete, further increasing competition in the identity management solutions industry.
We believe that our ability to compete successfully depends on a number of factors, including the type and quality of our products and the strength of our brand names, as well as many factors beyond our control. We may not be able to compete successfully against current or future competitors, and increased competition may result in price reductions, reduced profit margins, loss of market share and an inability to generate cash flows that are sufficient to maintain or expand the development and marketing of new products, any of which would adversely impact our results of operations and financial condition.
The Company may be unable to effectively protect its intellectual property. The Company has many issued patents related to its products and technology, and many pending patent applications as of the date of this report. There is no guarantee that the Company will ever be issued patents on the applications it has submitted. In addition, in order to control costs, we have filed patent applications only in the United States. This may result in our having limited or no protection in other jurisdictions. Our success depends to a significant degree upon the protection of our products and technology. If we are unable to secure patents for our products and technology, or are otherwise unsuccessful at protecting our technology, other companies with greater resources may copy our technology and/or products, or improve upon them, putting us at a disadvantage to our competitors.
Successful infringement claims against us could result in significant monetary liability or prevent us from selling some of our products. We believe our products and technology may be highly disruptive to a very large and growing market. Our competitors are well capitalized with significant intellectual property protection and resources and they (and/or patent trolls) may initiate infringement lawsuits against our Company. Such litigation could be expensive and could also prevent us from selling our products, which would significantly harm our ability to grow our business as planned.
Our failure to attract and retain highly qualified personnel in the future could harm our business. As the Company grows, it will be required to attract and retain additional qualified professionals, staff for research and development, regulatory professionals, sales and marketing professionals, accounting professionals, legal professionals, and finance experts. The Company may not be able to attract and retain qualified individuals for such positions, which will affect the Company’s ability to grow and expand its business.
We rely on third party service providers. Our third-party partners provide a variety of essential business functions, including hosting, contract labor, and others. It is possible that some of these third parties will fail to perform their services or will perform them in an unacceptable manner. If we encounter problems with one or more of these parties and they fail to perform to expectations, it could have a material adverse impact on the Company.
We currently have three customers that account for substantially all of our current revenues. During the Company’s technology stack development, we have focused on strong relationships with a number of significant partners and customers to guide the customer and product discovery process. As such, our historical financial results identify that for a number of years we generated substantially all of our revenue from those three customers.
In the opinion of our management, we would be able to continue operations without our current customers. However, the unanticipated loss of the Company’s current customers could have an adverse effect on the company’s financial position.
23
Table of Contents
We face risks related to distributing our products and services through channel partnerships, such as our partnership with FIS. When selling our products and services through indirect sales channels, such as through FIS, we are reliant on the efforts of those channel partners to successfully market and sell our products to end-customers. To the extent that FIS is unsuccessful at selling our products and services, our results of operations may suffer. Further, as of the date of this report, our only channel partnership is with FIS, which may increase the risk of harm to our Company if FIS is unsuccessful in selling our products and services. While we may seek to attract and retain additional indirect channel partners that will be able to market our products effectively and provide timely and cost-effective customer support and services, we may not succeed in doing so, and this could limit our ability to grow revenues and achieve profitability. Selling through channel partnerships is also a relatively new endeavor for us. Historically, we have generated a majority of sales through direct sales. Managing indirect sales channels may require more management attention than managing our direct sales force. If the indirect sales channels grow, management attention may be diverted, impairing our ability to execute other parts of our strategy.
We face risks related to our target customers. The majority of the customers that we are targeting are large organizations with complex and expansive operations. These kinds of companies often have long and often unpredictable enterprise sales cycles, which can result in significant time and effort to close a deal with those companies (and there is no guarantee that a deal will occur). This can make sales forecasting difficult for our Company, which can lead to operational challenges. For example, we often need to hire staff ahead of closing on a new client contract to be ready to perform if and when the contract closes. If we are unable to effectively forecast sales, we may incur unnecessary or avoidable expenses, or exhaust our cash reserves, which could have a material negative impact on our Company’s financial condition and results of operations.
Our future success is dependent on the continued service of our small management team. Seven directors and four executive officers provide leadership to Trust Stamp. Three of the directors are also executive officers. Our success is dependent on their ability to manage all aspects of our business effectively. Because we are relying on our small management team, we lack certain business development resources that may hurt our ability to grow our business. Any loss of key members of our executive team could have a negative impact on our ability to manage and grow our business effectively. We do not maintain a key person life insurance policy on any of the members of our senior management team. As a result, we would have no way to cover the financial loss if we were to lose the services of our directors or officers.
We expect to raise additional capital through equity and/or debt offerings to support our working capital requirements and operating losses. In order to fund future growth and development, the Company will likely need to raise additional funds in the future by offering shares of its Common or Preferred Stock and/or other classes of equity, or debt that convert into shares of Common or Preferred Stock, any of which offerings would dilute the ownership percentage of investors in this offering. In order to issue sufficient shares in this regard, we may be required to amend our certificate of incorporation to increase our authorized capital stock, which would require us to obtain consent of a majority of our shareholders. Furthermore, if the Company raises capital through debt, the holders of our debt would have priority over holders of Common and Preferred Stock and the Company may be required to accept terms that restrict its ability to incur more debt. We cannot assure you that the necessary funds will be available on a timely basis, on favorable terms, or at all, or that such funds if raised, would be sufficient. The level and timing of future expenditure will depend on a number of factors, many of which are outside our control. If we are not able to obtain additional capital on acceptable terms, or at all, we may be forced to curtail or abandon our growth plans, which could adversely impact the Company, its business, development, financial condition, operating results, or prospects.
We are subject to risks related to foreign currency exchange rates. We operate on a global basis. We have operations (through our subsidiaries and/or directly) in many foreign countries and territories, including, but not limited to, United Kingdom, Poland, Rwanda, Denmark, and the Republic of Malta. The translation from any currencies to United States Dollars for financial statement presentation resulted in a foreign currency loss of $5 thousand for the year ended December 31, 2024, and $0 loss for the year ended December 31, 2023. As of June 30, 2022, the Company determined that there was currently no intention to settle intercompany accounts in the foreseeable future; therefore, beginning in June 30, 2022, future fluctuations in foreign currencies between the Company and its subsidiaries are recorded to Accumulated other comprehensive income on the balance sheet instead of Other expense. The translation from any currencies to United States Dollars for financial statement presentation resulted in Accumulated other comprehensive income of $181 thousand as of December 31, 2024, and $140 thousand as of December 31, 2023. Foreign currency translation losses, coupled with varying inflation rates across the countries we operate in, could have a material adverse effect on our business.
We are an emerging growth company, and the reduced reporting requirements applicable to emerging growth companies could make our Class A Common Stock less attractive to investors. We are an emerging growth company, as
24
Table of Contents
defined in the Jumpstart Our Business Startups Act (the "JOBS Act"). For as long as we continue to be an emerging growth company, we may take advantage of exemptions from various reporting requirements that are applicable to other public companies that are not emerging growth companies, including not being required to comply with the auditor attestation requirements of Section 404 of the Sarbanes-Oxley Act of 2002, reduced disclosure obligations regarding executive compensation in our periodic reports and proxy statements, exemptions from the requirements of holding non-binding advisory votes on executive compensation and stockholder approval of any golden parachute payments not previously approved, and an exemption from compliance with the requirement of the PCAOB regarding the communication of critical audit matters in the auditor’s report on the consolidated financial statements. We could be an emerging growth company for up to five years following the year in which we completed our IPO, although circumstances could cause us to lose that status earlier. We will remain an emerging growth company until the earlier of (1) the last day of the fiscal year (a) following the fifth anniversary of the date of the closing of our IPO, (b) in which we have total annual gross revenue of at least $1.07 billion or (c) in which we are deemed to be a large accelerated filer, which requires the market value of our common stock that are held by non-affiliates to exceed $700.00 million as of the prior June 30th, and (2) the date on which we have issued more than $1.00 billion in non-convertible debt during the prior three-year period.
In addition, the JOBS Act provides that an emerging growth company can take advantage of an extended transition period for complying with new or revised accounting standards. This allows an emerging growth company to delay the adoption of certain accounting standards until those standards would otherwise apply to private companies. We have elected to use this extended transition period for complying with new or revised accounting standards that have different effective dates for public and private companies until the earlier of the date we (i) are no longer an emerging growth company or (ii) affirmatively and irrevocably opt out of the extended transition period provided in the JOBS Act. As a result, our consolidated financial statements may not be comparable to companies that comply with new or revised accounting pronouncements as of public company effective dates.
We cannot predict if investors will find our Class A Common Stock less attractive because we may rely on the reporting exemptions and the extended transition period for complying with new or revised accounting standards. If some investors find our Class A Common Stock less attractive as a result, there may be a less active trading market for our Class A Common Stock and our share price may be more volatile.
Our internal controls over financial reporting and our disclosure controls and procedures may not prevent all possible errors that could occur. Our management is responsible for establishing and maintaining adequate internal control over financial reporting to provide reasonable assurance regarding the reliability of our financial reporting and the preparation of financial statements for external purposes in accordance with accounting principles generally accepted in the United States of America (“U.S. GAAP”). Ensuring that we have adequate internal financial and accounting controls and procedures in place to produce accurate financial statements on a timely basis is a costly and time-consuming effort that needs to be re-evaluated frequently. Failure on our part to have effective internal financial and accounting controls would cause our financial reporting to be unreliable, could have a material adverse effect on our business, operating results, and financial condition, and could cause the trading price of our common stock to fall dramatically.
A control system, no matter how well designed and operated, can provide only reasonable, not absolute, assurance that the control system’s objectives will be satisfied. Internal control over financial reporting and disclosure controls and procedures are designed to give a reasonable assurance that they are effective to achieve their objectives. We cannot provide absolute assurance that all of our possible future control issues will be detected. These inherent limitations include the possibility that judgments in our decision making can be faulty, and that isolated breakdowns can occur because of simple human error or mistake. The design of our system of controls is based in part upon assumptions about the likelihood of future events, and there can be no assurance that any design will succeed absolutely in achieving our stated goals under all potential future or unforeseeable conditions. Because of the inherent limitations in a cost-effective control system, misstatements due to error could occur and not be detected. This and any future failures could cause investors to lose confidence in our reported financial information, which could have a negative impact on our financial condition and stock price.
In future periods, if the process required by Section 404 of the Sarbanes-Oxley Act reveals any material weaknesses or significant deficiencies, the correction of any such material weaknesses or significant deficiencies could require remedial measures which could be costly and time-consuming. In addition, in such a case, we may be unable to produce accurate financial statements on a timely basis. Any associated accounting restatement could create a significant strain on our internal resources and cause delays in our release of quarterly or annual financial results and the filing of related reports, increase our costs and cause management distraction. Any of the foregoing could cause investors to lose confidence in the
25
Table of Contents
reliability of our financial statements, which could cause the market price of our common stock to decline and make it more difficult for us to finance our operations and growth.
Management identified certain material weaknesses relating to corporate finance and accounting, resulting in the Company not maintaining effective internal controls over financial reporting as of the year ended December 31, 2024. Management identified certain material weaknesses relating to corporate finance and accounting, resulting in the Company not maintaining effective internal controls over financial reporting as of the year ended December 31, 2024. As a result, the Company has not maintained effective internal controls over financial reporting as required for a public company. The resulting material weakness relates to proper design and implementation of controls over management’s review of the Company’s accounting for and recording of complex equity transactions. The failure to establish effective internal controls left us without the ability to properly account for important transactions accurately, to reliably compile our financial information, and significantly impaired our ability to prevent error and detect fraud. In response to these identified material weaknesses, in the fourth quarter of 2024 and first quarter of 2025, the Company has established additional operational processes to prevent the incorrect recording of stock-based awards. Such additional operational processes that have been established relating to recording of complex equity transactions include, but are not limited to:
•Enhanced review with multiple layers for all equity transactions to ensure that the calculations are correct and match the terms in corresponding agreement.
•Augmented our existing resources with additional consultants to assist in the analysis and recording of complex accounting transactions.
•Implemented multiple tiers of checks and reviews between data entry in our internal records and the use of such data to calculate complex equity transaction entries for our financial statements.
The Company’s management recently implemented internal control processes adopted in response to the identified material weaknesses specifically related to complex equity transactions and believe the procedures will address the identified material weakness. However, the implemented and enhanced controls have not operated for a sufficient period of time to demonstrate that the material weakness was remediated as of the date of this report.
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Risk Management and Strategy
We review cybersecurity risk as part of our overall enterprise risk management program with a goal of ensuring that cybersecurity risk management remains a top priority in our business strategy and operations.
Our risk management strategy includes, among other elements:
•Identification: We aim to proactively identify sources of risk, areas of impact, and relevant events that could give rise to cybersecurity risks, such as changes to our infrastructure, service providers, or personnel.
•Assessment: We conduct periodic risk assessments to identify cybersecurity threats. We also conduct likelihood and impact assessments with the goal of identifying reasonably foreseeable internal and external risks, the likelihood and potential damage that could result from such risks, and the sufficiency of existing policies, procedures, systems, and safeguards in place to manage such risks.
•Management: Following our risk assessments, we design and implement reasonable safeguards to address any identified gaps in our existing processes and procedures.
We engage third parties, including consultants and auditors, to evaluate the effectiveness of our risk management program, control environment, and cybersecurity practices through security audits, penetration testing, and other engagements.
The Company's cybersecurity policies and procedures are fully integrated into its broader risk management framework, reflecting a holistic approach to cybersecurity risk management. Regular cybersecurity risk assessments are conducted to identify potential threats and vulnerabilities, with detailed mitigation strategies developed and implemented accordingly.
Trust Stamp has adopted an Information Security Incident Response Plan that establishes policy and protocol to follow in response to an information security incident or event impacting Trust Stamp. This policy applies to all Trust Stamp
26
Table of Contents
employees holding management responsibilities. Incidents are reported by users via various methods including verbally, email, or other methods. The Development Operations team via the Chief Technology Officer or Executive Vice President is the main point of contact for technical support issues. It is to be expected that potential security incidents will be raised through this channel.
The Company engages third-party cybersecurity assessments to ensure an objective evaluation of its cybersecurity stance, including the effectiveness of its risk management strategies.Oversight of cybersecurity risks posed by third-party service providers is systematically managed, ensuring that all external risks are identified and mitigated.
The Company did not have any material cybersecurity breaches during the year ended December 31, 2024.
Board of Director's Governance
The Board of Directors (the "Board") includes members with substantial cybersecurity expertise, ensuring informed oversight of cybersecurity risks.Documentation of the Board's involvement in cybersecurity oversight is maintained, highlighting the frequency and topics of discussions related to cybersecurity risks and incident response. The Board is regularly updated on cybersecurity risks and incidents through established reporting mechanisms, ensuring they are well-informed to make strategic decisions regarding the Company's cybersecurity posture.
Management's Governance
Management's roles and responsibilities in cybersecurity oversight are clearly defined, with specific committees or positions designated for managing cybersecurity risks. The day-to-day management of cybersecurity is the responsibility of the Chief Technology Officer who oversees our technology team. These include procedures for incident response and regular reporting of cybersecurity information to the Board of Directors (the "Board"), ensuring effective communication and oversight. Cybersecurity risk management is seamlessly integrated into the Company's overall business strategy and decision-making processes, demonstrating a proactive approach to managing cybersecurity risks.
The Company has established clear criteria for determining the materiality of cybersecurity incidents, which include assessing potential or actual financial impacts, reputational damage, and operational disruptions. Documented incidents are meticulously recorded, detailing their nature, scope, and financial implications, ensuring transparency and accountability. The timeliness of Form 8-K filings following material cybersecurity incidents is strictly adhered to, with a thorough process in place for documenting any reasons for delayed disclosures. This ensures compliance with SEC requirements and maintains stakeholder confidence in the Company's cybersecurity posture.
Item 2. Properties
The Company contracts for use of office space at 3017 Bolling Way NE, Floor 2, Atlanta, Georgia, 30305, United States of America, which serves as its corporate headquarters and primary operational hub. The Company also leases office space (through a subsidiary) in Malta, which primarily serves as a research and development space. The Company contracts for coworking arrangements in other office spaces (either directly or through its subsidiaries) in North Carolina, Denmark and Rwanda to support its dispersed workforce. Minimum lease commitments related to these agreements are described in Note 13 to the consolidated financial statements provided under Item 8 of this report. We believe our existing properties are in good condition and are sufficient and suitable for the conduct of our business.
Item 3. Legal Proceedings
From time to time, the Company may be involved in a variety of legal matters that arise in the normal course of business. The Company is not currently involved in any litigation, and its management is not aware of any pending or threatened legal actions relating to its intellectual property, conduct of its business activities, or otherwise. See “Risk Factors” for a summary of risks our Company may face in relation to litigation against our Company.
Item 4. Mine Safety Disclosures
Not applicable.
27
Table of Contents
PART II
Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
Common Stock
As of December 31, 2024 and 2023, our Class A Common Stock is traded on the Nasdaq Capital Market ("Nasdaq") under the symbol “IDAI”. Trust Stamp received approval from Nasdaq to have our Class A Common Stock listed on the Nasdaq Capital Market under the symbol “IDAI” with trading commencing on January 31, 2022.
Holders
As of March 28, 2025, there were approximately 2,746 registered holders of record of our Class A Common Stock and the last reported sale price of our Class A Common Stock on the Nasdaq was $1.98 per share on March 28, 2025.
The number of shares of our Class A Common Stock that are freely tradable as of March 28, 2025 was 1,819,690.
Performance Graph
We are a smaller reporting company, as defined by Rule 12b-2 of the Exchange Act and are not required to provide the information required under this item.
Dividend Policy
To date, we have not paid any dividends on our Class A Common Stock and do not anticipate paying any dividends in the foreseeable future. The declaration and payment of dividends on the Class A Common Stock is at the discretion of the Board and will depend on, among other things, our operating results, financial condition, capital requirements, contractual restrictions, or such other factors as the Board may deem relevant. We currently expect to use all available funds to finance the future development and expansion of our business.
Securities Authorized for Issuance Under Equity Compensation Plans
On April 9, 2019, management created a new entity, Tstamp Incentive Holdings (“TSIH”) to which the Company issued 21,368 shares of Class A Common Stock that the Board of Directors of TSIH could use for employee stock awards in the future. The purpose of the entity was to provide an analogous structure to a traditional stock incentive plan. As of December 31, 2024 and the date of this report, no shares of Class A Common Stock are held by TSIH as all shares have been issued pursuant to employee Restricted Stock Units. The Company has completed the process of administratively dissolving TSIH with the dissolution was effective February 13, 2025.
Executive Compensation Philosophy
The Board of Directors determines the compensation given to our executive officers in their sole discretion. The Board reserves the right to pay our executives or any future executives a salary, and/or issue them shares of Class A Common Stock issued in consideration for services rendered and/or to award incentive bonuses which are linked to our performance, as well as to the individual executive officer’s performance. This package may also include long-term stock-based compensation to certain executives, which is intended to align the performance of our executives with our long-term business strategies. Additionally, the Board of Directors has granted and reserves the right to grant performance-based equity awards in the future, if the Board of Directors in its sole determination believes such grants would be in our best interests.
Incentive Bonus
The Board of Directors may grant incentive bonuses to our executive officers and/or future executive officers in its sole discretion, if the Board believes such bonuses are in our best interest, after analyzing our current business objectives and growth, if any, and the amount of revenue we are able to generate each month, as revenue is a direct result of the actions and ability of such executives.
28
Table of Contents
Long-Term, Stock Based Compensation
In order to attract, retain and motivate executive talent necessary to support the Company's long-term business strategy we may award our executives and any future executives with long-term, stock-based compensation in the future, at the sole discretion of the Board.
Recent Sales of Unregistered Securities:
29
Table of Contents
*The share numbers in the table above reflect the shares issued after giving effect to both Reverse Splits, described in Note 1 to the consolidated financial statements provided under Item 8 of this report.
(1) On December 21, 2023, the 104,889 common stock purchase warrants to purchase shares of Class A Common Stock of the Company at a price of $20.10 per warrant were exercised for total proceeds of $2,108,262.
(2) On December 21, 2023, the 85,314 common stock purchase warrants to purchase shares of Class A Common Stock of the Company at a price of $20.10 per warrant were exercised for total proceeds of $1,714,798.
(3) On September 3, 2024, the 240,000 common stock purchase warrants to purchase shares of Class A Common Stock of the Company at a price of $4.8345 per warrant were exercised for total proceeds of $1,160,280.
(4) The warrants to purchase the 190,987 shares of the Company’s Class A Common Stock remain outstanding as of the date of this report.
(5) The warrants to purchase the 370,370 and 277,778 shares of Class A Common Stock remain outstanding as of the date of this report.
(6) The warrants to purchase the 414,202 and 207,101 shares of Class A Common Stock remain outstanding as of the date of this report.
Item 6. Reserved
30
Table of Contents
Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
The following discussion and analysis of our financial condition and results of operations should be read in conjunction with our consolidated financial statements and the accompanying notes thereto included elsewhere in this Annual Report on Form 10-K. This discussion contains forward-looking statements based upon current plans, expectations, and beliefs, involving risks and uncertainties. Our actual results may differ materially from those anticipated in these forward-looking statements. You should review the section titled “Statement Regarding Forward-Looking Statements” for a discussion of forward-looking statements and the section titled “Risk Factors” for a discussion of factors that could cause actual results to differ materially from the results described in or implied by the forward-looking statements contained in the following discussion and analysis and elsewhere in this Annual Report on Form 10-K. Our historical results are not necessarily indicative of the results that may be expected for any period in the future.
Overview
Trust Stamp was incorporated under the laws of the State of Delaware on April 11, 2016 as “T Stamp Inc.” T Stamp Inc. and its subsidiaries (“Trust Stamp”, “we”, or the “Company”) develop and market identity authentication software for enterprise and government partners and peer-to-peer markets.
Trust Stamp primarily develops proprietary artificial intelligence-powered solutions, researching and leveraging machine learning artificial intelligence, including computer vision, cryptography, and data mining, to process and protect data and deliver insightful outputs that identify and defend against fraud, protect sensitive user information, facilitate automated processes, and extend the reach of digital services through global accessibility. We utilize the power and agility of technologies such as GPU processing, edge computing, neural networks, and large language models to process and protect data faster and more effectively than historically possible to deliver results at a disruptively low cost for usage across multiple industries.
Our team has substantial expertise in the creation and development of AI-enabled software products. We license our technology and expertise in numerous fields, with an increasing emphasis on addressing diverse markets through established partners who will integrate our technology into field-specific applications.
Over the last 12 months, while maintaining our strong emphasis on identity authentication for financial services, the Company has undertaken a multi-pronged process to position itself better to leverage the growing opportunities offered by the expanded capabilities, use, and acceptance of AI technologies. This process has included:
• Reducing the size of the non-production-focused executive and consulting teams to reduce overhead.
•Releasing sales staff that did not meet their targets.
•Negotiating a services contract to offset the cost of the technical team members while maintaining significant R&D and product development capabilities.
•Refocusing go-to-market strategies on joint ventures with proven industry partners with access to target markets
•Expanding our IP portfolio to strengthen our existing position related to presentation attack detection and tokenization and include implementations such as:
i.Embedded ownership verification for cryptographic assets, a technology that we believe to have significant potential with the expansion in the ownership of crypto-assets including potential deregulation (or loosening or clarification of regulation) in the United States together with the global growth of stable coins including Central Government Digital Currencies.
ii.A simple user interaction utility called “Shape Overlay” that augments biometric verification and combats deepfakes and injection attacks by having the user interact in real-time with their captured image.
iii.Stable Key (or “Stable IT2”) which is an innovative technology that generates a “key” directly from the biometric of the user which key has a mathematical correlation to all of the user's passwords, PINS, and other “secrets” for every account and use case meaning that those secrets never need to be stored in their entirety.
iv.A patent for “Interoperable Biometric Representations” that potentially breaks vendor lock-in by allowing users of biometric technologies to compare like-modality templates from different sources.
31
Table of Contents
•Strengthening our international 3rd party cybersecurity and data handling certifications by adding SOC2 certification to our NCSC Cyberessentials Plus certification and obtaining a renewed D-Seal certification (the world’s first certification that includes not just data security but also the ethical and responsible use of data).
•Opening an office in Tokyo (with funding from the City of Tokyo and the Japanese government) to pursue opportunities in the APAC region.
•Retaining an investment bank to explore strategic partnership and M&A opportunities across multiple sectors.
Recent Developments
Equity Distribution Agreement with Maxim
On February 25, 2025, the Company entered into an Equity Distribution Agreement (the “Agreement”), with Maxim Group LLC (“Maxim”), pursuant to which the Company may offer and sell, from time to time, through Maxim, as sales agent or principal, shares of its common stock, $0.01 par value per share (the “Common Stock”).
Subject to the terms and conditions of the Agreement, Maxim will use commercially reasonable efforts consistent with its normal trading and sales practices, applicable state and federal law, rules and regulations and the rules of the Nasdaq Capital Market to sell shares of the Company’s Common Stock from time to time based upon the Company’s instructions, including any minimum price, time or size limits specified by the Company. Under the Agreement, Maxim may sell shares by any method deemed to be an “at the market” offering as defined in Rule 415 under the U.S. Securities Act of 1933, as amended (the “Securities Act”), or any other method permitted by law, including in privately negotiated transactions. Maxim’s obligations to sell shares under the Agreement are subject to satisfaction of certain conditions, including customary closing conditions for transactions of this nature. The Company will pay Maxim a commission of 3.0% of the aggregate gross proceeds from each sale of shares and has agreed to reimburse Maxim for certain specified expenses of up to $40,000, aggregate, in addition to up to $3,000 quarterly for the Maxim’s counsel’s fees and any incidental expenses to be reimbursed by us. We have agreed to provide indemnification and contribution to Maxim against certain civil liabilities, including liabilities under the Securities Act.
The Company is not obligated to make any sales of its Common Stock under the Agreement and no assurance can be given that the Company will sell any shares under the Agreement, or, if it does, as to the price or amount of shares that the Company will sell, or the dates on which any such sales will take place. The Agreement will terminate upon the earlier of (i) the sale of all shares having an aggregate offering price of $6,196,000 pursuant to the Agreement, (ii) twelve (12) months from the date of the Agreement, (iii) mutual termination by both Maxim and the Company upon the provision of fifteen (15) days written notice, and (iv) termination of the Agreement as otherwise permitted therein.
Sales of shares of Common Stock under the Agreement will be made pursuant to the Company’s effective registration statement on Form S-3 (Registration No. 333-271091) (the “Registration Statement”) which was declared effective April 12, 2023 and a related prospectus supplement which was filed with the U.S. Securities and Exchange Commission (the “SEC”) on February 25, 2025 (the “ATM Prospectus”). The ATM Prospectus relates to the offering of up to $6,196,000 worth of shares of the Company’s Common Stock from time to time. The issuance and sale, if any, of Common Stock under the Agreement is subject to the effectiveness of the Registration Statement and “baby shelf” limitations under General Instruction I.B.6. of Form S-3.
The foregoing summary of the Agreement does not purport to be complete and is qualified in its entirety by reference to the full text of the Agreement, which was filed as Exhibit 1.1 to the Company's Current Report on Form 8-K filed with the SEC on February 26, 2025.
Appointment of New Chief Financial Officer
On January 17, 2025, the Board of Directors of the Company appointed Lance Wilson as the Company’s new Chief Financial Officer ("CFO"), to fill the vacancy in the position left after Alex Valdes’s resignation as Chief Financial Officer effective January 2, 2025.
Lance Wilson, a licensed Certified Public Accountant in Georgia, first joined the Company in 2021, serving in various financial capacities, most recently as the Senior Vice President of Accounting & Finance at Trust Stamp from July 2024 until being appointed to his role as CFO. Lance leads all external financial reporting, including SEC filings and technical
32
Table of Contents
accounting research and implementation. Lance has played a key role in multiple initiatives, including a successful public fundraising campaign that resulted in Trust Stamp’s NASDAQ listing in January 2022.
Prior to joining Trust Stamp, Lance served as the Financial Reporting Manager at Cousins Properties (NYSE: CUZ) from July 2020 to July 2021, where he managed all SEC filings, technical accounting projects, and audit engagements. Prior to that, he served in various accounting roles at The North Highland Company, Change Healthcare (formerly McKesson Technology Solutions), and BDO-USA, LLC. Lance holds a Master of Accountancy degree and a Bachelor of Science in Commerce and Business Administration from The University of Alabama.
Lance Wilson has no family relationships with any other director, executive officer, or person nominated or chosen by the Company to become a director or executive officer.
Lance Wilson and the Company entered into an Executive Employment Agreement (the “Agreement”), with an effective date of January 1, 2025, for his role as Chief Financial Officer (CFO) of the Company. The Agreement outlines Mr. Wilson’s ongoing responsibilities, including oversight of the Company’s financial integrity, regulatory compliance, and multicurrency financial reporting. It also details his leadership in investor relations and compliance with applicable SEC, Nasdaq, and Sarbanes-Oxley requirements.
Under the Agreement, Mr. Wilson will receive an annual base salary of $182,250, subject to periodic review, and will be eligible for an annual equity bonus of at least 10% of his base salary in the form of restricted stock units. The Agreement also includes provisions for reimbursement of business expenses, participation in Company benefit plans, and relocation assistance if applicable.
The Agreement has an open-ended term, continuing until either party provides 120 days’ written notice of termination. It also specifies termination provisions, including compensation and benefits in the event of termination by the Company without cause or by Mr. Wilson for good reason, such as severance equal to up to 36 months of base salary and accelerated vesting of equity awards in certain circumstances, including a change in control. Termination for cause or voluntary resignation without good reason would result in payment of only accrued compensation and benefits through the termination date.
The Agreement contains customary confidentiality and non-disclosure provisions related to the Company’s trade secrets and other sensitive information.
The foregoing description of the Agreement is intended to be a summary, and is qualified in its entirety by reference to the Agreement itself, a copy of which was filed as Exhibit 10.1 to the Company's Current Report on Form 8-K filed with the SEC on January 21, 2025.
Securities Purchase Agreement dated January 6, 2025
On January 6, 2025, the Company entered into a securities purchase agreement (the “January 2025 SPA”) with an institutional investor (the “Selling Stockholder”), pursuant to which the Company agreed to issue and sell to the Selling Stockholder (i) in a registered direct offering, (a) 175,000 shares of Class A Common Stock (the “January 2025 Shares”); and (b) Pre-Funded Warrants (the "January 2025 Pre-Funded Warrants") to purchase 239,202 shares of the Company’s Class A Common Stock at an exercise price of $0.001 per share and (ii) in a concurrent private placement, common stock purchase warrants consisting of Series A common warrants exercisable for up to 414,202 shares of Class A Common Stock at an exercise price of $8.45 per share of Class A Common Stock (the “January 2025 Series A Warrants”), and Series B common warrants exercisable for up to 207,101 shares of Class A Common Stock at an exercise price of $8.45 per share (the “January 2025 Series B Warrants”, and collectively with the January 2025 Series A Warrants, the “January 2025 Private Placement Warrants”). The offering price per January 2025 Share and respective January 2025 Private Placement Warrants was $8.45, and the offering price per Pre-Funded Warrant was $8.449.
The securities to be issued in the registered direct offering were offered pursuant to the Company’s shelf registration statement on Form S-3 (File 333-271091) (the “Shelf Registration Statement”), initially filed by the Company with the SEC under the Securities Act on April 3, 2023 and declared effective on April 12, 2023. The January 2025 Pre-Funded Warrants are immediately exercisable upon issuance and will remain exercisable until all of the January 2025 Pre-Funded Warrants are exercised in full.
33
Table of Contents
The January 2025 Private Placement Warrants (and the shares of Class A Common Stock issuable upon the exercise of the January 2025 Private Placement Warrants) were not registered under the Securities Act, and were offered pursuant to an exemption from the registration requirements of the Securities Act provided under Section 4(a)(2) of the Securities Act and/or Rule 506 of Regulation D promulgated under the Securities Act.
The terms of the Series A and January 2025 Series B Warrants that comprise the January 2025 Private Placement Warrants are identical, except that the January 2025 Series A Warrants provide for additional protections for the Selling Stockholder in the event of a “Fundamental Transaction” while the January 2025 Series A Warrants are outstanding (which includes, but is not limited to, merger transactions or a sale of substantially all of the Company’s assets). In such an event, then if holders of the Company’s Common Stock are given any choice as to the securities, cash or property to be received in a Fundamental Transaction, then the Selling Stockholder will be given the same choice as to the consideration it receives upon any exercise of either the Series A or January 2025 Series B Warrants following such Fundamental Transaction. Notwithstanding anything to the contrary, for the January 2025 Series A Warrants, in the event of a Fundamental Transaction, the Selling Stockholder may require the Company or its successor to repurchase the January 2025 Series A Warrants for its Black-Scholes Value (as defined in the Series A Warrant) in cash. This right can be exercised concurrently with, or within 30 days following, the consummation or public announcement of the transaction. If the Fundamental Transaction occurs outside the Company’s control, such as in a hostile takeover or an unapproved transaction, the holder is entitled to receive consideration equivalent in type and proportion to that offered to common stockholders, also calculated based on the Black-Scholes model. Additionally, if no consideration is offered to the Company’s stockholders in the transaction, the holder is deemed to receive common stock of the successor entity, preserving the January 2025 Series A Warrants’ value.
The January 2025 Private Placement Warrants are immediately exercisable upon issuance, and will expire five years thereafter, and in certain circumstances may be exercised on a cashless basis. If we fail for any reason to deliver shares of Class A Common Stock upon the valid exercise of the January 2025 Private Placement Warrants, subject to our receipt of a valid exercise notice and the aggregate exercise price, by the time period set forth in the January 2025 Private Placement Warrants, we are required to pay the applicable holder, in cash, as liquidated damages as set forth in the January 2025 Private Placement Warrants. The January 2025 Pre-Funded Warrants and January 2025 Private Placement Warrants also include customary buy-in rights in the event we fail to deliver shares of common stock upon exercise thereof within the time periods set forth in the January 2025 Pre-Funded Warrants and January 2025 Private Placement Warrants.
On January 8, 2025, the Company closed the registered direct offering and the private placement offering (collectively, the “January 2025 Offering”), raising gross proceeds of approximately $3.50 million before deducting placement agent fees and other offering expenses payable by the Company. In the event that all January 2025 Private Placement Warrants are exercised for cash, the Company will receive additional gross proceeds of approximately $5,250,250. The Company’s primary use of the net proceeds will be for working capital, capital expenditures and other general corporate purposes.
Pursuant to the terms of the January 2025 SPA, the Company is required within 30 days of January 6, 2025 to file a registration statement on Form S-1 or other appropriate form if the Company is not then S-1 eligible registering the resale of the shares of Class A Common Stock issued and issuable upon the exercise of the January 2025 Private Placement Warrants. The Company is required to use commercially reasonable efforts to cause such registration to become effective within 91 days of the closing of the January 2025 Offering, and to keep the registration statement effective at all times until no investor owns any January 2025 Private Placement Warrants or shares issuable upon exercise thereof.
Pursuant to the terms of the January 2025 SPA, from January 6, 2025 until 30 days after closing, subject to certain exceptions, we may not issue, enter into any agreement to issue or announce the issuance or proposed issuance of any shares of common stock or common stock equivalents, or file any registration statement or any amendment or supplement thereto, other than a prospectus supplement for the Shelf Registration Statement. In addition, from January 6, 2025 until 45 days after closing, we are prohibited from effecting or entering into an agreement to effect any issuance of common stock or common stock equivalents involving a variable rate transaction (as defined in the January 2025 SPA).
The foregoing description of the January 2025 SPA, January 2025 Pre-Funded Warrants, January 2025 Series A Warrants, and January 2025 Series B Warrants is intended to be a summary, and is qualified by reference to the full text of each of these documents, which were filed as exhibits 10.1, 4.1, 4.2, and 4.3, respectively to the Company's Current Report on Form 8-K filed with the SEC on January 10, 2025.
34
Table of Contents
Securities Purchase Agreement dated December 5, 2024
On December 5, 2024, the Company entered into a securities purchase agreement (the “December 2024 SPA”) with an investor, pursuant to which the Company agreed to issue and sell to the Selling Stockholder (i) in a registered direct offering, (a) 139,000 shares of Class A Common Stock (the “December 2024 Shares”); and (b) Pre-Funded Warrants (the "December 2024 Pre-Funded Warrants") to purchase 231,370 shares of the Company’s Class A Common Stock at an exercise price of $0.015 per share and (ii) in a concurrent private placement, common stock purchase warrants consisting of Series A common warrants exercisable for up to 370,370 shares of Class A Common Stock at an exercise price of $8.10 per share of Class A Common Stock (the “December 2024 Series A Warrants”), and Series B common warrants exercisable for up to 277,778 shares of Class A Common Stock at an exercise price of $8.10 per share (the “December 2024 Series B Warrants”, and collectively with the December 2024 Series A Warrants, the “December 2024 Private Placement Warrants”). The offering price per December 2024 Share and respective December 2024 Private Placement Warrants was $8.10 and the offering price per December 2024 Pre-Funded Warrant was $8.09.
Pursuant to the December 2024 SPA, the Company agreed to hold an annual or special meeting of its stockholders within sixty (60) days following the closing date of the December 2024 SPA for the purpose of obtaining shareholder approval of (i) an increase in the number of authorized shares of the Company; and (ii) the December 2024 SPA and transactions contemplated thereunder (including, but not limited to, the issuance of the December 2024 Private Placement Warrants, and shares issuable upon the exercise of the December 2024 Private Placement Warrants) as may be required by the applicable rules and regulations of the Nasdaq Stock Market (“Shareholder Approval”). If the Company does not obtain Shareholder Approval at the first meeting, the Company must call a meeting every ninety (90) days thereafter to seek Shareholder Approval until the earlier of the date on which Shareholder Approval is obtained or the warrants are no longer outstanding.
The terms of the December 2024 Series A and Series B Warrants that comprise the December 2024 Private Placement Warrants are identical, except that the December 2024 Series A Warrants provide for additional protections for the Selling Stockholder in the event of a “Fundamental Transaction” while the December 2024 Series A Warrants are outstanding (which includes, but is not limited to, merger transactions or a sale of substantially all of the Company’s assets). In such an event, then if holders of the Company’s Common Stock are given any choice as to the securities, cash or property to be received in a Fundamental Transaction, then the Selling Stockholder will be given the same choice as to the consideration it receives upon any exercise of either the December 2024 Series A or Series B Warrants following such Fundamental Transaction. Notwithstanding anything to the contrary, for the December 2024 Series A Warrants, in the event of a Fundamental Transaction, the Selling Stockholder may require the Company or its successor to repurchase the December 2024 Series A Warrants for its Black-Scholes Value (as defined in the Series A Warrant) in cash. This right can be exercised concurrently with, or within 30 days following, the consummation or public announcement of the transaction. If the Fundamental Transaction occurs outside the Company’s control, such as in a hostile takeover or an unapproved transaction, the holder is entitled to receive consideration equivalent in type and proportion to that offered to common stockholders, also calculated based on the Black-Scholes model. Additionally, if no consideration is offered to the Company’s stockholders in the transaction, the holder is deemed to receive common stock of the successor entity, preserving the December 2024 Series A Warrants’ value.
The December 2024 Private Placement Warrants are immediately exercisable upon the date December 2024 Shareholder Approval is received, and will expire five years thereafter, and in certain circumstances may be exercised on a cashless basis. If we fail for any reason to deliver shares of Class A Common Stock upon the valid exercise of the December 2024 Private Placement Warrants, subject to our receipt of a valid exercise notice and the aggregate exercise price, by the time period set forth in the December 2024 Private Placement Warrants, we are required to pay the applicable holder, in cash, as liquidated damages as set forth in the December 2024 Private Placement Warrants. The December 2024 Pre-Funded Warrants and December 2024 Private Placement Warrants also include customary buy-in rights in the event we fail to deliver shares of common stock upon exercise thereof within the time periods set forth in the December 2024 Pre-Funded Warrants and December 2024 Private Placement Warrants.
The foregoing description of the December 2024 SPA, December 2024 Pre-Funded Warrants, December 2024 Series A Warrants, and December 2024 Series B Warrants is intended to be a summary, and is qualified by reference to the full text of each of these documents, which were filed as exhibits 10.1, 4.1, 4.2, and 4.3, respectively, to the Company's Current Report on Form 8-K filed with the SEC on December 6, 2024.
Amendment to Third Amended and Restated Certificate of Incorporation of the Company (Reverse Stock Split)
35
Table of Contents
On December 30, 2024, the Company filed a Certificate of Amendment to the Company’s Third Amended and Restated Certificate of Incorporation, which was previously approved by the Company’s stockholders at the special meeting held on November 18, 2024 and described in the Company’s definitive proxy statement filed with the SEC on September 30, 2024 to effectuate a reverse stock split at a ratio of one (1) share of Common Stock for every fifteen (15) shares of Common Stock (the “Reverse Stock Split”) which became effective as of the opening of business on January 6, 2024 (the “Effective Time”).
As a result, at the Effective Time, each fifteen (15) pre-split shares of Common Stock outstanding automatically combined into one (1) new share of Common Stock, and the number of outstanding shares of Common Stock were reduced from 28,984,426 to 1,933,990. Proportional adjustments have also been made to the number of shares of Common Stock issuable upon exercise or conversion of the Company’s outstanding equity awards, stock options, and warrants in existence as of the Effective Time, as well as the applicable exercise price(s) of such instruments.
The number of authorized shares of Common Stock and the par value of each share of Common Stock remain unchanged. No fractional shares were issued as a result of the Reverse Stock Split, and any fractional shares that would otherwise have resulted from the Reverse Stock Split were rounded up.
For more information regarding the Reverse Stock Split, see the definitive proxy statement filed by the Company with the Securities and Exchange Commission on September 30, 2024 and Form 8-K filed on November 21, 2024announcing the result of the stockholder vote, the relevant portions of which are incorporated herein by reference. The description of the Certificate of Amendment and the Reverse Stock Split is qualified in its entirety by reference to the full text of the Certificate of Amendment, a copy of which is included as Exhibit 3.1 to the Company's Current Report on Form 8-K filed with the SEC on January 2, 2025.
Results of Stockholder Special Meeting
On November 18, 2024, the Company held a Special Meeting of Stockholders (the “Special Meeting”) to consider and vote upon:
•Proposal 1: Ratification of the approval of that certain Securities Purchase Agreement dated July 13, 2024 between our Company and DQI Holdings, Inc. (the “July DQI SPA”) and all transactions contemplated thereunder, including, but not limited to, the sale of 306,514 shares of our Class A Common Stock, par value $0.01 per share to DQI as required by and in accordance with Nasdaq Listing Rule 5635(d)); and
•Proposal 2: Ratification of the approval of the issuance of certain warrants issued to the Selling Stockholder pursuant to a securities purchase agreement dated September 3, 2024 as required by and in accordance with Nasdaq Listing Rule 5635(d));
•Proposal 3: Approval of the issuance of certain warrants issued to the Selling Stockholder pursuant to a warrant exercise agreement also dated September 3, 2024 as required by and in accordance with Nasdaq Listing Rule 5635(d)); and
•Proposal 4: Approval a reverse stock split of our Common Stock at a ratio of not less than 1-for-5 and not more than 1-for-50, with such ratio to be determined by the Board of Directors on or prior to December 31, 2024, in its sole discretion, and which would be effected by filing a Certificate of Amendment to the Company’s Third Amended and Restated Certificate of Incorporation with the State of Delaware
At the Special Meeting, 44% of our Common Stock entitled to vote at the Special Meeting were represented in person or by proxy at the Special Meeting. Based on the results of the vote, the stockholders voted to approve Proposals 1, 2, 3 and 4. The number of votes cast for or withheld from the approval is also set forth below. The voting results disclosed below are final.
36
Table of Contents
For more information regarding the Reverse Stock Split, see the definitive proxy statement filed by the Company with the Securities and Exchange Commission on September 30, 2024 and Form 8-K filed on November 21, 2024 announcing the result of the stockholder vote, the relevant portions of which are incorporated herein by reference. The description of the Certificate of Amendment and the Reverse Stock Split is qualified in its entirety by reference to the full text of the Certificate of Amendment, a copy of which was filed as Exhibit 3.1 to the Company's Current Report on Form 8-K filed with the SEC on January 2, 2025.
Election of New Board Member
On November 2, 2024, the Board of Directors of the Company elected Andrew Scott Francis, the current Chief Technology Officer of the Company, to the Board of Directors, effective immediately, to fill a vacancy on the Board of Directors left from the resignation of Joshua Allen from the Company’s Board of Directors on September 26, 2024. Andrew Scott Francis will be a member of the “Class III” directors of the Company.
Key Business Measures
In addition to the measures presented in our consolidated financial statements, we use the following key non-GAAP business measures to help us evaluate our business, identify trends affecting our business, formulate business plans and financial projections, and make strategic decisions.
Adjusted EBITDA
This discussion includes information about Adjusted EBITDA that is not prepared in accordance with U.S. GAAP. Adjusted EBITDA is not based on any standardized methodology prescribed by U.S. GAAP and is not necessarily comparable to similar measures presented by other companies. A reconciliation of this non-GAAP measure is included below.
Adjusted EBITDA is a non-GAAP financial measure that represents U.S. GAAP net income (loss) adjusted to exclude (1) other expense, (2) other income, (3) gain on sale of mobile hardware, (4) interest expense, (5) interest income, (6) stock-based compensation, (7) change in fair value of warrant liabilities (8) impairment of assets, (9) non-cash expenses for in-kind services, (10) depreciation, and (11) certain other items management believes affect the comparability of operating results.
Management believes that Adjusted EBITDA, when viewed with our results under U.S. GAAP and the accompanying reconciliations, provides useful information about our period-over-period results. Adjusted EBITDA is presented because management believes it provides additional information with respect to the performance of our fundamental business activities and is also frequently used by securities analysts, investors and other interested parties in the evaluation of
37
Table of Contents
comparable companies. We also rely on Adjusted EBITDA as a primary measure to review and assess the operating performance of our Company and our management, and it will be a focus as we invest in and grow the business.
Adjusted EBITDA has limitations as an analytical tool and should not be considered in isolation from, or as a substitute for, analysis of our results as reported under GAAP. Some of these limitations are:
•Adjusted EBITDA does not reflect our cash expenditures or future requirements for capital expenditures or contractual commitments.
•Adjusted EBITDA does not reflect changes in, or cash requirements for our working capital needs.
•Although Depreciation and amortization are non-cash charges, the assets being depreciated and amortized will often have to be replaced in the future, and Adjusted EBITDA does not reflect any cash requirements for such replacements.
•Adjusted EBITDA does not include the impact of certain charges or gains resulting from matters we consider not to be indicative of our ongoing operations.
Due to these limitations, Adjusted EBITDA should not be considered as a measure of discretionary cash available to us to invest in the growth of our business. We compensate for these limitations by relying primarily on our U.S. GAAP results and using Adjusted EBITDA only as a supplement to our U.S. GAAP results.
Reconciliation of Net Loss to Adjusted EBITDA
For the year ended December 31,
Less: Gain on sale of mobile hardware — (216,189)
Add: Change in fair value of warrant liability (1,497) (5,033)
Add: Non-cash expenses for in-kind services — 18,547
Adjusted EBITDA loss (non-GAAP) for the year ended December 31, 2024, increased by 12.17%, to $7.29 million from $6.50 million for the year ended December 31, 2023. During the year ended December 31, 2024, the Company signed a license agreement with Boumarang in exchange for 5,000,000 prepaid warrants from Boumarang that were valued at $1.00 per warrant or $5.00 million and accounted for by recording as an investment and other income. Subsequently, the Company recorded a $4.38 million impairment to other income for the Boumarang prepaid warrants as a result of a change in fair value identified by an observable market transaction. The net impact to other income, $705 thousand, was deducted from the Net income to arrive at the Adjusted EBITDA loss (non-GAAP) and is the primary driver for the significant change in Adjusted EBITDA loss (non-GAAP) for the year ended December 31, 2024 compared to the prior period. Additionally, the Company recorded a $1.17 million loss to other expense due to the Company entering into a Termination and Release Agreement between the Company and an institutional investor that terminated the remaining stock purchase warrants in exchange for the Company making a $1,650,000 payment to the institutional investor. The Company also recorded a loss of $360 thousand to other expense related to the difference in the cash paid for the warrants and the fair market value of the warrants issued on September 10, 2024.
During the year ended December 31, 2023, the Company recognized non-refundable license revenue advances from Interactive Global Solutions (“IGS”) for the provision of software of $2.51 million. This was a one-time occurrence which significantly improved our net revenues during the year ended December 31, 2023. As there was no similar transaction during the year ended December 31, 2024, this contributes to the significant change in Adjusted EBITDA loss (non-
38
Table of Contents
GAAP) for the year ended December 31, 2024. See “Results of Operations” below for further discussion on the drivers behind the decrease in stock-based compensation during the year ended December 31, 2024.
Components of Results of Operations
Net revenue
We derive our revenue primarily from professional services though our business model is transitioning to focus on recurring Software-as-a-Service (SaaS) revenue.
In addition to revenue from Mastercard and our S&P 500 bank customer, the Company also continued to expand the Orchestration Layer platform, which is being utilized by several customers including FIS’ new global identity authentication system. The Orchestration Layer platform is a SaaS platform that includes the Company’s proprietary tokenization technology, and facilitates no-code, and low-code implementations, making adoption faster and even more cost-effective for a broader range of potential customers. The Company expects this platform to accelerate its evolution, from being exclusively a custom solutions provider, to also offering a modular and highly scalable SaaS model with low-code implementation.
Furthermore, on November 12, 2024, the Company entered into a business arrangement with Qenta. Under the arrangement, Qenta spun its Goldstar KYC technology off into a newly formed subsidiary, QID Technologies LLC (“QID”). In parallel, the Company entered into a license and assignment agreement with QID, in which the Company provided a non-exclusive license of its AI-powered identity technologies to QID in exchange for (I) a $1.0 million license fee in the form of a promissory note, which is due and payable in three equal tranches on December 31, 2024; February 1, 2025, and March 1, 2025; and (ii) the transfer of 10% of QID to the Company by Qenta. The Company has received no payments pursuant to this note during the year ended December 31, 2024. The Company has received $600 thousand in payments pursuant to this note as of the date of this report.
In addition, the Company (through its subsidiary, Trust Stamp Malta Ltd.) and QID agreed to enter into a Master Technology Services Agreement, under which QID will contract with the Company for business development, product development, and product operations for identity and privacy services and solutions in return for monthly service fees starting January 1, 2025, and capped at $3.6 million annually.
On January 1, 2025, pursuant and adhering to the Master Technology Services Agreement terms and conditions, a Statement of Work was signed which the Company will provide certain product development and product operations and commercial business development and related services on behalf of QID. During the first six months of this agreement, the service fee shall be a minimum $100 thousand per month. Thereafter, the service fee payable shall be up to $300 thousand per month.
Cost of services provided
Cost of services provided generally consists of the cost of hosting fees and cost of labor associated with professional services rendered. Depreciation and amortization expense is not included in cost of services provided.
During the year ended December 31, 2023, we expected that cost of services provided will continue to decrease in absolute dollars until the transition to primarily SaaS revenue is complete. After the transition is complete, we expect cost of services to increase in absolute dollars as the volume of usage revenue increases, but the margin will continue to improve until they stabilize over time. This was evident during the year ended December 31, 2024.
Research and development
Research and development expenses (“R&D”) consist primarily of personnel costs, including salaries and benefits. Personnel costs are allocated to R&D for time spent working on the preliminary project stage and post-implementation maintenance as well as time spent on bug fixes associated with internal-use software activities, front-end application development in which technological feasibility has not been established, and services rendered to customers under funded software-development arrangements.
During the year ended December 31, 2023 we planned to continue to invest in personnel to support our research and development efforts. As a result, research and development expenses increased in absolute dollars. During the year ended
39
Table of Contents
December 31, 2024 research and development expenses decreased, primarily driven by a decrease in outsourced software development during the year ended December 31, 2024 as the Company continued to transition this work internally.
Selling, general, and administrative
Selling, general, and administrative (“SG&A”) expenses were generally composed of payroll, legal, and professional fees.
We expect that the sales and marketing expenses within the SG&A expenses will increase in absolute dollars as we continue to invest in our potential and current customers, in growing our business, and enhancing our brand awareness.
Depreciation and amortization
The increase in depreciation and amortization is primarily due to a continued investment in internally developed software and patent registrations which will be used for future productization.
Interest expense, net
Interest expense, net consists primarily of interest expense accrued on a promissory note payable. The Company earned interest income in the form of interest on employee stock loans.
Other income
Other income is mainly driven by miscellaneous income earned that is unrelated to the main focus of the Company’s business including the gain or loss on sale of assets.
Other expense
Other expense is mainly driven by miscellaneous expenses unrelated to the main focus of the Company’s business.
40
Table of Contents
Results of Operations
The following table summarizes our consolidated statements of operations for the Years Ended December 31, 2024 and 2023
For the years ended December 31,
Operating Expenses:
Non-Operating Income (Expense):
Change in fair value of warrant liability 1,497 5,033
Net loss attributable to non-controlling interest — —
Comparison of the Years Ended December 31, 2024 and 2023
Net revenue
For the years ended December 31,
During the year ended December 31, 2024, Net revenue decreased to $3.08 million from Net revenue of $4.56 million for the year ended December 31, 2023, with $1,497,195 coming in the fourth quarter of 2024. During the year ended December 31, 2024, the $3.08 million in Net revenue consisted of $1.35 million from an S&P bank, $1.00 million license fee from QID under the license and assignment agreement between the Company and QID, $424 thousand from Mastercard, $193 thousand from Triton, $89 thousand from FIS and various other customers for the remaining $22 thousand.
The majority of the decrease in Net revenue during the year ended December 31, 2024 compared to the year ended December 31, 2023 was due to the termination of the September 15, 2022 Master Services Agreement with IGS ("IGS Contract"), which caused Company to recognize non-refundable license revenue advances from IGS under the IGS Contract for the provision of software of $2.51 million. This was a one-time occurrence which significantly improved our net revenues during the year ended December 31, 2023, and therefore is the primary reason for the stark decrease in net
41
Table of Contents
revenues of the Company during the year ended December 31, 2024. This decrease from the IGS contract was partially offset by the $1.00 million in revenue recognized for a non-exclusive software license issued to QID during the year ended December 31, 2024.
During the year ended December 31, 2024, the Company generated $1.25 million total revenue from customers using the Orchestration Layer compared to $310 thousand during the year ended December 31, 2023. The Orchestration Layer is designed to be a one-stop-shop for Trust Stamp services and provides for easy integration to our products; chargeable on a per-use basis and is accelerating the Company’s evolution from being exclusively a custom solutions provider to also offering a modular and highly scalable SaaS model with low-code implementation.
Since its launch in the third quarter of 2022, there have been 79 enterprise customers on the Orchestration Layer platform, including 66 financial institutions, as of December 31, 2024. Additionally, revenue from the Orchestration Layer's flagship enterprise customer grew 176% between the comparative periods as a result of transitioning and launching the customer on the Orchestration Layer platform. Orchestration Layer's flagship enterprise customer is already in full production and generating monthly recurring revenue with gross margins in excess of 80.54%. Finally, the Company's S&P 500 bank customer began its transition to an augmented version of the SaaS platform during the year ended December 31, 2024.
Cost of services
For the years ended December 31,
Cost of services (“COS”) increased by $153 thousand or 16.77% for the year ended December 31, 2024, compared to the year ended December 31, 2023. The increase during the year ended December 31, 2024 was primarily driven by a $243 thousand increase in costs for the expansion of our proof of identity solutions using a third-party as required for proof of identity contracts. The solution was not considered a cost of sale until the fourth quarter of 2023, thus, the total expense for this solution during the year ended December 31, 2023 was $21 thousand and increased to $264 thousand during the year ended December 31, 2024. The Company also incurred $42 thousand for compliance services due to a specific customer requirement during the year ended December 31, 2024 and this expense was not incurred during the year ended December 31, 2023. Furthermore, the Company saw a slight increase in service requests by our main customers, during the year ended December 31, 2024 resulting in an increase of $10 thousand when compared to the year ended December 31, 2023.
On the other hand, less development hours were charged directly to cost of sales for the year ended December 31, 2024 when compared to the year ended December 31, 2023 resulting in a decrease of $133 thousand in cost of services. This was mainly due to less work being requested from one of our major customers.
Research and development
For the years ended December 31,
Research and development (“R&D”) expenses decreased by $211 thousand, or 8.97% for the year ended December 31, 2024, compared to the year ended December 31, 2023. The decrease in R&D expense during the year ended December 31, 2024 was primarily driven by a decrease in outsourced software development during the year ended December 31, 2024 as the Company continued to transition this work internally, as well as, a decrease in salaries related to R&D from the Malta office, together resulting in a decrease of $140 thousand collectively. Comparatively, outsourced software development costs decreased by 86% when comparing the year ended December 31, 2024 to the year ended December 31, 2023. In both periods, R&D expenses mainly were related to R&D payroll and other R&D compensation expenses.
Additionally, the Company recognized an impairment loss on Capitalized internal-use software of $25 thousand during the year ended December 31, 2024. There was $19 thousand impairment loss on Capitalized internal-use software for the year ended December 31, 2023. Capitalized internal-use software are considered long-lived assets under applicable accounting guidance. Recoverability of assets held and used is measured by comparison of the carrying amount of an asset or an asset group to estimated undiscounted future net cash flows expected to be generated by the asset or asset group. If the carrying amount of an asset exceeds these estimated future cash flows, an impairment charge is recognized by the amount by which
42
Table of Contents
the carrying amount of the assets exceeds the fair value of the asset or asset group. Assets to be disposed of are reported at the lower of the carrying amount or fair value less costs to sell.
Furthermore, stock-based compensation decreased to $61 thousand during the year ended December 31, 2024, from $123 thousand during the year ended December 31, 2023. This was mainly due to the decrease in employee Restricted Stock Unit award grant date values as a result of the decrease in share price on the grant dates.
Selling, general, and administrative
For the years ended December 31,
Selling, general, and administrative expense (“SG&A”) increased by $118 thousand, or 1.40%, for the year ended December 31, 2024, compared to the year ended December 31, 2023. The increase in SG&A expense was driven by a $840 thousand increase in salaries and stock-based compensation ("SBC") during the year ended December 31, 2024. Included in the $840 thousand increase in salaries and stock-based compensation is an increase of $630 thousandin SBC during the year ended December 31, 2024 due to the timing of stock-based compensation awards.
Furthermore, there was a $109 thousand increase in SG&A when comparing the year ended December 31, 2024 to the year ended December 31, 2023 resulting from the reversal of out-of-period costs incurred during the year ended December 31, 2024 associated with carrying mobile hardware assets, reversed due to the cancellation of the related mobile hardware subscription. In addition, the Company had an increase in dues and subscriptions, due to continued business development and growth, of $50 thousand during the year ended December 31, 2024 when compared to the year ended December 31, 2023. Other notable increases in SG&A for the year ended December 31, 2024 included a total increase of $215 thousand in travel costs and accounting, audit fees and taxes.
The increases in SG&A were substantially offset by notable reductions for the year ended December 31, 2024 including a total reduction of $1.10 million in professional fees, management consulting, training, and office and IT services as a direct result of the Company's recent non-personnel cost cutting initiative.
In both periods, SG&A expenses were primarily comprised of payroll and other compensation expenses to our Company's workforce.
Depreciation and amortization
For the years ended December 31,