AU10TIX Review
5.8/10A 2002 Israeli identity-verification vendor whose real edge is deepfake and injection-attack detection, majority-owned by SEC-reporting ICTS International (66.30% at Dec 2025), PA-Registered and on the UK DIATF register, but carrying an audited 31.5% revenue collapse to $31.5M with a $12.2M loss (FY2025 20-F), a 2024 credential-exposure incident, a breach disclosure rewritten a year later, and a single named gaming operator (888).
Our read
A modular IDV and authentication engine (document, biometric with liveness, AI age estimation, proof of address, eKYC, AML/PEP/sanctions, POS) whose edge is deepfake and injection-attack detection (multi-layer AI on metadata, visual, and behavioral signals), with under-8-second and 98%-completion figures vendor-stated, coverage counts not published, and no orchestration or reusable-ID play.
PA PGCB Registered (AU10TIX Ltd., exp 04/12/2027, the lower class, not Certified) plus a UK OfDIA DIATF register presence (page 1 confirmed), while the UKGC, AMLD, UIGEA, and KOSA name-drops are marketing rather than approvals and ISO 27001 is claimed only, a two-register trail but nothing higher.
API plus SDK with mobile document capture, but integration details are gated behind sales with no open developer portal (contrast GBG's docs.go.gbgplc.com), no named platform or PSP integrations surfaced, and no reusable-KYC or orchestration story, the thinnest delivery surface of the in-tier vendors.
The thinnest named-operator footprint of the in-tier vendors: exactly one named operator, 888 Holdings (a case study with a Director-level quote), plus the register and DIATF presence, so it clears the bar of a live gaming page and a named operator, but a single client alongside the audited customers-were-lost note makes gaming a con rather than a strength.
The review's center of gravity and the only sub-5 dimension in the segment: audited revenue down 31.5% ($46.0M to $31.5M) plus a $12.2M segment loss (ICTS FY2025 20-F, filing citing customer losses), the 2024 credential-exposure incident (404 Media, June 2024, admin credentials exposed over a year, still working when tested, PII and ID-image links for TikTok/Uber/X users), and the breach disclosure rewritten a year later, the 2025 no-production-connection account narrowing the 2024 reporting and the company's own 2024 potentially-accessible admission.
No public pricing, enterprise sales only, the opaque camp shared with GBG, Socure, and Prove and the opposite of the iDenfy and Shufti Pro publish-the-price approach (Jul 2026).
Methodology. Our own score, a weighted average of six dimensions, tilted toward verification coverage and compliance. Weighted on the identity-verification scale, where verification coverage leads at 0.22 and compliance and certifications follows at 0.20, so a strong deepfake-detection engine and a two-register trail lift the top dimensions while an audited revenue decline, a security incident, a breach disclosure rewritten a year later, and a one-operator gaming footprint hold the score at the segment floor. Read the full methodology
- Deepfake and injection-attack detection depth is where AU10TIX leads: multi-layer AI across image metadata, visual anomalies, and behavioral patterns, built and marketed hard for the synthetic-identity and deepfake threat that defines remote onboarding in 2026, a real edge over most of the tier.
- Fast, automated verification for high-volume onboarding: results in under 8 seconds, a 98% completion rate, and 24-hour new-market deployment (vendor figures, Jul 2026), a speed-first positioning that suits operators pushing large sign-up volumes.
- Unusual financial visibility for the tier: because majority parent ICTS International N.V. is SEC-reporting, AU10TIX segment revenue and profit are disclosed in audited 20-F filings, so a buyer can actually read the numbers, which is rare in a category where almost every peer keeps financials private.
- A two-register footprint anchored in the US and UK: PA PGCB Registered (AU10TIX Ltd., exp 04/12/2027) plus a UK OfDIA DIATF statutory register presence (page 1 confirmed), a real regulated-market trail, and a full check spread (document, biometric with liveness, age estimation, proof of address, eKYC, AML) in one engine from a vendor operating since 2002.
- An audited revenue collapse: the parent ICTS International's FY2025 Form 20-F (filed 30 April 2026) shows the AU10TIX authentication segment's revenue falling 31.5% from $46.0M in 2024 to $31.5M in 2025 and swinging to a $12.2M net loss after prior-year profit, with the filing stating in its own words that some customers were lost and activity declined, the rare filing-grade stability con in a tier that otherwise hides its numbers.
- The 2024 credential-exposure incident: 404 Media reported in June 2024 that AU10TIX administrative credentials to a logging platform had been exposed online for over a year, harvested by infostealer malware from a NOC manager's machine and posted to Telegram, were still functional when tested in June 2024, and gave access to names, dates of birth, nationalities, ID numbers, document types, and links to ID-document images of end users verified for TikTok, Uber, and X.
- The breach disclosure rewritten a year later (our finding): AU10TIX's July 2025 retrospective statement describes a single set of previously compromised inactive employee credentials for a legacy log-management system with no connection to production systems and no evidence of data exposure, a softer account than the 2024 record, where the credentials still worked when tested and exposed links to real ID images and AU10TIX itself admitted PII was potentially accessible, a narrowing that reduces the apparent severity.
- The thinnest named-gaming footprint of the identity-verification tier: exactly one named operator, 888 Holdings (a case study with a Director-level quote), with no other named regulated-gaming clients surfacing on the vendor site or in trade press (Jul 2026), which alongside the audited customers-were-lost note makes gaming a weak spot instead of a strength.
- PA Registered rather than Certified, plus opaque ownership and pricing: AU10TIX holds the lower of Pennsylvania's two classes (a rung below GBG, Socure, and Shufti Pro), it is a private company under a thinly-traded OTCQB parent routed through a Netherlands holding company, it publishes no pricing, and ISO 27001 is asserted with no issuer certificate (claimed only).
Operators whose specific problem is deepfake and injection-attack fraud at onboarding, that want a full document, biometric, age, and AML spread in one fast automated engine, and that are comfortable with an enterprise-opaque vendor carrying a security-incident and revenue-decline history.
Operators who weight security-incident history and disclosure consistency heavily, need a deep named-operator gaming track record, want published pricing, or want a financially growing vendor, since AU10TIX is shrinking, PA-Registered below the Certified class, and thin on gaming clients.
Markets & licensing
AU10TIX carries a register trail on both sides of the Atlantic, but at the lower rung on the US side. In the US, AU10TIX Ltd. is a Registered gaming service provider on Pennsylvania's PGCB list (as of 3/24/2026), description ID verification services, expiring 04/12/2027. PA distinguishes Certified from the lower Registered class, and AU10TIX holds Registered, a rung below GBG, Socure, and Shufti Pro, all of which are Certified. In the UK, AU10TIX Ltd. appears on the OfDIA statutory DIATF register (page 1, alongside Veriff and OCR Labs), without published per-service detail. The framework name-drops on the gaming page, UKGC, AMLD 5 and 6, UIGEA, GDPR, ISO 27001, and KOSA/SCOPE, are marketing rather than approvals, and ISO 27001 is asserted with no issuer certificate published.
The US gaming registration is real but at the lower rung: AU10TIX Ltd. is a Registered, not Certified, gaming service provider on the PGCB list (as of 3/24/2026) for ID verification services, expiring 04/12/2027. That puts it a class below the Certified peers in the tier. US operators get a real state-register anchor in Pennsylvania, but per-state coverage beyond PA should be confirmed at contract, and the audited Americas-heavy revenue decline covered in the trust section is the backdrop a US buyer should weigh.
AU10TIX Ltd. is present on the OfDIA Digital Identity and Attributes Trust Framework statutory register, on page 1 alongside Veriff and OCR Labs. The per-service detail (product names and confidence profiles) is not published in the register listing, so a UK operator should confirm the exact scope at contract. The register presence itself is real and is the stronger of the two anchors for a UK-facing operator.
- AU10TIX Ltd., PA PGCB registrationPennsylvania, United States
- Registered gaming service provider, description ID verification services, held by AU10TIX Ltd. directly, at the lower of PA's two classes · On the Authorized Certified and Registered Gaming Service Providers List as of 3/24/2026 · Registered (lower class) · exp 04/12/2027 · entity listed at Hod Hasharon, 972
- AU10TIX Ltd., OfDIA DIATF registerUnited Kingdom
- Present on the statutory Digital Identity and Attributes Trust Framework register, the UK trust anchor for the identity products · Page 1 of the register (as of Mar 2026) alongside Veriff OU and OCR Labs/IDVerse · per-service detail not published in the listing
Licensing tier: Two registers, but the lower-value kind on the US side: PA Registered and not Certified, plus a UK DIATF page-1 presence without published per-service detail. Unusually for the tier, the parent files audited numbers (ICTS 20-F), but ISO 27001 is asserted on the gaming page with no issuer certificate published.
The two register anchors are the checkable gaming footprint. AU10TIX serves customers predominantly in the United States per the parent 20-F, but the gaming-relevant registers are the PA registration and the UK DIATF entry (Jul 2026).
No restricted-market list applies: AU10TIX sells identity software out of Tel Aviv, and no gambling license attaches to it, so the register trail runs through Pennsylvania and the UK DIATF page instead (Jul 2026).
Platform & capabilities
The feature set: what's built in. Capabilities light up when present. Anything not shown isn't offered or isn't disclosed.
Integrations & engineering
One contract and one API instead of a separate deal per studio, feed, or PSP. Here's what connects, how fast, and on what stack.
AU10TIX integrates through an API plus SDK with mobile document capture, but the developer surface is gated behind sales rather than exposed as an open portal. The product is positioned as a verification and fraud-defense engine, document, biometric with liveness, age estimation, proof of address, eKYC, and AML screening fronted by deepfake and injection-attack detection, rather than a no-code orchestration canvas of the Sumsub or GBG GO kind, and reusable KYC or passporting is not a marketed feature. No named PSP or casino-platform connectors surfaced on the vendor site, so operators should assume a direct API build.
No public integration-time claim beyond the vendor-stated 24-hour new-market deployment figure on the gaming page (Jul 2026). API and SDK details arrive after sales contact, so the real calendar comes out of the sales process.
Products & tools
A modular verification and authentication engine: document verification, biometric selfie with liveness, AI age estimation, proof of address, eKYC, and AML/PEP/sanctions screening, all fronted by the multi-layer deepfake and injection-attack detection AU10TIX markets hardest on.
Identity Verification Suite
A modular stack covering document verification, biometric selfie with liveness, AI age estimation, proof of address, eKYC, and AML/PEP/sanctions screening, plus a POS verification flow for in-app and point-of-sale gaming transactions.
- Document verification through real-time capture or secure upload (gaming page, Jul 2026)
- Biometric verification with selfie and liveness checks
- AI-driven instant age estimation for age-gated onboarding
- Proof of address with authentication and forgery detection
- eKYC validating name, date of birth, and government credentials against trusted sources
Deepfake & Injection-Attack Detection
Multi-layer AI that inspects image metadata, visual anomalies, and behavioral patterns to catch synthetic identities, deepfakes, and camera-injection attacks, the capability AU10TIX markets hardest on as of 2026.
- Multi-layer detection across metadata, visual anomalies, and behavioral signals
- Aimed at synthetic-identity fraud, deepfakes, and injection attacks specifically
- Positioned as the core of the fraud-defense pitch rather than an add-on
- Sold into gaming alongside the document and biometric checks
- The one part of the stack with a real competitive edge over the tier
AML, PEP & Sanctions Screening
Watchlist screening against AML, PEP, and sanctions lists with ongoing monitoring, bundled with the verification suite and never sold as a standalone monitoring platform.
- AML, PEP, and sanctions watchlist screening at onboarding
- Ongoing monitoring for status changes after the initial check
- Delivered inside the same engine as document and biometric verification
- Framed for gaming against UKGC, AMLD 5 and 6, and UIGEA on the vertical page
- Screening depth and list coverage not enumerated publicly (Jul 2026)
On the record
The history that matters: the milestones, the scale, the awards, and who runs it.
AU10TIX was founded in 2002 by Ron Atzmon and Gil Atzmon, headquartered in Tel Aviv with a development center in Hod Hasharon. It is the authentication-technology arm of ICTS International N.V. (OTCQB: ICTSF), held through AU10TIX Technologies B.V. in the Netherlands, with ICTS owning 66.30% as of 31 December 2025 (down from 67.51% a year earlier). Minority investors TPG ($60M in July 2019) and Oak HC/FT ($20M in preferred in November 2019) put in the $80M ICTS cites, routed through an ABC Technologies B.V. intermediate holding. Dan Yerushalmi has been CEO since January 2023. The segment provides authentication services to financial and other companies predominantly in the United States, and its audited FY2025 results, revenue of $31.5M down 31.5% from $46.0M and a $12.2M net loss, are disclosed in the parent's Form 20-F filed 30 April 2026.
Brands & clients on the platform
Corporate
Leadership
Milestones
- 2002
AU10TIX is founded by Ron Atzmon and Gil Atzmon in Israel, later the authentication-technology arm of ICTS International.
- 2019
TPG invests $60M (July) and Oak HC/FT $20M in preferred (November), the $80M minority stake in the AU10TIX business.
- 2023
Dan Yerushalmi is appointed CEO (January), the year a roughly 9% workforce cut was reported.
- 2024
404 Media reports (26 June) that AU10TIX administrative credentials were exposed online for over a year and still worked when tested, with access to end-user ID data for TikTok, Uber, and X users.
- 2025
AU10TIX publishes a retrospective statement (28 July) describing the event as inactive legacy credentials with no production connection and no data exposure, an account that conflicts with the 2024 reporting.
- 2026
The parent ICTS files its FY2025 Form 20-F (30 April): AU10TIX segment revenue $31.5M (down 31.5%) and a $12.2M net loss, with ICTS at 66.30% ownership as of December 2025.
Where they're pushing next
- Deepfake and injection-attack detection as synthetic fraud rises, the vendor's clearest strength
- US market, where the segment serves customers predominantly per the parent 20-F
- UK, anchored by the OfDIA DIATF register presence
Trust signals
The checks an operator runs before signing: incidents, enforcement, ownership, and longevity, from our research.
- Security incidents: Major
AU10TIX vs alternatives
The same attributes, side by side, from our normalized provider set, useful for seeing where this vendor fits against its peers.
| Attribute | AU10TIX | Veriff | Jumio | Sumsub |
|---|---|---|---|---|
| Founded | 2002 | 2015 | 2010 | 2015 |
| Team | — | — | — | 500+ |
| US market | Available | Available | Available | — |
| Pricing | Not published | Not published | Not published | Public |
| Country coverage | Global coverage marketed | 230+ countries | 200+ countries and territories | Document-free verification in… |
| UK DIATF | UK OfDIA DIATF statutory regi… | UK DIATF gamma | Yes | Certified IDSP |
The take: Veriff is the closest peer, a document-and-biometric IDV vendor with a thin gaming footprint of its own (Stake only) but a cleaner financial and incident picture. Jumio brings the deepest named gaming roster and a US-lens push, and Sumsub pairs a broader stack with public per-check pricing AU10TIX hides. AU10TIX's edge over all three is deepfake and injection-attack detection plus speed, while its weakness is the audited revenue decline, the 2024 incident with its rewritten disclosure, and a one-operator gaming record. Pick AU10TIX when synthetic-fraud defense is the specific problem and you can accept the trust and stability history.
Pricing & terms
AU10TIX quotes pricing on request. Exact figures come at the deal stage, under NDA. Here's what's public about the model and terms.
Enterprise sales only, no per-check or per-seat schedule on record (Jul 2026)
Turnkey
White-label
Support & account management
The service layer operators inherit: availability, the channels support runs on, and language coverage.
Frequently asked
The things operators actually ask before signing.
What happened in the 2024 data-exposure incident, and why does AU10TIX's story differ between 2024 and 2025?+
In June 2024, 404 Media reported that AU10TIX administrative credentials to a logging platform had been exposed online for more than a year, harvested by infostealer malware from a NOC manager's machine and posted to Telegram, and were still functional when tested in June 2024, giving access to names, dates of birth, nationalities, ID numbers, document types, and links to ID-document images of end users verified for TikTok, Uber, and X. AU10TIX said at the time that PII was potentially accessible but that it saw no evidence the data had been exploited. In a July 2025 retrospective, the company recast the event as a single set of previously compromised inactive employee credentials for a legacy log-management system with no connection to production systems and no evidence of data exposure. That 2025 account is narrower and more exculpatory than both the 2024 reporting (credentials that still worked and exposed real ID-image links) and AU10TIX's own 2024 potentially-accessible admission, which is the discrepancy we record, dated to both statements.
Is AU10TIX financially stable?+
The audited numbers show a business in decline. Because majority parent ICTS International N.V. is SEC-reporting, AU10TIX's segment figures are disclosed: in the FY2025 Form 20-F filed 30 April 2026, the authentication segment's revenue fell 31.5% from $46.0M in 2024 to $31.5M in 2025 and swung to a $12.2M net loss after a prior-year profit, with the filing stating that some customers were lost and activity declined against largely fixed costs. The revenue drop is chronologically adjacent to the 2024 credential-exposure incident, though the filing does not attribute a cause. This is the rare filing-grade financial visibility in the tier, and what it shows is a shrinking, loss-making segment as of the 2025 fiscal year.
Which gambling operators actually use AU10TIX?+
One named operator is on record: 888 Holdings, a case study with a quote from Ofir Asbet, Director of Funnel & Customer Safety Products. No other named regulated-gaming operators surfaced on the vendor site or in tier-1 trade press (Jul 2026). That single named client is the thinnest gaming footprint of the identity-verification vendors we rate, and 888's own materials were not confirmed to name AU10TIX, so the evidence is the vendor case study rather than operator-side corroboration. The cross-industry names in circulation (TikTok, Uber, X, PayPal, Coinbase) come from the 2024 breach reporting and are non-gaming.
Is AU10TIX PA Certified or Registered?+
Registered, which is the lower of Pennsylvania's two classes. AU10TIX Ltd. is a Registered gaming service provider on the PGCB list (as of 3/24/2026) for ID verification services, expiring 04/12/2027. PA distinguishes Certified from Registered, and AU10TIX holds Registered, a rung below GBG, Socure, and Shufti Pro, which are all Certified. It is also present on the UK OfDIA DIATF statutory register (page 1), though the register listing does not publish the per-service detail.