Skip to content

About Ingenium

We don't build identity technology. We test whether it works.

Ingenium is an independent biometric and identity testing lab. We were founded to address a critical gap in the identity ecosystem: the absence of rigorous, impartial, scientifically grounded assurance for technologies that carry profound real-world consequences. We close that gap for the organisations that deploy identity systems, and for the vendors who build them.

A gap that needed closing

Identity systems are central to how modern organisations operate. They enable access, prevent fraud, and underpin digital services at scale. And yet, for most of their history, the assurance underpinning those systems has come primarily from the vendors who built them, tested in conditions they controlled, against benchmarks they set, mapped to an organisation’s business case.

That is not a criticism of vendors, it is simply the nature of commercial incentives. As well as working with buyers, Ingenium works directly with vendors to help them guard against this potential criticism and close potential gaps.

Ingenium provides independent, empirical validation of how biometric and identity systems perform, under real-world conditions, against current attack methods, using reproducible scientific methodology. We have no stake in the technology we test. We do not sell software, issue certifications, or set the standards we test against. Our only function is to find out whether a system does what it is supposed to do.

Decades of experience. Brought to bear on your systems.

Our founders and leadership team bring together decades of experience spanning government, national security, international standards bodies, and global identity programmes.

That experience includes shaping policy, defining standards, and advising institutions including the UK Government, the European Commission, the World Bank, and international regulatory bodies. It is experience built not at a desk, but in environments where the performance of identity systems carries real consequences, and where the difference between a system that works and one that merely appears to work is measured in breach events, not audit reports.

That depth of expertise informs how we design tests, how we interpret results, and how we support clients in using those results, whether they are navigating regulatory scrutiny, making procurement decisions, or building a case for their own customers.

Test as attackers behave. Measure as scientists do. Add actionable reporting with clarity.

Our laboratory is rooted in academia, based on the University of Kent campus, with strong ties to the global research community. Our methodology reflects that foundation: structured, evidence-based, and aligned to internationally recognised standards.

We do not rely on theoretical models or paper-based assessments. We design and execute empirical tests that generate defensible, repeatable results.

In practice, that means:

Adversarial by design

Our tests reflect real attacker behaviour,  including the techniques and tools being actively used by organised threat actors, not just the baselines that standards mandate. When hackers fail, they innovate. Our methodology keeps pace.

Continuously evolving.

The threat landscape does not stand still. Neither does our approach. We continuously update our methodologies in line with emerging attack methods, including advances in deepfakes, adversarial AI, and synthetic identity generation.

Scientifically grounded.

Every engagement produces evidence that is repeatable, transparent, and capable of withstanding independent scrutiny. Not a snapshot, but a defensible record.

Independent by design. Connected where it counts.

Independence is not just a position we hold – it is built into how we operate. We do not sell the technology we test. We are not affiliated with certification bodies. We do not benefit from a system passing or failing. That structural separation is what makes our findings trustworthy.

But staying genuinely ahead of the threat landscape requires more than neutrality. It requires active investment in the relationships and intelligence that keep testing methodologies current.

Ingenium works in close partnership with public sector bodies, academic institutions, and international standards working groups. Those relationships give us access to emerging threat intelligence, including attack methods not yet reflected in published standards, and allow us to develop tests that mirror the capabilities of organised threat actors rather than merely the requirements of regulators.

Accredited. Recognised. Accountable.

Trust in testing starts with rigour, independence, and recognised accreditation. Ingenium is an ISO/IEC 17025 accredited laboratory, demonstrating our technical competence, methodological integrity, and quality assurance processes,  accredited The Global Accreditation Cooperation Incorporated (Global ACI). GACI is the international authority on the accreditation of laboratories, certification bodies, inspection bodies, proficiency testing providers, validation/verification bodies, reference material producers and biobanks. Our accreditation was provided by Perry Johnson Laboratory Accreditation, Inc.

Accreditation is not a badge. It is a commitment to repeatable, scientifically valid testing, transparent methodologies, and continuous review of emerging risks. Our accreditations include:

Biometric performance testing

Presentation Attack Detection (PAD)

Injection attack detection

Authorised testing for biometric and identity verification certification

Trusted partner for open-source identity systems

National Protective Security Authority (biometric testing laboratory)

A structured process. A clear outcome.​

Every engagement begins with a consultation, not a sales pitch. We take time to understand your objectives, your technology stack, your risk profile, and the regulatory context you’re operating in. From there, we design a tailored testing approach and agree on scope, methodology, and commercial terms before any testing begins.

Understanding your objectives, systems, and risk context

Tailored testing approach, agreed methodology, commercial terms

Aligning on access requirements, data flows, and ways of working

Configuring and validating the test environment

Formal checkpoint confirming readiness

Rigorous testing, with client involvement calibrated to your needs

Structured close ensuring completeness and integrity

Detailed findings, metrics, and clear recommendations

Presenting findings and supporting you in communicating them – internally, to regulators, or to the market

The question isn't whether your systems are tested. It's who by.

Whether you’re evaluating a new system, preparing for regulatory scrutiny, or looking to build independent evidence into your product, Ingenium provides rigorous, impartial testing and reporting to give you a clear picture of where you are and what it takes to close the gaps.