NewThe detectors that scored perfect collapsed the hardest under attack.
In your environment

Run the attack on your own corpus, without your data leaving your environment.

Our benchmarks show how detectors hold up against the attacks that are circulating. When you need that answer for your own population, we bring the same tooling into your environment and run it against your private corpus and your detector. The corpus never moves, and the report comes back broken down by demographic cell, condition, and the attack behind each failure.

How it works

A scoped engagement, run where your data already lives.

  1. 01

    Scope the engagement

    We agree on the threat model, the detector or pipeline under test, the demographic cells that matter to you, and the conditions to emulate.

  2. 02

    Deploy the tooling in your environment

    Our attack and scoring tooling runs self-hosted inside your infrastructure. Nothing about your corpus is copied out.

  3. 03

    Generate attacks against your corpus

    We produce identity-preserving and synthetic attacks against your real population, under the conditions your pipeline actually sees.

  4. 04

    Score and report

    We run your detector and report results broken down by demographic cell, condition, and the tactic, technique, and procedure behind each failure.

Why in your environment

Test on the data you cannot send anywhere.

Your data never leaves

The corpus, and the results, stay inside your environment. You can test on production faces you are not allowed to share.

Your population, your pipeline

Attacks are generated against your real distribution and pushed through your actual processing, so the numbers reflect deployment, not a lab.

The same rigor as the benchmarks

Paired evaluation, per-cell breakdowns, and TTP-tagged failures, the method behind our public data cards, applied to your data.

Who it is for

Teams whose faces cannot leave the building.

Identity-verification and KYC, liveness and presentation-attack teams, and platforms holding sensitive biometric data. If your corpus is the thing you are protecting, the evaluation should come to it.

  • Evaluate injection and presentation attacks against your live pipeline.
  • Break down detector failures by demographic cell to find fairness gaps.
  • Get failures tagged by tactic, technique, and procedure, so fixes are targeted.
  • Keep the corpus and the results entirely inside your environment.
Start a conversation
Tell us what you want tested, and we will scope an engagement in your environment.
Contact us