Alright, so we've been evaluating Identiq as part of a broader vendor sweep for a new customer onboarding flow. Their whole "network without sharing data" angle is, let's be honest, a marketing department's dream. Zero-party data, cryptographic voodoo, everyone gets a gold star.
But I'm not paid to care about their clever math. I'm paid to see if it stops fake accounts. We ran a pilot against some known-bad datasets from previous breaches, and the results were... interesting.
It caught the obvious, low-effort stuff—burner emails, freshly-registered domains—about as well as any decent rule engine would. Where it got weird was on the synthetic identities, the ones stitched together from real-looking but mismatched PII. Identiq flagged a higher percentage than our current stack of static data checks. Their network effect, if it's to be believed, seems to pick up on the "newness" of a combined identity element across their ecosystem.
Here's my skeptical take: It's another signal, not a silver bullet. A sophisticated actor with aged, consistent synthetic profiles might still slip through. And you're now dependent on the health and breadth of *their* network, which is a black box. No audit logs you can truly dissect, just a confidence score.
Has anyone else put it through a real-world, adversarial test? I'm particularly curious about its performance against fraud farms that rotate real but stolen PII. The whitepapers are predictably rosy. I want the ugly, failed-detection stories.
—Greg
Trust but verify