YESPRESS / COMPANY PROFILE   VERIDIUM: FOUR FINGERS, ONE ENTERPRISE PROBLEM✦   24,000 USERS IN A NAMED BANK PROJECT✦   PASSKEYS / BIOMETRICS / RISK POLICYYESPRESS / COMPANY PROFILE   VERIDIUM: FOUR FINGERS, ONE ENTERPRISE PROBLEM✦   24,000 USERS IN A NAMED BANK PROJECT✦   PASSKEYS / BIOMETRICS / RISK POLICY

Company profile / Identity security

The Password Was the Easy Part. The Office Was Harder.

Veridium began by teaching a phone camera to read four fingers. Its larger invention was persuading the messy corporate login - VPN, Windows, virtual desktop and all - to accept a better answer than a password.

There is a peculiar glamour to a fingerprint. It seems so decisively yours. A password, by comparison, is an awkward bit of theatre: invented on Monday, forgotten by Thursday, written on a sticky note by Friday. In the mid-2010s, a company called Hoyos Labs had a more photogenic idea. Point a phone camera at four fingers, use its flash for light, and let software do the work of a scanner. The demonstration made people look. Then came the harder question: where, exactly, would a bank put it?

The short version

  • Veridium sells enterprise software for passwordless and multi-factor authentication, not a consumer password manager.
  • Its origin was contactless fingerprint research; its present offer spans passkeys, security keys, facial and native biometrics, QR, push and risk-based policy.
  • Allianz and National Bank of Egypt are named customers; the latter project was announced for a workforce of 24,000 users.
  • The practical lesson: a better login succeeds when it fits the old applications people still need.

01 / THE TURNFour fingers made the room pay attention

Hector Hoyos founded Hoyos Labs, the research business that became Veridium. Its 4 Fingers TouchlessID method captured four fingerprints with an ordinary smartphone camera and flash. No specialist scanner was needed. That mattered for cost and reach: a phone was already in the user’s hand, while fingerprint hardware was not necessarily on every desk. The team also worked on liveness checks, intended to distinguish a living person from a photograph or mold.

A Veridium contactless fingerprint demonstration on a smartphone
A hand, a camera, four fingers. The theatrical part of Veridium’s early pitch fit in a pocket; the enterprise wiring did not.

In 2016 Hoyos Labs became Veridium and launched VeridiumID. The rebrand was more than fresh lettering. The company’s announcement described an end-to-end authentication product for enterprises, with administrative controls and integrations for Active Directory and FIDO. It could be hosted in the cloud or deployed on premises. The change of emphasis was plain: research had to survive procurement, deployment and the office’s stubborn inventory of old software.

A year later, Veridium demonstrated the four-finger method at FinovateEurope. At the time it described its distribution as licensed business-to-business software and named Dutch mobile bank bunq as a customer it could disclose. The showpiece was still the scan. The sale, however, was the software around it.

“We’re going to replace what you know (passwords) with what you are (biometrics).”Todd Shollenbarger, 2016 launch statement

02 / THE BUYERThe trouble with a perfect login

A company does not have one front door. An employee may start at Windows, pass through a VPN, open a virtual desktop, and arrive at an application older than the phone in her pocket. Each asks for proof in its own dialect. This is why a beautiful biometric can lose to an ugly password: the password, for all its faults, already works almost everywhere.

Veridium’s current Identity Assurance Platform is an attempt to make stronger checks travel across those doors. Its server coordinates enrollment, authenticators and policy flows. It supports familiar enterprise protocols and connections including SAML, OpenID Connect, RADIUS, Active Directory and Windows login. Its mobile app and SDK supply methods such as native fingerprint or face unlock, QR and verified push; FIDO passkeys and hardware keys can be used where they fit. A risk engine and session controls extend the decision beyond the first tap.

That broad menu may sound unfashionable in an industry fond of one-button futures. It is also an admission of reality. Some users have FIDO keys; some have managed smartphones; some are on older systems; some need a fallback. Veridium still lists PIN and SMS one-time passcodes alongside phishing-resistant factors. Those older methods are weaker against phishing, so their presence is best understood as migration equipment, not a claim that every option is equally strong.

The company says Allianz uses its passwordless approach across VPN/RADIUS connections, virtual desktops, mobile and personally owned devices, and legacy apps. This is a useful customer example because the list is inconveniently specific. It describes the route an actual employee takes rather than the tidier route in a product demo.

4Fingers captured in the original phone-camera method
$16.5mSeries B funding announced in 2018
24,000Users in the announced National Bank of Egypt project scope

03 / THE PRICE OF ENTRYThe sale is in the seams

In June 2018, Veridium announced a $16.5 million Series B led by Michael Spencer, with Citrix and Michael Powell participating. It was capital for the less glamorous side of biometrics: product development, integrations and selling to large organizations. Veridium does not publish standard customer pricing. A buyer should expect an enterprise conversation about deployment, support and the number and kind of identities to protect, rather than a public checkout page.

In July 2024 the company said National Bank of Egypt had selected it for a passwordless workforce program covering 24,000 users. Veridium said it had been shortlisted against RSA Security and BIO-key. The number describes the announced scope, not a verified count of employees already using the product. Still, it shows the sort of buyer the company courts: an institution with a large workforce, high exposure to phishing and little appetite for breaking its daily access systems.

Veridium also works beside, rather than exclusively against, identity providers. It has published an Okta integration brief and detailed ways to connect with Microsoft Entra ID. In its Entra documentation, a Veridium mobile app can create device-bound FIDO credentials during enrollment; those credentials can be revoked when a device is deregistered. The distinction matters. Making a passkey is easy to celebrate. Removing one from a lost phone is what an administrator needs on a bad Tuesday.

Veridium illustration showing security, compliance and user experience around its authentication platform
Veridium’s own diagram gives security, compliance and user experience equal corners. One is always liable to complain about the other two.

04 / WHAT TRAVELSA good trick needs a boring second act

The market around Veridium is crowded. Microsoft and Okta own many identity front doors; RSA, Ping, BIO-key and others sell strong authentication. Veridium’s claim to a place among them is that it can add a broad selection of authenticators, biometric methods, policies and risk checks while working with the systems a customer already has. Its 2024 product material emphasized on-premises, hybrid and cloud deployment. Its 2026 version 3.9 documentation puts more attention on single sign-on, session security and administrative visibility.

For a security team, the copyable part is the order of operations. Inventory the doors employees actually use. Decide which deserve phishing-resistant factors first. Give people a way to enroll, recover and replace a device. Then measure whether the experience works across VPN, desktop and legacy applications, not merely in a launch-day demonstration. That is a sounder test than counting the number of biometric methods on a brochure.

There are limits. A device-bound passkey needs a device; a biometric system needs usable capture conditions and careful handling of sensitive data; an organization with poor identity records will not fix them by adding a face scan. The promise of continuous authentication also depends on sensible policy: too many prompts recreate the nuisance that passwordless software was meant to remove. Veridium’s range gives an administrator choices, and therefore the responsibility to make them well.

The company began with a vivid image: four fingers in front of a camera. A decade later, the most consequential image is probably much duller - an employee signing in to the right application, on the right device, while nothing remarkable happens. In security, the quiet afternoon is a respectable product.