01
Identity-verification engineering
The engineers who ran the detection stack in production, across roughly 15 million onboardings, for eight years.
Company
TessLabs started inside an identity-verification business in 2018 and spun out at the end of 2025. We are five people, working from DIFC in Dubai.
Background
From 2018 we ran fraud detection inside a live identity-verification business. Over eight years, millions of identity checks passed through that system, and we corrected our detection models against real fraud attempts rather than test datasets.
Privacy rules make it hard to train biometric models on real customer faces at scale, so we built a generator to produce synthetic faces and trained our detectors on those instead.
The generator did better than we planned for. In our own testing, frontier vision-language models accept its output as real between 94 and 100% of the time, which makes the same data useful to any team training a detector. We spun TessLabs out at the end of 2025 to sell it.
# same seed, same person, every run
identity = foundry.seed("0x7F3A_D22F")
render = identity.generate(
gender = "female",
age = 29,
skin_tone = "medium olive",
expression = "neutral",
glasses = "no glasses",
headwear = "no headwear",
)
# 23 independent attribute dials
assert render.identity == identity
# hash-stamped, auditable
The team
TessLabs is five people. Everyone here worked on the detection stack or the generator before the company existed. We can share named backgrounds and references on request.
01
The engineers who ran the detection stack in production, across roughly 15 million onboardings, for eight years.
02
The researchers who established what adversarial pressure looks like at population scale, measured against live attempts rather than benchmarks.
03
The team that turned an internal training tool into a deterministic, mathematically seeded system with 23 independent attribute dials.
How we work
We help teams find and fix the cases where their biometric models accept a synthetic face as real. We work to four rules.
01
Each face comes from a fixed seed. If you cannot regenerate it exactly on your own hardware, we have not finished the job.
02
Every delivery ships with a signed manifest and checksums, so you verify the contents yourself.
04
No real person's face enters the pipeline. These identities are synthetic from the start, which is not the same as anonymised data.
05
We report detection rates for every model we test, including the ones where we score worst, and we label internal testing as internal.
Start with a sample you score yourself, or talk to us about a programme. Nothing is charged and nothing is reserved by asking.