
For decades, identity verification (IDV) has forced organizations into an impossible choice: accept more fraud to keep conversion high, or add friction to stop more fraudsters and watch legitimate users walk away. This tradeoff has been treated as a law of physics: painful, but unavoidable.
To solve this tradeoff, IDV systems must accomplish two things. First, they must confirm that the user is who they claim to be. Second, they must confirm that the session itself hasn’t been faked. Perhaps most importantly, they must accomplish both without introducing friction for legitimate users.
That's exactly what GovFaceMatch and Deepsight deliver, together.
Traditional identity verification falls into two categories, each with a critical flaw.
Non-document verification runs background checks against data sources, including credit bureaus and telecom records, creating a frictionless experience for users. But those checks only confirm that data exists, not that the person presenting it is who they claim to be. That means synthetic and stolen identities pass, and fraud slips through at scale.
Document-based verification improves fraud capture by requiring users to capture their identity document alongside a live selfie. But every additional step comes at a cost. Incode data shows that 40% of legitimate users abandon document-based verification flows before completing them.
The result: organizations are either inviting fraud or turning away legitimate customers. Both outcomes directly impact the bottom line.
This tradeoff plays out across two dimensions. The first is identity authenticity: fraudsters combine real stolen PII, high-quality fabricated documents, and their own photos to pass traditional checks. The second is session authenticity: what seems like a high-assurance flow can be hijacked by deepfake injection attacks that impersonate real users with synthetic video, bypassing liveness checks without adding a second to the fraudster's experience.
Traditional identity verification wasn't built to address either dimension fully. It can't confirm that the identity belongs to the person presenting it, and it can't confirm that the session itself is genuine. GovFaceMatch closes the first gap by matching a live biometric directly against the DMV's issuing record. Deepsight resolves the second by confirming that the session represents a real person on a real device in real time.
Together, they answer both questions, all without adding friction for legitimate users.

The conversion-fraud tradeoff was already costly. The rise of AI has turned it into an existential threat.
On the identity side, modern fraudsters no longer need to invent identities. They use real identities, stolen at scale. There have been over 18,000 data breaches in the U.S. in the last decade, with a record 3,300+ data compromises in 2025 alone, including over 1,000 that specifically exposed Driver's License numbers.
Armed with real stolen personally identifiable information (PII), bad actors use AI to generate fake ID documents that pass almost every document check. High-quality synthetic IDs can be produced for as little as $15 in minutes. The fraudster presents their own face alongside the fabricated document, and every probabilistic check sees consistency.
On the session side, AI has made it equally trivial to fake the interaction itself. Virtual cameras, rooted devices, and automated bots now allow fraudsters to inject synthetic video feeds mid-session, impersonating real users in ways that bypass basic liveness checks. These injection attacks are the fastest-scaling vector in fraud today. By replaying synthetic content during live sessions, fraudsters transform individual attempts into high-volume, automated pipelines.
Case in point: Incode customers have experienced a 7x increase in deepfake-driven impersonation attempts over the last two years, and Deloitte projects that generative AI could drive total fraud losses in the US to $40 billion by 2027.
Organizations now face two simultaneous attack surfaces, and traditional identity verification was never designed to properly address either of them. Adding more friction doesn't close these gaps. It just costs you more legitimate users.
The solution is a structurally different kind of verification, one that addresses both attack surfaces simultaneously, and does so without adding steps or wait time for the real users who belong there.
GovFaceMatch closes the identity gap. Users complete two simple steps: scan their driver’s license barcode and take a live selfie. GovFaceMatch sends only the minimum required information to the state DMV to biometrically match the live selfie against the DMV’s authoritative portrait and return a deterministic match result. No front ID image is required. Facial biometrics can be deleted immediately following verification, and no government-held PII ever leaves the DMV environment.
The difference from traditional identity verification is structural. Traditional checks compare a selfie to a cropped image from a submitted document, a comparison that can be manipulated. By matching biometrics against government records, GovFaceMatch confirms not only that an identity exists in a database, but that the person in front of the camera is the person that identity belongs to. This is why GovFaceMatch is 150x more accurate than traditional document-based verification alone.
Deepsight closes the session gap. While GovFaceMatch confirms the identity, Deepsight verifies that the interaction is real: a real person, a real device, an unmanipulated video feed, captured at the time of verification. It operates across three coordinated layers:
All of this runs in the background, with zero additional steps and no increase in processing time for legitimate users.
Because both products are designed to eliminate friction (GovFaceMatch by replacing front and back ID capture steps with a simple barcode scan, and Deepsight by operating entirely in the background), they compound each other's conversion benefit rather than offsetting it. The result is a 20% improvement in overall conversion rate alongside the most accurate fraud capture available. More real users are approved, while more sophisticated attacks are stopped. No tradeoff required.
With Deepsight and GovFaceMatch, Incode presents the most robust, enterprise-ready IDV system on the market: identity confirmed at the source, session confirmed in real time, and the user experience protected throughout.
Interested in learning more about ending the tradeoff between conversion and fraud prevention?
Request a demo today.