Use iBeta's published ISO/IEC 30107-3 PAD confirmation letters to evaluate and select a liveness detection vendor by certification level rather than marketing claims
domain: ibeta.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
Pull the vendor's specific iBeta PAD confirmation letter rather than relying on a general 'iBeta certified' claim, since letters specify the exact product configuration and SDK version tested
Confirm whether the vendor achieved Level 1 (basic 2D presentation attacks: printed photos, screen replays) or Level 2 (more sophisticated attacks: masks, 3D models) certification
Check the test date and product version on the letter against the version you would actually deploy, since certification does not automatically carry forward to later major releases
Cross-reference the certified configuration (e.g., passive vs. active/challenge-response liveness) against the actual mode you intend to use in production
Factor certification level into vendor selection alongside your threat model — Level 2 is appropriate where mask/3D-model attacks are a realistic risk (e.g., regulated financial onboarding)
Known gotchas
A vendor can hold a valid Level 1 certification while marketing it ambiguously as 'iBeta certified' without disclosing that Level 2 was not achieved — always check the letter for the specific level and attack types covered
Certification applies to a tested SDK version and configuration; upgrading the vendor's SDK or changing capture settings can invalidate the assurance the certification implied
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?