Frequently asked questions
Everything we’re most often asked about palm vein recognition, security, hardware, deployment and integrating with BioWavePass. Can’t find your answer? Get in touch.
Palm Vein Technology
Palm vein recognition uses near-infrared (NIR) light to capture the unique pattern of veins beneath the surface of your palm, combined with a visible-light scan of the palm surface itself. Because the vein pattern sits under the skin, it can't be photographed, copied or lifted the way a fingerprint or face can — making it one of the most secure biometric modalities available today.
Yes. Palm vein scanning is fully contactless — you simply hover your hand a few centimetres above the sensor. There's no surface contact, so it's inherently more hygienic than fingerprint or card-based systems.
Very. Under the default matching threshold, both the RGB palmprint and NIR palm vein modalities independently reach a false-accept rate (FAR) of one in a million. Because a false accept requires both modalities to fail at once, the combined false-accept risk falls to roughly 1 in hundreds of billions — a financial-grade level of security. Gekonova also offers a large-scale matching model for higher-assurance deployments, which improves both accuracy and security further beyond these default figures.
Yes — the system is designed to work from around age 6 through elderly users, and tolerates natural hand movement during capture rather than requiring you to hold perfectly still.
The sensors are built to operate across a wide range of indoor and outdoor lighting and temperature conditions. Very direct, intense sunlight on the sensor is the main condition to avoid, same as with any optical sensor.
Fingerprints and faces are surface features — they can be photographed, lifted or replicated. Vein patterns are internal, so there's nothing on the surface to copy. Combined with liveness detection, this makes palm vein significantly harder to spoof.
Security, Privacy & Compliance
Yes. Data is encrypted both at rest and in transit — AES-256 class encryption for stored data, TLS/SSL for data in motion.
Data is stored on infrastructure that you (the client) own and control — it never leaves your environment to sit on a third-party biometric cloud. This is a deliberate architecture choice to keep you in control of data residency and compliance.
No. What's stored is a mathematical representation (a “feature template”) derived from your palm — not a viewable image. It cannot be reverse-engineered back into a picture of your hand.
The architecture is designed to support compliance with major frameworks including GDPR, CCPA, LGPD, PDPA and POPIA, and aligns with biometric presentation-attack-detection standards (ISO/IEC 30107-3) and payment standards (PCI DSS, EMVCo) where relevant to the deployment.
Yes. Records can be removed on request, and the system keeps an auditable deletion history for compliance purposes.
Palm vein as an industry is still relatively young, so formal third-party certification schemes are still emerging. Performance figures are based on rigorous internal testing at vendor scale (tens of millions of samples), and we're happy to support additional independent certification where a client's compliance programme requires it.
Hardware & Devices
A range of palm vein terminals and modules covering mobile payment/eKYC (battery-powered, cellular-connected units), fixed retail/access-control terminals, and USB scanner modules for integrating palm vein capture into your own kiosks or POS hardware. Devices also typically support complementary methods like NFC, QR and card, so palm vein can sit alongside — not just replace — your existing checkout or access flow.
Some devices are designed specifically for unstable-power environments, with an internal battery that charges while the unit is in use. On the software side, we also support fully offline/local recognition for sites where network connectivity itself isn't reliable.
Devices are rated for a wide indoor/outdoor temperature and humidity range, so the same core hardware line can serve a retail counter, an outdoor access gate, or a warehouse floor.
Deployment Flexibility
Yes. There are two device-side integration paths: a server-connected mode that talks to a recognition backend (self-hosted by you or scaled up for larger user bases), and a fully local/offline mode that performs matching entirely on the device itself, with no server dependency at all. The offline mode is a good fit for branches, kiosks or remote sites where network connectivity can't be guaranteed.
Yes. For smaller deployments, a containerised (Docker-based) private-server setup is available so you can run the recognition backend entirely on your own infrastructure, rather than depending on any third-party cloud.
Yes. The matching engine is built to scale horizontally — moving from a small pilot to a much larger user base is done by adding backend capacity, with no downtime and no data migration required.
Capacity is tied to the number of registered users, not transaction volume, and can be expanded on request without requiring a new deployment or client-side rebuild. The system also has a defined, graceful response if a capacity ceiling is hit, rather than failing silently — so this is planned for upfront during scoping, not discovered in production.
Developer & Integration
Yes. Our solutions are hardware-agnostic. We support integration with existing POS terminals, kiosks, gates and time clocks via USB, RS232, OTG, and SDK/API libraries for Android, Windows and Linux.
Absolutely. Gekonova offers full SDK and API documentation for easy integration into your system. We support Flutter, React Native and native development for biometric enrolment, liveness checks, transaction authentication and more.
Registration (the first time someone enrols) intentionally uses a slower, higher-quality capture process to build a reliable long-term reference. Everyday identification is optimised for speed instead. Combining both into one tap would slow down every single transaction to accommodate a one-time step, so they're kept as two separate flows.
Yes, a test environment is available for integration and QA before going live, with structured, documented error codes for scenarios like duplicate enrolment or unrecognised users.
A structured result — a match/no-match decision along with confidence scores — rather than any raw biometric data. Your system consumes this result to drive whatever business logic comes next, such as unlocking a door or authorising a payment token.
Native Android is supported out of the box, along with a Flutter layer for cross-platform apps and React Native support. If your team needs a different framework, let us know during scoping and we'll confirm feasibility.
Deployment & Support
Integration can take 2–6 weeks, depending on project complexity. For existing POS systems or partners using Gekonova-approved hardware, MVP setups can be completed in as little as 2–3 weeks.
Yes. Our platforms can be fully white-labelled to match your brand identity. We also support OEM partners who wish to embed Gekonova technology into their own hardware or software ecosystems.
Critical issues are prioritised with defined response targets, and hardware issues are handled via direct replacement. Ongoing support covers deployment assistance, upgrade support and case analysis/optimisation as your deployment matures.
Reach out via our contact page to discuss your project. We'll arrange a call, provide a demo, and map out the best route forward for your biometric or payment needs.
