Interviews
Ricardo Amper, CEO and Founder of Incode – Interview Series

Ricardo Amper, CEO and Founder of Incode, is a serial entrepreneur and technology executive with more than two decades of experience building and scaling companies across technology, consumer products, and industrial sectors. He founded Incode in 2015 with the vision of transforming how people verify and authenticate their identities in the digital world. Previously, Amper served as CEO of Grupo Amco, Latin America’s leading aroma chemicals and essential oils business, where he developed OneView, a machine learning-based predictive data platform, before the company was acquired by Brenntag Group. He also co-founded and led Amco Foods, which was acquired by Grupo Bimbo, and earlier founded La Burbuja Networks. His career combines entrepreneurship, artificial intelligence, data-driven systems, and experience successfully building companies through acquisition.
Incode is an AI-powered identity platform designed to help organizations establish trust across interactions with people, businesses, and increasingly AI agents. Its technology combines document verification, biometric authentication, facial recognition, liveness detection, deepfake detection, and direct checks against government systems of record, while supporting areas including Know Your Customer (KYC), Anti-Money Laundering (AML) compliance, Know Your Business (KYB), age assurance, workforce verification, and account takeover prevention. Incode develops its AI technology in-house and has expanded its platform to address emerging threats such as synthetic identities and generative AI-enabled fraud, as well as Agentic Identity tools for verifying the owners of AI agents and tracing their actions.
You founded Incode in 2015 after building companies in very different industries, and you have argued that approaching problems with a fresh, first-principles mindset can be more valuable than relying on inherited industry assumptions. What did you see in identity verification that established providers were missing, and how has that original insight shaped Incode’s development?
Pre-2015, the industry treated identity as a compliance problem and afterthought: scan a document, have someone in a back office review it, check the box. I came in without that inference and saw an AI problem with the industry’s approach to identity.
So made three decisions on day one that nobody else was making:
AI does the verification instead of humans looking at your data, we develop every layer of the technology ourselves instead of assembling other people’s parts, and privacy is architecture, not policy. Ten years later, generative AI has made those the only decisions that hold up.
That choice shaped the company we became.
- We are builders first: even today, a larger share of our people work in engineering and product than at a typical B2B software company, and that is what keeps us nimble enough to adapt as fast as the threat does.
- We also deliberately started in one of the hardest fraud environments in the world, Latin America, and largely solved it for some of the region’s biggest banks and enterprises. When your technology survives there, markets where fraud is real but less relentless become a much easier test.
We have never been interested in patching problems or making companies merely compliant for today. We enjoy the hard version of this problem: verify a real person with the least possible friction and the strongest possible privacy, and do it for a future that is changing.
Incode has now been named a Leader in the Gartner® Magic Quadrant™ for Identity Verification for three consecutive years. What do you believe this consistency says about how the company has evolved, and which capabilities were most important to maintaining that position as the threat landscape changed?
Anyone can have a good year. Three consecutive years reflects consistency, and consistency is what enterprises buy. Those three years span the entire generative AI fraud wave, and the thing that helped us maintain our status as the industry leader through it is that we own our full technology stack. When a new attack class or vector appears, we retrain our own models in days instead of waiting on someone else’s product roadmap or updates. The other constants are our direct connections to authoritative identity sources and the discipline of treating conversion as seriously as fraud, because enterprises need both.
Incode describes a new generation of autonomous fraud attacks in which AI agents can generate synthetic documents, produce targeted deepfakes, test them against verification systems, and adapt after each rejection. How close are we to seeing these fully automated attack workflows operate at scale?
Fraud at scale always required people at scale. The bottleneck was human, and AI has just removed it. We went looking for the evidence and published what we found: publicly reported, independently sourced AI-enabled fraud incidents in the United States, large part of them confirmed in court filings or regulatory actions. When we scored how much of each scheme an autonomous agent could run on its own, almost all could run end to end, and not one was immune. The old model was capped by how many skilled people you could recruit. The new one is capped only by compute.
Incode says it continuously runs an agentic attacker against its own defenses. How does this adversarial testing process work, and what can an AI attacker uncover that conventional penetration testing or static fraud benchmarks might miss?
The idea is simple: the only way to build defenses against these attacks is to run the attacks against ourselves first. So we operate an attacker that works exactly like the criminal ones. It generates deepfakes, synthetic documents, and injection attempts, submits them to our own live defenses, learns from every rejection, and comes back with a better variant. A conventional penetration test checks a known list of attacks once and goes home. An adaptive attacker never stops inventing new ones, so it finds the weak point, and the attack that does not exist yet, before a criminal does.
As generative models make synthetic documents and biometric media increasingly convincing, which signals remain the most difficult for attackers to fabricate reliably?
The pixels are a losing game if that is all you look at, because generative models improve every month. What attackers still cannot fabricate reliably is everything outside the image: the integrity of the device and capture path the media traveled through, behavior that stays consistent across sessions, and the record held by the source that issued the identity. That is the principle behind Deepsight, our deepfake detection technology. It never judges the image alone: it analyzes the media, the hardware, the software path, and user behavior in a single real-time decision, and it can identify which generative model produced a fake. Purdue University independently tested it against 24 other government, academic, and commercial systems and validated it as the most accurate.
Incode emphasizes verifying identities against authoritative government records rather than relying solely on the document presented by a user. How does this change the accuracy of identity verification, and what technical or regulatory challenges arise when deploying this approach across different countries?
A document tells you what was presented. The authoritative record tells you what is true. Every check that judges whether an artifact looks authentic keeps losing ground as generative AI improves, but a government record does not, because it is ground truth the fraudster cannot control. The challenges are real: every country has different authoritative sources, different access rules, and different privacy law, so we build direct connections market by market and process everything under privacy by design.
Identity verification systems must stop sophisticated fraud without creating unnecessary friction for legitimate users. How do you evaluate the trade-off between security, false rejections, onboarding speed, and conversion?
Every identity provider is pulling levers between those four things. The real question is which levers you own. Much of the industry implements technology it licensed from someone else, so when fraud spikes they cannot see inside the model or retrain it, and the only lever left is friction: more steps, more manual review, more good users rejected. We made the opposite choice and develop every AI model ourselves, liveness, deepfake detection, document verification, all of it, so our lever is accuracy. We retrain in days, push fraud down inside the model, and leave the user experience alone. That is why letting every good user through and stopping every attack is one job for us, not a trade.
Incode’s trust network is designed to identify repeat fraud and recognize trusted histories across organizations without pooling raw personal data. What technologies make that type of privacy-preserving intelligence sharing possible?
Cryptography is the enabler, but the concept is the point: collaboration without exposure. Organizations in the network can learn whether an identity signal has been tied to fraud elsewhere without any party ever seeing another’s data, so there is no pooled database, nothing to breach, and no data brokerage. This is why we acquired Identiq, whose team spent years building exactly this privacy-enhancing cryptographic technology, and why we are committing more than 100 million dollars this year to privacy-preserving identity infrastructure. The network gets smarter with every verification while every individual’s data stays sealed, on the scale of more than 7 billion trust checks and 400 million profiles. We have always believed privacy and fraud prevention are not a tradeoff. They are the same problem, solved together or not at all.
As AI agents begin making purchases, accessing accounts, signing agreements, and communicating on behalf of people, how should organizations verify not only the agent itself, but also its owner, permissions, and authority to perform a specific action?
Start with the owner, because an agent’s authority means nothing if it does not trace back to a verified human. That is exactly what we built Agentic Identity for: we verify the owner with high-assurance identity proofing and deepfake-resistant liveness, issue the agent a secure token that links every action back to that accountable person, and verify its permissions scope so an agent authorized for one task cannot quietly drift into others. Then we monitor continuously, because agents change behavior faster than any quarterly access review. It is the same biometrics, the same fraud intelligence, the same network we use for humans, extended to the systems acting on their behalf.
Looking ahead, will identity verification remain a distinct checkpoint during onboarding, or will it become a continuous trust layer operating throughout every digital interaction between people, businesses, and autonomous AI agents?
Both for a while, and then continuous wins. Onboarding stays as the anchor where identity is established at the highest assurance, but trust cannot remain a moment in time when attacks adapt across sessions and agents transact around the clock. The destination is a persistent trust layer: re-verification at moments of real risk, behavioral and network signals correlated continuously, and the same accountability extended to AI agents acting on people’s behalf. Identity stops being a checkpoint and becomes infrastructure, and we are building for that world.
Thank you for the great interview, readers who wish to learn more should visit Incode.












