Request a Briefing
Authority Before Autonomy

No autonomous system acts until identity, authority, and live validity are confirmed.

IrisKey.ai licenses a single patented credential architecture that verifies identity and every eligibility condition before granting operational authority — across transport, finance, and beyond. Hardware-anchored, cryptographically verifiable, revocable in real time.

Fleet of commercial trucks on a highway at sunset
Mission

Make every autonomous decision accountable to a verified chain of human authority

No vehicle, driver, or system should be able to act without cryptographic, revocable proof of who authorised it — and whether that authorisation still holds, right now, not at last year's licence renewal.

Driver's hand on the wheel at night
Vision

A transport system where trust is provable, not assumed

Static licensing checks a credential once and trusts it for months. Continuous operational authorisation checks it constantly — closing the licence-shopping, cross-boundary, and phantom-driver gaps that static systems leave open.

01 — Transport

The vehicle no longer trusts the key

Stolen credentials, cloned fobs, unauthorised drivers, drink- and drug-impaired driving, fatigue, fleet misuse — every one of these begins with a vehicle accepting an instruction from someone it should not have trusted. That applies as much to the car on your drive as it does to a haulage fleet.

Driver's hand on the wheel at night
01
Identity

Biometric iris recognition confirms who is actually behind the wheel — not whose fob or card was used.

02
Alcohol

Pupillary response, verified through iris analysis, flags impairment with no breathalyser and no blood sample.

03
Drugs

Multi-spectral iris analysis detects substance impairment as part of the same biometric check.

04
Fatigue

Continuous behavioural sensor monitoring keeps a live fatigue index, not a once-a-shift assessment.

05
Cargo & Manifest

Occupants and payload are verified against what the vehicle is actually authorised to carry.

Distributed revocation is what sits underneath all five gates. When a licence is suspended, a fleet contract ends, or a credential is compromised, every vehicle relying on it knows immediately — no database lag, no overnight sync, no manual enforcement.

This is the infrastructure layer for autonomous vehicles, insurance telematics, private cars, and commercial haulage alike — any vehicle that needs to be accountable to more than its owner.

Where It's Applied

Tuned to what each vehicle actually needs to verify

Fire truck responding to an emergency
Emergency Response

Biometric driver verification, live

Continuous safety and authority checks for ambulance, fire, and rescue drivers, so control rooms know who's behind the wheel and whether they're cleared to respond.

Learn more →
Commercial trucking fleet on a highway
Commercial Fleet

Credentials checked in real time

Licence, medical, and training status validated continuously across HGV and logistics fleets — not once a year at renewal.

Learn more →
London black cab at night
Taxi & Private Hire

Closing the licensing gaps

A single, always-current authority record that closes the licence-shopping and cross-boundary revocation gaps identified in national safeguarding reviews.

Learn more →
Ambulance responding at night
OEM Integration

Hardware-anchored, built in

A credential layer designed to sit inside the vehicle platform itself — secure element to control room — not bolted on after the fact.

Learn more →
02 — Financial Systems

The transaction knows who you are before it clears

Financial systems have spent thirty years layering fraud detection on top of transactions that have already happened. This architecture inverts the problem: authority is established before the transaction is permitted, and withdrawn the instant it shouldn't exist.

01
Biometric presence
not a stolen credential or a bot
02
Jurisdictional threshold
age, licence, accreditation
03
Geography
action is legal where it's taken
04
Device match
the one they registered
05
Live credential
valid right now, not this morning
🎰
Gambling

Age · self-exclusion · jurisdiction · stake limit

🎮
Gaming

Age · parental override · content rating · session limit

🏦
Banking

KYC · fraud score · sanctions-free · spending authority

Tokenisation

Identity-bound quantum token anchored to XRPL / Cardano

Distributed revocation is the commercial breakthrough here too. A self-excluded gambler is stopped at every operator, instantly. A compromised card is dead across every merchant, instantly. Not by a central database — by an architecture that doesn't need one.

03 — The Core Credential

One architecture. Every domain.

A single patented system verifies identity and every eligibility condition simultaneously, before granting any operational authority — transport, gambling, gaming, banking, or tokenisation. Same five-element architecture. Same enforcement logic. Domain-agnostic by design.

Macro photograph of a secure circuit board

An operational authority credential is issued only once every stream is satisfied: biometrically verified identity, every active eligibility check evaluated in parallel, and cryptographic binding inside a hardware secure element with non-exportable private keys. One stream failing denies the credential, regardless of the others.

Invalidation is deterministic and non-overridable. The instant a regulator, a fleet manager, a self-exclusion register, or a fraud authority withdraws authority, the platform drops to a restricted or fallback state — a controlled stop in a vehicle, a frozen account in gambling, a suspended transaction in banking. No override, no operator workaround.

Revocation works offline, too. A locally cached list enforces invalidation for up to 72 hours without live network connectivity — so a self-excluded gambler is blocked everywhere the instant the signal propagates, with no central database and no manual process.

🚗
Transport

Sobriety + drug-free + identity + fatigue + cargo

🎰
Gambling

Age + self-exclusion + jurisdiction + stake limit

🎮
Gaming

Age + parental override + content rating + session limit

🏦
Banking

KYC + fraud score + sanctions-free + spending authority

Wind turbine generating renewable energy in an open field
04 — Energy Architecture

Power where the grid cannot reach

Sensors, credentials, vehicles, remote installations, and sovereign infrastructure all share a constraint: continuous power in places where continuous power isn't available. Batteries run down. Cables end. Solar fails at night.

This architecture pulls energy from multiple sources at once — movement, thermal gradient, vibration, electromagnetic ambient — and combines them into one reliable supply. Where one source fades, another carries the load. Applications span autonomous remote sensors, vehicle-integrated credential hardware that never needs charging, defence and maritime installations beyond the grid, and industrial IoT without the maintenance tax of battery replacement.

Light filtering through deep ocean water
05 — Sovereign Compute

OceanGrid — beneath the sea

The cloud sits on someone else's land, under someone else's jurisdiction, on someone else's grid. For nations and industries whose data can't leave their sovereign envelope, that's no longer acceptable.

OceanGrid places distributed compute on the seabed within national waters — cooled by the ocean for free, powered continuously by marine energy, serviced by a resident fleet of autonomous underwater vehicles. A quantum-hardened governance layer sits above the physical architecture, enforcing who can compute what, where, and under whose authority — cryptographically, not contractually. When authority is revoked, compute stops.

Secure network infrastructure cabling
06 — Defence & Public Sector

Built to grade, not just to work

Defence and public-sector procurement doesn't accept "it works" as an answer. It wants a documented case for exactly how a system fails, and what happens next — environmental qualification, a formal safety case, configuration management, supplier-level cyber assurance.

The same credential architecture already carries that discipline: deterministic invalidation, no operator workaround, an audit trail built to hold up to scrutiny. IrisKey.ai is engaged with UK defence and public-sector innovation programmes and working toward the standards that sector requires.

Def Stan 00-35 — Environmental
Def Stan 00-56 — Safety Management
Def Stan 05-57 — Configuration Management
Def Stan 05-138 — Cyber Security for Suppliers
5
Patent families
across the portfolio
1
Filed & live
UK credential patent
1
PCT-ready
ahead of the 2027 window
10%
Corporation tax rate
under UK Patent Box
UK
Coventry-based,
IP-licensing only
The Founder

Why this company exists

Twenty-five years in the automotive industry came before the first patent. Around 2013, that included co-founding one of the UK's first 3G connected vehicle dashcam systems — a business later taken through a coordinated partner conspiracy, its technology misappropriated. A £4.5 million judgment followed in 2022; the professional negligence proceedings that came after are still ongoing.

The legal outcome matters less than the lesson it left: disclose before you file, trust before you verify, and the infrastructure you built becomes someone else's asset. IrisKey.ai is built on the opposite protocol — patent first, NDA before disclosure, license rather than manufacture. IP that appreciates over decades, not products that depreciate over quarters.

"Built for the generation that will inherit these systems."
— Adam McCrum, Founder & CEO
The Closing Thesis

Universal security

Every system now acts on someone's behalf. Vehicles drive themselves. Agents move money. Models make decisions. The question is no longer what can it do — it's who authorised it, and can that authority be revoked the instant it shouldn't exist?

Control room monitors

One architecture enforces identity, authority, and live validity at the infrastructure layer — not the application layer, not the policy layer, not after the fact. The same five-element model expressed across transport and finance is domain-agnostic by design.

We do not manufacture. We license. The portfolio is Patent Box qualified and structured for long-term sovereign, financial, and industrial partners.

SME News UK Transport Awards 2026 — Best Transport Safety & Security Technology Innovator
Working with automotive research universities on validation
DfT / Innovate UK pitch in preparation
Let's Talk Licensing

Building autonomous or semi-autonomous vehicle systems?

IrisKey.ai licenses its patent portfolio to OEMs, fleet operators, and government partners under the UK Patent Box regime. If continuous operational authorisation is part of your roadmap, we should talk.

Get in Touch