Business
BIO key International : Amendment to Annual Report (Form 10-K/A)
BIO key International : Amendment to Annual Report (Form

About this update from Bio-key International, Inc.
[{"type":"text","content":" \n \n \n This Amendment No. 1 (the \"Amendment No. 1\") to the Annual Report on Form 10-K of BIO-key International, Inc. (the \"Company\") for the year ended December 31, 2025, originally filed with the Securities and Exchange Commission on June 12, 2026, is being filed solely to replace the Report of Independent Registered Public Accounting Firm and the Consent of Independent Registered Public Accounting Firm. For ease of reference the Company is refiling the Annual Report on Form 10-K in its entirety. The Company is also including in this Amendment No. 1 currently dated certifications from its Chief Executive Officer and Chief Financial Officer as required by Sections 302 and 906 of the Sarbanes-Oxley Act of 2002 as Exhibits 31.1 and 31.2 and Exhibits 32.1 and 32.2, respectively.\n \n Table of Contents \n TABLE OF CONTENTS\n \n \n PART I\n \n 1 \n \n Item 1.\n \n \n Business\n \n \n 1\n \n \n Item 1A\n \n \n Risk Factors\n \n \n 9\n \n Item 1B\n Unresolved Staff Comments \n \n 18\n \n Item 1C\n Cybersecurity \n 18 \n \n Item 2\n \n \n Properties\n \n \n 18\n \n \n Item 3\n \n \n Legal Proceedings\n \n \n 18\n \n \n Item 4\n \n \n Mine Safety Disclosures\n \n \n 18\n \n \n PART II\n \n 19 \n \n Item 5\n \n \n Market for Registrant's Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities\n \n \n 19\n \n \n Item 6\n \n \n Reserved\n \n \n 19\n \n \n Item 7\n \n \n Management's Discussion and Analysis of Financial Condition and Results of Operations\n \n \n 20\n \n \n Item 7A\n \n \n Quantitative And Qualitative Disclosures About Market Risk\n \n \n 25\n \n \n Item 8\n \n \n Financial Statements and Supplementary Data\n \n \n 25\n \n \n Item 9\n \n \n Changes in and Disagreements with Accountants on Accounting and Financial Disclosure\n \n \n 25\n \n \n Item 9A\n \n \n Controls and Procedures\n \n \n 26\n \n \n Item 9B\n \n \n Other Information\n \n \n 26\n \n \n Item 9C\n \n \n Disclosure Regarding Foreign Jurisdictions that Prevent Inspections\n \n \n 26\n \n \n PART III\n \n 27 \n \n Item 10\n \n \n Directors, Executive Officers and Corporate Governance\n \n \n 27\n \n \n Item 11\n \n \n Executive Compensation\n \n \n 30\n \n \n Item 12\n \n \n Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters\n \n \n 35\n \n \n Item 13\n \n \n Certain Relationships and Related Transactions, and Director Independence\n \n \n 37\n \n \n Item 14\n \n \n Principal Accountant Fees and Services\n \n \n 38\n \n \n PART IV\n \n 39 \n \n Item 15\n \n \n Exhibits and Financial Statement Schedules\n \n \n 39\n \n \n Item 16\n \n \n Form 10-K Summary\n \n \n 40\n \n \n Signatures\n \n \n 74\n \n Table of Contents PRIVATE SECURITIES LITIGATION REFORM ACT \n All statements other than statements of historical facts contained in this Annual Report on Form 10-K, including statements regarding our future financial position, business strategy and plans and objectives of management for future operations, are forward-looking statements. The words \"anticipate,\" \"believe,\" \"should,\" \"estimate,\" \"will,\" \"may,\" \"future,\" \"plan,\" \"intend\" and \"expect\" and similar expressions generally identify forward-looking statements. These statements are not guarantees of future performance or events and are subject to risks and uncertainties that may cause actual results to differ materially from those included within or implied by such forward-looking statements. These risks and uncertainties include, without limitation, our history of losses and limited revenue; our ability to raise additional capital; our ability to continue as a going concern; our ability to protect our intellectual property; changes in business conditions; changes in our sales strategy and product development plans; changes in the marketplace; continued services of our executive management team; security breaches; competition in the biometric technology and identity access management industries; market acceptance of biometric products generally and our products under development; our ability to convert sales opportunities to customer contracts; our ability to expand into Asia, Africa and other foreign markets; our ability to migrate Swivel Secure customers to BIO-key and Portal Guard offerings; our ability to execute definitive agreements with Fiber Food Systems and/or its customers to utilize our access management solutions; our ability to integrate our solutions into any of Fiber Food System's offerings; fluctuations in foreign currency exchange rates; the duration and extent of continued hostilities in Ukraine and its impact on our European customers; the impact of tariffs and other trade barriers which may make it more costly for us to import inventory from China and Hong Kong and certain product components from South Korea; delays in the development of products, the commercial, reputational and regulatory risks to our business that may arise as a consequence of non-compliance with Securities and Exchange Commission (\"SEC\") and Nasdaq periodic reporting requirements; the commercial reputational and reputational risk and impact on the trading and liquidity of our common stock as a result of the recent suspension of trading of our common stock on the Nasdaq Capital Market; our temporary loss of the use of a Registration Statement on Form S-3 to register securities in the future; any disruption to our business that may occur on a longer-term basis should we be unable to maintain effective internal controls over financial reporting, statements of assumption underlying any of the foregoing, and numerous other matters of national, regional and global scale, including those set forth under the caption \"Risk Factors\" in Item 1A of this Annual Report and other filings with the SEC. These factors are not intended to represent a complete list of the general or specific factors that may affect us. It should be recognized that other factors, including general economic factors and business strategies, may be significant, presently or in the future. Except as required by law, we undertake no obligation to update any forward-looking statement, whether as a result of new information, future events or otherwise.\n \n Table of Contents PART I \n ITEM 1. BUSINESS \n Solely for convenience, trademarks and tradenames referred to in this Annual Report on Form 10-K appear (after the first usage) without the ® and ™ symbols, but those references are not intended to indicate, in any way, that we will not assert, to the fullest extent under applicable law, our rights or that the applicable owner will not assert its rights, to these trademarks and tradenames.\n Overview \n BIO-key International, Inc. (the \"Company,\" \"BIO-key,\" \"we,\" or \"us\") is a leading identity and access management (IAM) platform provider enabling secure work-from-anywhere for enterprise, education, and government customers using secure multi-factor authentication (MFA). Our vision is to enable any organization to secure streamlined and passwordless workforce, customer, citizen and student access to any online service, workstation, or mobile application, without a requirement to use tokens or phones for roving users and shared workstations. Our products include PortalGuard® and PortalGuard Identity-as-a-Service (IDaaS) enterprise IAM, WEB-key® biometric civil and large-scale ID infrastructure, MobileAuth® mobile phone authentication application for iOS and Android, and high-quality, low-cost accessory fingerprint scanner and FIDO-compliant hardware to provide a full and complete solution for identity-innovating customers.\n \n \n \n BIO-key PortalGuard empowers organizations to maximize the power of cloud, mobile and web technologies by securing users' identities and connecting them with the applications they rely on, while keeping cyber-intruders and unauthorized delegates (proxy users) out. Competing MFA solutions require a phone or token for every user authentication use case, but this is expensive and ineffective for workforce users who cannot use a phone in their workplace, who rove among workstations or share kiosks for access to information systems. BIO-key's exclusive Identity-Bound Biometrics (IBB) authentication methods address this by making biometric identification based available at any end point device, making the user, not their phone or a token, their own credential.\n \n \n \n Our customers trust BIO-key® to secure access to a variety of cloud, mobile and web applications, on-premise and cloud-based hypervisor servers from all of their devices. Employees and contractors sign into BIO-key PortalGuard to seamlessly and securely access the applications needed to do their work, and customers sign into BIO-key PortalGuard to access online services. Organizations use PortalGuard to securely collaborate and communicate with their partners and to provide their customers with flexible, resilient user experiences online and while using mobile devices. PortalGuard can operate standalone as a comprehensive MFA, Single Sign On, and Self-Service Password Reset solution, directly authenticating for Windows sign in and application access, or as an upgraded MFA user experience within an enterprise IAM framework such as Microsoft, Okta, Ping or ForgeRock.\n \n \n \n BIO-key's WEB-key is a scalable biometric service management platform, incorporating key functions for regulatory compliance, enrollment, authentication or identification, and integrity in a multi-tenant private or public cloud delivery platform. Government agencies use BIO-key for their large-scale civil ID projects, because WEB-key underpins a biometric identity ecosystem, is cloud-ready, and provides a scalable, high-integrity trust platform which can be operated anywhere and supports over 30 fingerprint scanners interchangeably.\n \n \n \n We also deliver biometric software integration application programming interfaces, or APIs, allowing software developers to leverage our platform to securely and efficiently embed biometric multi-factor authentication, or MFA, into their own products. This allows software developers to focus on their core functionality while BIO-key ensures users enter the application without requiring them to carry their phone or any token.\n \n \n \n Even the most security-focused organizations are suffering breaches as a result of human error or improper conduct. As enterprises scale the number of software as a service, or SaaS applications, and multi-cloud services they rely on and the interconnections between them increase, assured identity has emerged as a critical component of an organization's security framework, directly affecting each triad of cybersecurity - confidentiality, integrity, and availability. As access perimeters dissolve, organizations must evolve from network-based security models to Zero Trust and Continuous Authentication and Risk Trust Assessment (CARTA) security models, focusing on adaptive and context-aware controls. True server-secured biometric verification removes the human nature vulnerability at the root of many security compromises creating a more reliable means to manage user access and protect digital assets against rogue users willing to hand over their credentials to a proxy. Our global identity as a service, or IDaaS, hosting capability allows our customers to simplify and efficiently scale their security infrastructures across internal IT systems and external customer facing applications without installation overhead, security or uptime management efforts.\n Table of Contents \n We designed BIO-key PortalGuard IDaaS and WEB-key to provide organizations an integrated approach to managing and securing all of their identities using the technologies they already use while providing capacity for future needs through the strategic use of biometrics to limit vulnerability and contain authentication costs. Our platform allows users to authenticate their customers, employees, contractors, and partners. It enables any user to connect to any device, cloud or application, all with a simple, customizable, intuitive and consumer-friendly user experience. We utilize server-secured Identity-Bound Biometrics to support roving users without requiring them to carry their phone or a token. As of December 31, 2025, more than 600 customers across multiple industries use BIO-key to secure and manage access for users around the world.\n Development of Business \n BIO-key was founded in 1993 to develop and market advanced fingerprint biometric technology and related security software solutions. First incorporated as BBG Engineering, the company was renamed SAC Technologies in 1994 and renamed BIO-key International, Inc. in 2002. Our principal executive office is located at 101 Crawfords Corner Road, Suite 4116, Holmdel, NJ, 07733. \n \n \n \n BIO-key was a pioneer in developing automated finger identification technology that supplements or compliments other methods of identification and verification, such as personal inspection identification, passwords, tokens, smart cards, ID cards, credit card, passports, driver's licenses, or other form of possession or knowledge-based credentialing. Our advanced technology and is used to improve both the accuracy and speed of fingerprint biometrics in some of the largest biometric systems in the world.\n \n \n \n On June 30, 2020, we enhanced our product offering by acquiring PistolStar, Inc. (\"PistolStar\"). PistolStar provides enterprise-ready identity access management solutions to commercial, government and education customers throughout the United States and internationally. PistolStar develops and markets our PortalGuard line of software and services. \n \n \n \n On March 8, 2022, we expanded our sales and support operation into Europe, Africa and the Middle East (\"EMEA\") by acquiring Swivel Secure Europe, SA. Swivel Secure Europe is a Madrid, Spain based provider of IAM solutions serving over 300 customers through a network of dozens of channel partners throughout EMEA. Until the fourth quarter of 2024, Swivel Secure Europe was the exclusive distributer of the AuthControl® Sentry, AuthControl Enterprise, and AuthControl MSP product line in Europe, Middle East, and Africa, excluding the United Kingdom. Swivel Secure, now operates under the name BIO-key EMEA, maintains a direct sales force with offices in Madrid, Spain and Lisbon, Portugal, and sells only BIO-key hardware, software and services.\n \n \n \n On November 27, 2024, we commenced a collaboration with Fiber Food Systems, Inc., an early-stage company engaged in developing global food security solutions. Under this arrangement, we are working to explore IAM use cases across the food industry. As part of this agreement, we acquired shares of Boumarang, Inc. from Fiber. Boumarang is developing sustainable, AI-driven, hydrogen-powered, long-range drone technology. We are working with Boumarang and its partners to integrate our biometric technology into autonomous systems, targeting applications across aerospace and other industries. We expect that these initiatives have the potential to create new commercial opportunities in future periods.\n Our Products \n BIO-key PortalGuard and PortalGuard IDaaS \n BIO-key PortalGuard is an independent, customer-controlled and neutral-by-design cloud-based identity platform that allows our customers to integrate with any cloud or on-premise SaaS application, service or cloud host, as well as Windows device authentication through a single secure, reliable and scalable IAM platform. It provides identical capabilities in both a SaaS (PortalGuard IDaaS) or on-premise (PortalGuard) delivery model. PortalGuard integrates BIO-key's Identity Bound Biometric (IBB) authentication as what-you-are authentication options that are not tied to a device or \"what you have\" authentication, allowing our customers to positively identify who is accessing their systems, not the device they might have handed off to another user. Our three-way IAM neutrality consists of:\n \n \n ●\n \n \n seventeen MFA authentication factor choices, including our server-secured IBB via fingerprint scanners, or using a palm scan, facial selfie, or voice biometric via our MobileAuth app on a mobile phone;\n \n \n ●\n \n \n open user directory choices including on premise, hybrid or full-Azure Active Directory, LDAP, IBM Domino, or custom SQL user directory; and \n \n \n ●\n \n \n multiple single sign on, or SSO, federation options, including SAML, Open ID Connect (OIDC), OAUTH, CAS and WS-Fed.\n \n \n \n These capabilities allow our customers to combine and authenticate legacy and future technologies and to securely connect users to the technology that they choose. We design transparent compatibility of the BIO-key PortalGuard IDaaS with on-premise infrastructures and public and hybrid clouds.\n \n \n \n Our customers use the BIO-key PortalGuard IDaaS to secure their workforces and student populations and make their partner networks more collaborative. PortalGuard IDaaS provides more and secure experiences for their customers and end users, which enables our customers to future-proof their environments. PortalGuard IDaaS can be used as the central system for an organization's connectivity, access, authentication and identity lifecycle management needs across all of its users, technology and applications. We enable our customers to easily deploy, manage and secure applications and devices, and offer provisioning services using open source tools.\n \n \n \n Developers can leverage an extensive suite of API and modular SDK tools to build custom cloud, mobile and web application enrollment and authentication experiences that leverage BIO-key PortalGuard and WEB-key as the underlying identity management platform. Once deployed, PortalGuard allows administrators to enforce contextual access management decisions based on conditions such as user identity, device, geolocation, application destination identity, IP range, and time of day.\n Table of Contents \n Our customers use BIO-key to (i) manage and secure work-related IT access of their employees, contractors and supply chain partners, which we call workforce identity; and (ii) manage and secure the identities of users of their web properties, which we call customer identity.\n BIO-key PortalGuard and PortalGuard IDaaS for Workforce Identity . PortalGuard streamlines the way an organization's employees, contractors and supply chain partners connect to its applications and data from any device, while increasing user efficiency, preventing unauthorized delegation, credential sharing, and keeping digital environments secure through our MFA capabilities. We enable organizations to provide their workforces with immediate and secure access to every application from any device they use, without maintaining multiple credentials. Our multi-directory support interfaces with the directories in place at an organization, while allowing SQL-based custom directories where none presently exist. BIO-key PortalGuard Desktop allows customers to extend the BIO-key PortalGuard IDaaS to their existing on-premises and remote workstation Windows sign in. \n BIO-key PortalGuard and PortalGuard IDaaS for Customer Identity . BIO-key PortalGuard allows organizations to secure access to their online properties, while upgrading their customers' user experience by delivering self-enrollment and management for customer-facing cloud, mobile or web applications. We enable an organization's product team to layer BIO-key's MFA, SSO and self-service password reset, or SSPR, functionality into their cloud, web and mobile applications through federation standards or using our APIs. Our customers are able to centrally manage policies, audit and log access across their properties, leading to more seamless customer experiences.\n BIO-key VST and WEB-key; Products; Civil and Large-Scale ID Infrastructure \n We have developed what we believe is the most discriminating and effective commercially available finger-based biometric technology. This technology is embedded in our PortalGuard product for enterprise security, providing customers with a unique capability to authenticate users without a phone or token, where appropriate, such as manufacturing, retail, call centers, and health care workers. Other markets for scalable biometric engines include government markets, large scale identity projects such as voter's registration, driver's license, national ID programs, and SIM card registration.\n \n \n \n We also offer a full line of easy to use finger scanners for both enterprise and consumer markets. Our PIV Pro, SidePass®, EcoID II® and SideSwipes® finger readers can be used on any laptop, tablet or other device which contains a USB A or C port. We market and sell these fingerprint scanners through distributors and directly to end users via Amazon.\n Fingerprint Readers \n Our series of compact fingerprint readers, we find commercial companies use SidePass®, SideSwipe® or EcoID II® to replace their Windows passwords and enable Windows Hello for Business without replacing or upgrading laptops or tablets.\n Identity and Access Management, User Multi-Factor Authentication, Single Sign On, Privilege Entitlement and Access Control \n Our products simplify the authentication process for enterprise users and consumers, while raising security levels. This allows our customers to meet new, stronger authentication requirements and security best practices across many industries, while delivering a superior end-user experience. Customers use our products to reduce risk of theft, fraud, loss, account takeover attacks, and unauthorized account sharing by limiting access to valuable assets, privileges, data, services, networks and places to only authorized individuals. Our products provide stronger identity binding and a superior user experience versus traditional credentialing systems, which utilize a physical or knowledge-based electronic credential to authenticate the holder but fail to authenticate the actual user in addition to the token. Both commercial enterprises and the public sector have seen a shift in the requirement for stronger authentication, and the FBI, NIST and industry thought leaders such as SalesForce and Microsoft have encouraged entities to enhance their security posture by implementing stronger 2-factor authentication (2FA) or MFA. We believe the market for advanced user MFA, including fingerprint biometrics, extends to nearly every industry segment and the market opportunity for our products is massive, global and growing. \n Our Markets \n Historically, our largest market has been identity and access management for highly regulated industries like government and healthcare. However, we are witnessing a change in the landscape as organizations within all industries and of all sizes are embracing biometric technology and MFA as a security and workflow solution. Millions of users have been successfully using biometrics in phones from Apple and Samsung and they welcome the same user experience to access applications without passwords or tokens.\n \n \n \n Our acquisition of PistolStar added a large customer base in the state and local government and higher education (SLED) vertical. Colleges and universities throughout the United States use our PortalGuard MFA and SSO platform. As governments, colleges and universities continue to operate in remote environments, we have seen additional demand for our solutions.\n Table of Contents \n We believe there is potential for significant market growth in the following key areas:\n \n \n ●\n \n \n Enterprise MFA for access to computer networks, and applications.\n \n \n ●\n \n \n Large scale identification projects.\n \n \n ●\n \n \n Government funded initiatives, including the state board of elections.\n \n \n ●\n \n \n International law enforcement applications where we are viewed as a global leader in the biometric technology and serve customers such as the Israeli Defense Force and the Singapore Police departments.\n \n \n ●\n \n \n Consumer mobile credentialing, including mobile payments, credit and payment card programs, data and application access, and commercial loyalty programs. \n \n \n ●\n \n \n Demand for BIO-key hardware products from Windows Hello for Business users and Fortune 2000 companies.\n \n \n ●\n \n \n Government services and highly regulated industries including, Medicare, Medicaid, Social Security, drivers' licenses, campus and school ID, passports/visas.\n \n \n ●\n \n \n Remote authentication challenges, including those created by the remote work shift resulting from the pandemic.\n Business Model \n Our business model is focused on the following key areas:\n Market \n Drivers \n Enterprise needs are not being met by mainstream MFA's phone app or token approach. Supply chain breaches, ransomware attacks, and administrative access compromises highlight the shortcomings of mainstream MFA and security approaches, which leave far too much responsibility on end-users to comply with cyber-hygiene policies. BIO-key's biometric authentication process prevents human error and human nature from undermining secure authentication, while making the end user's access easier than ever. The current climate of broad enterprise adoption of MFA to replace passwords presents opportunities for us to leverage our unique differentiators and exploit the gaps in existing IAM technology approaches. One of those gaps is the challenge of authenticating users that \"rove\" among workstations. A second gap is preventing unauthorized account sharing and delegation.\n OEM \n Customers \n We continue to prioritize securing agreements with OEM customers. The history of success supporting NCR, Omnicell, and Idemia provides an established footprint that we intend to build upon. As OEM customers embed our solutions within their products, the customer benefits from the enhanced security and workflow, and frees them from investing in R&D to manage an IAM infrastructure of their own. OEM customers' ordering patterns are more predictable and OEM customers generally require lower service and support resourcing.\n Highly \n Regulated \n Industries \n Government ID projects and healthcare organizations, including hospitals, clinics, and small private practices present a strong opportunity for us. Additionally, the financial services industry, including banks and credit unions has grown substantially.\n Partner \n Model \n In 2025, we continued to grow our Channel Alliance Partner program focused on partnering with select value added resellers, integrators, and distributors. \n Microsoft \n Partnership \n We are a Microsoft Partner and our line of compact fingerprint scanners has been tested and qualified by Microsoft to support Windows Hello and Windows Hello for Business. \n Table of Contents \n Hardware \n Hardware products generated 22% and 9% of our revenue in 2025 and 2024, respectively. EcoID II® has emerged as one of our most popular scanner for enterprise deployments. For customers that require the highest level of security, PIV-Pro is a FIPS compliant fingerprint scanner, and our updated EcoID III® introduced in 2025 is PIV-071006 FAP-20 compliant, both suitable for highly regulated industries and organizations that want a best-in-class solution.\n \n \n \n We have grown our business through a combination of organic growth and the strategic acquisitions of PistolStar and Swivel Secure Europe. We expect to continue to pursue strategic acquisitions of select businesses and assets in the IAM space. In furtherance of this strategy, we are active in the industry and regularly evaluate businesses that we believe will either provide an entry into new market verticals or be synergistic with our existing operations and in either case, be accretive to earnings. We cannot provide any assurance as to whether we will be able to complete any acquisition and if completed, successfully integrate any business we acquire into our operations. Please see the section captioned \" RISK FACTORS \" for additional information regarding acquisition risks.\n Marketing and Distribution \n We sell our products directly through our field and inside sales teams, as well as indirectly through our network of channel partners. Through our Channel Alliance Program, we have partnered with more than 85 resellers, system integrators and other distribution partners. We are committed to continue to aggressively grow this program in 2025.\n \n \n \n We partner with leading application, managed service and infrastructure vendors, such as Intelisys, Insight, NGEN, Amazon Web Services, Pathify (formerly UCROO Campus), Software House International (SHI), Atlassian, and ProCirrus.\n \n \n \n We offer our software under a SaaS term license and generate annual recurring revenue (ARR) primarily by selling multi-year subscriptions to our software. We employ a customer success team, focused on customer satisfaction and early remediation. \n Intellectual Property Rights \n We develop and own significant intellectual property and believe that our intellectual property is fundamental to our biometric and IAM product operation: We own patented technologies and trade secrets developed or acquired by us.\n Table of Contents \n Patents \n On November 8, 2011, we were issued US Patent No. 8,055,027 for our \"Generation of Directional Information in the Context of Image Processing\" method for image enhancement and processing. With the payment of all maintenance fees, this patent will expire on October 10, 2027.\n \n \n \n On June 5, 2012, PistolStar was issued US Patent No. 8,196,193 for \"Method For Retrofitting Password Enabled Computer Software with a Redirectional User Authentication Method\", where a device, method, and system may be used to integrate and control authentication and passwords among various applications and platforms. With the payment of all maintenance fees, this patent will expire on November 1, 2030. \n \n \n \n On March 12, 2013, PistolStar was issued US Patent No. 8,397,077 for \"Client Side Authentication Redirection\", where user specific attributes may be accessed and used to produce a generated password, using an algorithm and the user attributes. With the payment of all maintenance fees, this patent will expire on August 7, 2030.\n \n \n \n On May 3, 2017, we were issued US Patent No. 9,646,146 for our \"Utilization of Biometric Data\", a method enables existing small area sensors to capture substantially more fingerprint surface area, leading to a higher degree of accuracy when performing a match. With the payment of all maintenance fees, this patent will expire on March 6, 2035. \n \n \n \n On June 19, 2018, we were issued U.S. Patent No. 10,002,244 for our \"Utilization of Biometric Data\" to allow continuous, passive user authentication on a mobile device. With the payment of all maintenance fees, this patent will expire on March 6, 2035.\n \n \n \n On July 27, 2018, we were issued U.S. Patent No. 10,025,831 for \"Adaptive Short Lists and Acceleration of Biometric Database Search\", a method to quickly and iteratively search a database of biometric data. With the payment of all maintenance fees, this patent will expire on August 10, 2036.\n \n \n \n On September 3, 2019, we were issued U.S. Patent No. 10,400,481 for \"Fingerprint Lock\", a lock design method of the shackle and spring integration to electronics. With the payment of all maintenance fees, this patent will expire on June 27, 2037.\n \n \n \n On September 10, 2019, we were issued U.S Patent No. 10,410,040 for \"Fingerprint Lock Control method and Fingerprint Lock System\", a lock design method of the control process of scanning, and server communications for user profile management. With the payment of all maintenance fees, this patent will expire on July 26, 2037.\n \n \n \n On April 20, 2021, we were issued U.S. Patent No. 10,984,085 for \"Biometric Recognition for Uncontrolled Acquisition Environments\", expected to be deployed in mobile devices, the patent provides a method of continuous capture of the users biometric data before the need of the authentication or enrollment, as well as during an active session with a user, to assure the user has not changed. With the payment of all maintenance fees, this patent will expire on March 13, 2039.\n \n \n \n We have also been granted parallel patents to the US Patent portfolio to certain of our patents in many foreign countries offering protection of our intellectual property rights around the world.\n Trademarks \n We have registered our trademarks \"BIO-key\", \"True User Identification\", \"Intelligent Image Indexing\", \"WEB-key\", \"SideSwipe\", \"SidePass\", \"EcoID\", \"PistolStar®\", \"PortalGuard\", \"MobileAuth\", \"PASSIVEKEY®\" and \"PISTOLSTAR®\" with the U.S. Patent & Trademark Office, as well as many foreign countries, protecting the names of our companies and our key technology offerings.\n Table of Contents \n We also own the following unregistered trademarks: \"PortalGuard Nebula™\", \"Password Power™\" and \"Scooch™\".\n Copyrights and trade secrets \n We take measures to ensure copyright and license protection for our software releases prior to distribution. When possible, the software is licensed in an attempt to ensure that only licensed and activated software functions to its full potential. We also take measures to protect the confidentiality of our trade secrets.\n Research and Development \n Our PortalGuard IAM product line is mature, with hundreds of active customers, and we are adding additional factors and capabilities to the product, as well as enhancing the self-management for the functionally equivalent PortalGuard IDaaS offering. A significant new authentication factor set will come via our MobileAuth application for users to experience multiple biometric secure authentication via their mobile phone devices. Our VST and WEB-key biometric platforms are mature, stable, and widely-deployed. We concentrate our research and development efforts on enhancing the functionality, reliability and integration of our current products as well as acquiring and developing new and innovative products and solutions for providing broader access to the BIO-key user experience. \n \n \n \n Although we believe that our identification technology is one of the most advanced and discriminating fingerprint technologies available today, the markets in which we compete are characterized by rapid technological change and evolving standards and use-cases. In order to maintain our position in the market, we will need to continue to upgrade and refine our existing technologies as new standards become relevant to our customers and markets.\n \n \n \n During the years ended December 31, 2025 and 2024, we incurred expenses of $2,609,893 and $2,511,080, respectively, for research and development.\n \n \n \n In future periods our R&D efforts will remain focused on updating and advancing our core software products including PortalGuard and PortalGuard IDaaS, MobileAuth, WEB-key and VST. These products are critical to support the anticipated growth in enterprise IAM.\n Competition \n The IAM, MFA and SSO market is characterized by multiple solution providers of solutions in either standalone or IAM suite delivery models. We believe that our unique differentiator in this market is the incorporation of an unparalleled server-secured biometric authentication capability among our seventeen authentication factors. There are numerous companies involved in the development, manufacturing and marketing of fingerprint biometrics products to commercial, government, law enforcement and prison markets. These companies include, but are not limited to, IDEMIA, Thales, NEC, Neurotechnology, and Innovatrics.\n \n \n \n The majority of sales for automated fingerprint identification products in the market to date have been deployed for government agencies, healthcare facilities, and law enforcement applications. The consumer and commercial markets represent areas of growth potential for biometrics, led by the use of mobile devices.\n \n \n \n The epidemic of security and data breaches reported over the past few years is one of the driving factors for identifying new methods of protecting valuable data. After attempting to create a more sophisticated password, or more efficient token or PIN, it has become apparent that each of these methods are easily compromised, and the downside risks are significant.\n \n \n \n We have also seen FIDO-compliant keys enter the market, led by Yubico's YubiKey, a hardware token device that acts as a credential for access. FIDO officially recommends enterprises purchase two or more keys for every user, to prevent lockout in the event of a lost or misplaced FIDO token. These hardware tokens alone do not meet the needs of large organizations for which key sharing and lost keys are concerns, establishing the opportunity for our Identity Bound Biometric differentiation. Where FIDO is needed, we offer a line of equivalent function and quality, but lower-cost FIDO 2.0 keys.\n \n \n \n With respect to competing biometrics technologies, each has its strengths and weaknesses and none has emerged as a market leader:\n \n \n ●\n Fingerprint identification is generally viewed as very accurate, inexpensive and non-intrusive and is the dominant biometric in use today and will be for the foreseeable future;\n \n \n ●\n Palm Vein scanning is expensive, technique-sensitive, and offers mobility challenges;\n Table of Contents \n ●\n Iris scanning is viewed as accurate, but the hardware is significantly more expensive; and\n \n \n ●\n Facial recognition can have privacy concerns with work-from-home use, and is typically highly dependent on ambient lighting conditions, angle of view, and other factors.\n Government Regulations \n Various state, federal and EU privacy laws govern the collection, storage, use and any sale of biometric-related data. To the extent that our IDaaS offerings include the collection and storage of customer users' personal or biometric data, we operate as a processor of such data. Our WEB-key platform includes compliance features to ensure automated compliance with these laws including collection of informed written consent during enrollment workflows and robust auditing to control and report on the retention of biometric data and removal requests. Additionally, our customers have access to these tools to maintain their own compliance, including deletion of user data when business relationships terminate.\n \n \n \n We believe in biometric privacy rights, and that both users and their organizations benefit from a responsibly operated biometric identity infrastructure. We actively participate in industry privacy workgroups as recognized biometric subject matter experts in order to influence and keep abreast of any proposed changes to these regulations. Beyond these regulations, we are not currently subject to direct regulation by any government agency, other than regulations generally applicable to businesses or related to specific project requirements. In the event of any international sales, we would be subject to various domestic and foreign laws regulating such exports and export activities.\n Environmental Regulations \n As of the date of this report, we have not incurred any material expenses relating to our compliance with federal, state, or local environmental laws and do not expect to incur any material expenses in the foreseeable future.\n Seasonality \n Generally, our revenues do not exhibit a seasonal pattern, however, revenue is affected by customer budgeting, government fiscal year planning, and capital budgets.\n Human Capital Resources \n As of the date of this report, we have forty-two employees consisting of forty-one individuals on a full-time basis and one part-time employee as follows: (i) nineteen in engineering, customer support, and research and development; (ii) nine in finance and administration; and (iii) fourteen in sales and marketing. We also have two factory contractors in China. None of our employees are represented by a labor union and we believe that our relationship with our employees is good.\n Table of Contents \n ITEM 1A. RISK FACTORS \n Set forth below are the risks that we believe are material to our investors. This section contains forward-looking statements. You should refer to the explanation of the qualifications and limitations on forward-looking statements appearing just before the section captioned \" BUSINESS \" in Item 1 above.\n BUSINESS AND FINANCIAL RISKS \n Material weaknesses could materially and adversely affect our operations, financial condition, reputation and stock price. \n It is possible that we may discover significant deficiencies or material weaknesses in our internal control over financial reporting in the future. For example, internal control over financial reporting may not achieve their intended objectives. Control processes that involve human diligence and compliance, such as our disclosure controls and procedures and internal control over financial reporting, are subject to lapses in judgment and breakdowns resulting from human failures. Controls can also be circumvented by collusion or improper management-override of such controls. Because of such limitations, there are risks that material misstatements due to error or fraud may not be prevented or detected, and that information may not be reported on a timely basis.\n Based on our limited cash resources, history of losses, negative cash flow from operations, and dependence on debt and equity financing to fund operations, our independent registered public accounting firm has included an explanatory paragraph in their opinion as to the substantial doubt about our ability to continue as a going concern. \n Due to, among other factors, our history of losses, limited cash resources, negative cash flow from operations, and dependence on debt and equity financing to fund operations, our independent registered public accounting firm has included an explanatory paragraph in their opinion for the year ended December 31, 2025 as to the substantial doubt about our ability to continue as a going concern within one year after issuance. Our financial statements have been prepared in accordance with accounting principles generally accepted in the United States, which contemplate that we will continue to operate as a going concern. Our financial statements do not contain any adjustments that might result if we are unable to continue as a going concern.\n Historically, we have not generated significant revenue and have sustained substantial operating losses. \n In order to increase revenue, we have developed a direct sales force and anticipate the need to retain additional sales, marketing and technical support personnel and may need to incur substantial expenses. We cannot assure you that we will be able to secure these necessary resources, that a significant market for our technologies will develop, or that we will be able to achieve our targeted revenue. If we are unable to achieve revenue or raise capital sufficient to cover our ongoing operating expenses, we will be required to scale back operations, including marketing and research initiatives, or in the extreme case, discontinue operations.\n Table of Contents \n We may need to obtain additional financing to execute our business plan, which may not be available. If we are unable to raise additional capital or generate significant revenue, we may not be able to continue operations. \n We have historically financed our operations through access to the capital markets by issuing secured and convertible debt securities, convertible preferred stock, common stock, and through factoring receivables. We currently require approximately $750,000 per month to conduct our operations, a monthly amount that we have been unable to consistently achieve through revenue generation. During 2025, we generated approximately $6.1 million of revenue, which is below our average monthly requirements. If we are unable to generate sufficient revenue to cover operating expenses and fund our business plan, we will need to obtain additional third-party financing. We may, therefore, need to obtain additional financing through the issuance of debt or equity securities. We cannot assure you that we will be able to secure any such additional financing on terms acceptable to us or at all. If we cannot obtain such financing, we will not be able to execute our business plan, will be required to reduce operating expenses, and in the extreme case, discontinue operations. \n Our failure to timely file our annual report on Form 10-K for the year ended December 31, 2025 has made us ineligible to use a Form S-3 to register the offer and sale of securities, which could adversely affect our ability to raise future capital. \n As a result of our failure to timely file our annual report on Form 10-K for the year ended December 31, 2025 we are not eligible to register the offer and sale of our securities using a registration statement on Form S-3 until one year from the date we regain and maintain status as a current filer, assuming that we remain listed on the Nasdaq Capital Market. Should we wish to register the offer and sale of our securities to the public prior to the time we are eligible to use Form S-3, both our transaction costs and the amount of time required to complete the transaction could increase, making it more difficult to execute any such transaction successfully and potentially harming our financial condition.\n Our biometric technology has yet to gain widespread market acceptance and we do not know how large of a market will develop for our technology. \n Biometric technology has received only limited market acceptance, particularly in the private sector. Our technology represents a novel security solution and we have not yet generated significant sales. Although recent security concerns relating to identification of individuals and appearance of biometric readers on popular consumer products, including the Apple iPhone, have increased interest in biometrics generally, it remains an evolving market. Biometric based solutions compete with more traditional security methods including keys, cards, personal identification numbers and security personnel. Acceptance of biometrics as an alternative to such traditional methods depends upon a number of factors including:\n \n \n ●\n \n \n national or international events which may affect the need for or interest in biometric solutions;\n \n \n ●\n \n \n the performance and reliability of biometric solutions;\n \n \n ●\n \n \n marketing efforts and publicity regarding these solutions;\n \n \n ●\n \n \n public perception regarding privacy concerns;\n \n \n ●\n \n \n costs involved in adopting and integrating biometric solutions;\n \n \n ●\n \n \n proposed or enacted legislation related to privacy of information; and\n \n \n ●\n \n \n competition from non-biometric technologies that provide more affordable, but less robust, authentication (such as tokens and smart cards).\n \n \n \n For these reasons, we are uncertain whether our biometric technology will gain widespread acceptance in any commercial markets or that demand will be sufficient to create a market large enough to produce significant revenue or earnings. Our future success depends, in part, upon business customers adopting biometrics generally, and our solution specifically.\n Biometric technology is a relatively new approach to Internet security, which must be accepted in order for our WEB-key solution to generate significant revenue. \n Our WEB-key authentication initiative represents a relatively new approach to Internet security, which has been adopted on a limited basis by companies that distribute goods, content or software applications over the Internet. The implementation of our WEB-key solution requires the distribution and use of a finger scanning device and integration of database and server side software. Although we believe our solutions provide a higher level of security for information transmitted over the Internet than existing traditional methods, unless business and consumer markets embrace the use of a scanning device and believe the benefits of increased accuracy outweigh implementation costs, our solution will not gain market acceptance.\n Table of Contents \n The market for our solutions is still developing and if the biometrics industry adopts standards or a platform different from our standards or platform, our competitive position would be negatively affected. \n The market for identity solutions is still developing. The evolution of this market may result in the development of different technologies and industry standards that are not compatible with our current solutions, products or technologies. Several organizations set standards for biometrics to be used in identification and documentation. Although we believe that our biometric technologies comply with existing standards, these standards may change and any standards adopted could prove disadvantageous to or incompatible with our business model and current or future solutions, products and services.\n Our software products may contain defects which will make it more difficult for us to establish and maintain customers. \n Although we have completed the development of our core biometric technology, it has only been used by a limited number of business customers. Despite extensive testing during development, our software may contain undetected design faults and software errors, or \"bugs\" that are discovered only after it has been installed and used by a greater number of customers. Any such defect or error in new or existing software or applications could cause delays in delivering our technology or require design modifications. These could adversely affect our competitive position and cause us to lose potential customers or opportunities. Since our technologies are intended to be utilized to secure physical and electronic access, the effect of any such bugs or delays will likely have a detrimental impact on us. In addition, given that biometric technology generally, and our biometric technology specifically, has yet to gain widespread acceptance in the market, any delays would likely have a more detrimental impact on our business than if we were a more established company. \n In order to generate revenue from our biometric products, we are dependent upon independent original equipment manufacturers, system integrators and application developers, which we do not control. As a result, it may be more difficult to generate sales. \n We market our technology through licensing arrangements with:\n \n \n ●\n \n \n original equipment manufacturers (OEMs), system integrators and application developers which develop and market products and applications which can then be sold to end users; and\n \n \n ●\n \n \n companies which distribute goods, services or software applications over the Internet.\n \n \n \n As a technology licensing company, our success will depend upon the ability of these manufacturers and developers to effectively integrate our technology into products and services which they market and sell. We have no control over these licensees and cannot assure you that they have the financial, marketing or technical resources to successfully develop and distribute products or applications acceptable to end users or generate any meaningful revenue for us. These third parties may also offer the products of our competitors to end users. While we have commenced a significant sales and marketing effort, we have only begun to develop a significant distribution channel and may not have the resources or ability to sustain these efforts or generate any meaningful sales.\n We face intense competition and may not have the financial and human resources necessary to keep up with rapid technological changes, which may result in our technology becoming obsolete. \n The Internet, facility access control, and information security markets are subject to rapid technological change and intense competition. We compete with both established biometric companies and a significant number of startup enterprises as well as providers of more traditional methods of access control. Most of our competitors have substantially greater financial and marketing resources than we do and may independently develop superior technologies, which may result in our technology becoming less competitive or obsolete. We may not be able to keep pace with this change. If we are unable to develop new applications or enhance our existing technology in a timely manner in response to technological changes, we will be unable to compete in our chosen markets. In addition, if one or more other biometric technologies such as voice, face, iris, hand geometry or blood vessel recognition are widely adopted, it would significantly reduce the potential market for our fingerprint identification technology. \n We recognized revenues from Africa and the European Union in 2025 and 2024 and expect continued revenues from these regions in future periods. Our financial performance will be subject to risks associated with changes in the value of the U.S. dollar versus local currencies. \n Owing to the international scope of our operations, including our recent acquisition of Swivel Secure Europe, SA, we are exposed to foreign exchange risk. Our primary exposure to movements in foreign currency exchange rates relates to non-U.S. dollar-denominated sales and operating expenses worldwide. Weakening of foreign currencies relative to the U.S. dollar will adversely affect the U.S. dollar value of our foreign currency-denominated sales and earnings, if any, and could lead to us raising international pricing, potentially reducing the demand for our products. In addition, margins on sales of our products in foreign countries and on sales of products that include components obtained from foreign suppliers could be materially adversely affected by foreign currency exchange rate fluctuations. As a result, our business and the price of our common stock may be affected by fluctuations in foreign exchange rates, which may have a significant impact on our results of operations and cash flows from period to period. Currently, we do not have any exchange rate hedging arrangements in place.\n Table of Contents \n Although we have made significant sales of our products throughout Asia and Africa in prior years, we have not been able to consistently enforce our contract rights and collect all receivables which has resulted in material write-offs. \n Our ability to enforce our international contracts is contingent on our relationships with foreign resellers, and their financial viability. Although we are making efforts to better enforce our contract rights, there can be no assurance that we will be able to fully collect all receivables originating in Asia and Africa or that will not have to write-off future receivables which may be material in amount. Any such write-offs have negatively impacted our financial position and results of operation.\n We depend on key employees and members of our management team, including our Chairman of the Board and Chief Executive Officer, Chief Financial Officer, and our Chief Legal Officer, in order to achieve our goals. We cannot assure you that we will be able to retain or attract such persons. \n Our employment contracts with Michael W. DePasquale, our Chairman of the Board and Chief Executive Officer, Cecilia C. Welch, our Chief Financial Officer, and James D. Sullivan, our Chief Legal Officer, each have one-year terms and renew automatically for successive one-year periods unless notice of non-renewal is provided by the Company. Although the contracts do not prevent them from resigning, they do contain confidentiality and non-compete clauses, which are intended to prevent them from working for a competitor within one year after leaving our Company. Our success depends on our ability to attract, train and retain employees with expertise in developing, marketing and selling software solutions. In order to successfully market our technology, we will need to retain additional engineering, technical support and marketing personnel. The market for such persons remains highly competitive and our limited financial resources will make it more difficult for us to recruit and retain qualified persons.\n We cannot assure you that the intellectual property protection for our core technology provides a sustainable competitive advantage or barrier to entry against our competitors. \n Our success and ability to compete is dependent in part upon proprietary rights to our technology. We rely primarily on a combination of patent, copyright and trademark laws, trade secrets and technical measures to protect our propriety rights. We have filed a patent application relating to both the optic technology and biometrics solution components of our technology wherein several claims have been allowed. The U.S. Patent and Trademark Office has issued us a series of patents for our Vector Segment fingerprint technology (VST), and our other core biometric analysis and identification technologies. However, we cannot assure you that we will be able to adequately protect our technology or other intellectual property from misappropriation in the U.S. and abroad. Any patent issued to us could be challenged, invalidated or circumvented or rights granted thereunder may not provide a competitive advantage to us. Furthermore, patent applications that we file may not result in issuance of a patent or, if a patent is issued, the patent may not be issued in a form that is advantageous to us. Despite our efforts to protect our intellectual property rights, others may independently develop similar products, duplicate our products or design around our patents and other rights. In addition, it is difficult to monitor compliance with, and enforce, our intellectual property rights on a worldwide basis in a cost-effective manner. In jurisdictions where foreign laws provide less intellectual property protection than afforded in the U.S. and abroad, our technology or other intellectual property may be compromised, and our business would be materially adversely affected.\n \n \n \n If any of our proprietary rights are misappropriated or we are forced to defend our intellectual property rights, we will have to incur substantial costs. Such litigation could result in substantial costs and diversion of our resources, including diverting the time and effort of our senior management, and could disrupt our business, as well as have a material adverse effect on our business, prospects, financial condition and results of operations. We can provide no assurance that we will have the financial resources to oppose any actual or threatened infringement by any third party. Furthermore, any patent or copyrights that we may be granted may be held by a court to infringe on the intellectual property rights of others and subject us to the payment of damage awards. \n We may be subject to claims with respect to the infringement of intellectual property rights of others, which could result in substantial costs and diversion of our financial and management resources. \n Third parties may claim that we are infringing on their intellectual property rights. We may violate the rights of others without our knowledge. We may expose ourselves to additional liability if we agree to indemnify our customers against third party infringement claims. While we know of no basis for any claims of this type, the existence of and ownership of intellectual property can be difficult to verify, and we have not made an exhaustive search of all patent filings. Additionally, most patent applications are kept confidential for twelve to eighteen months, or longer, and we would not be aware of potentially conflicting claims that they make. We may become subject to legal proceedings and claims from time to time relating to the intellectual property of others in the ordinary course of our business. If we are found to have violated the intellectual property rights of others, we may be enjoined from using such intellectual property, and we may incur licensing fees or be forced to develop alternative technology or obtain other licenses. In addition, we may incur substantial expenses in defending against these third-party infringement claims and be diverted from devoting time to our business and operational issues, regardless of the merits of any such claim.\n Table of Contents \n In addition, in the event that we recruit employees from other technology companies, including certain potential competitors, and these employees are engaged in the development of portions of products which are similar to the development in which they were involved at their former employers, we may become subject to claims that such employees have improperly used or disclosed trade secrets or other proprietary information. If any such claims were to arise in the future, litigation or other dispute resolution procedures might be necessary to retain our ability to offer our current and future services, which could result in substantial costs and diversion of our financial and management resources. Successful infringement or licensing claims against us may result in substantial monetary damages, which may materially disrupt the conduct of our business and have a material adverse effect on our reputation, business, financial condition and results of operations. Even if intellectual property claims brought against us are without merit, they could result in costly and time consuming litigation and may divert our management and key personnel from operating our business.\n If we are unable to effectively protect our intellectual property rights on a worldwide basis, we may not be successful in the international expansion of our business. \n Access to worldwide markets depends in part on the strength of our intellectual property portfolio. There can be no assurance that, as our business expands into new areas, we will be able to independently develop the technology, software or know-how necessary to conduct our business or that we can do so without infringing the intellectual property rights of others. To the extent that we have to rely on licensed technology from others, there can be no assurance that we will be able to obtain licenses at all or on terms we consider reasonable. The lack of a necessary license could expose us to claims for damages and/or injunction from third parties, as well as claims for indemnification by our customers in instances where we have a contractual or other legal obligation to indemnify them against damages resulting from infringement claims. With regard to our own intellectual property, we actively enforce and protect our rights. However, there can be no assurance that our efforts will be adequate to prevent the misappropriation or improper use of our protected technology in international markets.\n We may not achieve profitability if we are unable to maintain, improve our offerings. \n We believe that our future business prospects depend in part on our ability to maintain and improve our current services and to develop new ones on a timely basis. Our services will have to achieve market acceptance, maintain technological competitiveness, and meet an expanding range of customer requirements. We may experience difficulties that could delay or prevent the successful development, introduction or marketing of new services and service enhancements. Additionally, our new services and service enhancements may not achieve market acceptance. If we cannot effectively develop and improve services, we may not be able to recover our fixed costs or otherwise become profitable.\n We are subject to risks and uncertainties associated with the continued growth of our international operations, which may harm our business. \n We have international operations and continue to expand our international operations when we acquired Swivel Secure Europe SA. Accordingly, our business is subject to risks and uncertainties associated with doing business outside of the United States and could be adversely affected by a variety of factors, including:\n \n \n ●\n \n \n multiple, conflicting and changing laws and regulations such as privacy, security, and data use regulations, tax laws, export and import restrictions, economic and trade sanctions and embargoes, employment laws, anticorruption laws, regulatory requirements, reimbursement or payer regimes and other governmental approvals, permits and licenses;\n \n \n ●\n \n \n failure by us, our collaborators or our distributors to obtain regulatory clearance, authorization or approval for the use of our product candidates in various countries;\n \n \n ●\n \n \n additional potentially relevant third-party patent rights;\n \n \n ●\n \n \n complexities and difficulties in obtaining intellectual property protection and enforcing our intellectual property;\n \n \n ●\n \n \n difficulties in staffing and managing foreign operations;\n \n \n ●\n \n \n financial risks, such as longer payment cycles, difficulty collecting accounts receivable, the impact of local and regional financial crises on demand and payment for our product candidates and exposure to foreign currency exchange rate fluctuations;\n \n \n ●\n \n \n natural disasters, political and economic instability, including wars, terrorism and political unrest, outbreak of disease, boycotts, curtailment of trade and other business restrictions;\n \n \n ●\n \n \n regulatory and compliance risks that relate to maintaining accurate information and control over sales and distributors' activities that may fall within the purview of the U.S. Foreign Corrupt Practices Act (FCPA), its books and records provisions, or its anti-bribery provisions, or laws similar to the FCPA in other jurisdictions in which we may now or in the future operate; and\n \n \n ●\n \n \n anti-bribery requirements of several Member States in the European Union and other countries that may change and require disclosure of information to which U.S. legal privilege may not extend.\n \n \n \n Any of these factors could significantly harm our business, operating results, financial condition or prospects.\n Table of Contents \n Our business could be negatively impacted by security threats, including cybersecurity threats, ransomware, and other disruptions. \n Our customers use our solutions to access their business systems and store data related to their employees, contractors, partners and customers. Our systems' integrity is essential to their use of our platform, which stores, transmits and processes customers' proprietary information and users' personal data. If the confidentiality, integrity or availability of our customers' data or systems is disrupted, we could incur significant liability to our customers and to individuals or businesses whose information was being stored by our customers, and our platform may be perceived as less desirable, which could negatively affect our business and damage our reputation. We, our third-party service providers, and our customers may be unable to anticipate these techniques or to implement adequate preventive measures. Further, because we do not control our third-party service providers, or the processing of data by our third-party service providers, we cannot ensure the integrity or security of measures they take to protect customer information and prevent data loss beyond evaluating and relying on their representations as to their security methods and posture. Although we utilize various procedures and controls to monitor these threats and mitigate our exposure to such threats, there can be no assurance that these procedures and controls will be sufficient in preventing security threats from materializing. If any of these events were to materialize, they could lead to losses of sensitive information, critical infrastructure, personnel or capabilities, essential to our operations and could have a material adverse effect on our reputation, financial position, results of operations, or cash flows. As a technology company, we face various security threats, including cybersecurity threats to gain unauthorized access to sensitive information. on an ongoing basis.\n \n \n \n In addition to threats from traditional computer \"hackers,\" malicious code (such as malware, viruses, worms and ransomware), employee or contractor theft or misuse, password spraying, phishing and denial-of-service attacks, we and our third-party service providers now also face threats from sophisticated nation-state and nation-state-supported actors who engage in attacks (including advanced persistent threat intrusions) that add to the risks to our systems (including those hosted on AWS' systems), internal networks, our customers' systems and the information that they store and process. Cybersecurity attacks in particular are evolving, we expect that they will continue, and we expect the scope and sophistication of these efforts may increase in future periods. As a result, we and our third-party service providers may be unable to anticipate these techniques or implement adequate preventative measures quickly enough to prevent either an electronic intrusion into our systems or services or a compromise of customer data, employee data or other protected information. \n \n \n \n Although we have implemented systems and procedures that are designed to protect customer, employee, vendor and Company information, prevent data loss and other security breaches, and otherwise identify, assess, and analyze cybersecurity risks, these measures may not function as expected or may not be sufficient to protect our internal networks and platform against certain attacks. Development and maintenance of these systems is costly and requires ongoing monitoring and updating as technologies change and efforts to overcome security measures increase and become more sophisticated. We face an evolving threat landscape in which cybercriminals, among others, employ a complex array of techniques designed to access personal data and other information, including, for example, the use of fraudulent or stolen access credentials, malware, ransomware, phishing, denial of service and other types of attacks. While, to the best of our knowledge, we have not experienced any material misappropriation, loss or other unauthorized disclosure of confidential or personally identifiable information as a result of a security breach or cyberattack that could materially increase financial risk to the Company or our customers, such a security breach or cyberattack could adversely affect our business and operations, including by damaging our reputation and our relationships with our customers, employees and investors, exposing us to litigation, fines, penalties or remediation costs.\n \n \n \n We maintain cybersecurity insurance, but our insurance may be insufficient to cover all liabilities incurred in any such incident, and any incident may result in loss of, or increased costs of, that cybersecurity insurance. Any breach, or any perceived breach, of our systems, our customers' systems, or other systems or networks secured by our products, without regard to whether any breach is due to a vulnerability in our platform, may also undermine confidence in our platform or the identity as a service industry and could result in damage to our reputation and brand, negative publicity, loss of partners, customers and sales, increased costs to correct any problem, costly litigation and other liabilities. In addition, a breach of the security measures of one of our partners could result in the disclosure of confidential information or other data that may provide additional avenues of attack, and if a high profile security breach occurs with respect to a comparable cloud technology provider, our customers and potential customers may lose trust in the security of the cloud business model generally, which could adversely impact our ability to retain existing customers or attract new ones. Any of these negative outcomes could adversely impact market acceptance of our products and could harm our business, results of operations, and financial condition.\n Our failure to comply with applicable privacy, data protection and information security laws or related contractual obligations could subject us to significant liability and negatively impact our financial position and results of operation. \n There are numerous laws and regulations in various jurisdictions regarding privacy, data protection, information security, and the storing, sharing, use, processing, transfer, disclosure and protection of personal data. In light of the increasing pace of new technology development, including with respect to biometric data, the scope of these data protection and privacy-related laws and regulations are expanding, subject to differing interpretations, and may be inconsistent among jurisdictions, or conflict with other rules that we are subject to. These evolving laws and regulations may result in increasing regulatory and public scrutiny and escalating levels of enforcement and sanctions. We are also subject to the terms of our privacy policies and contractual obligations to third parties related to privacy, data protection and information security.\n \n \n \n Any failure or perceived failure by us to comply with our privacy policies, our privacy-related obligations to customers or other third parties, or applicable laws or regulations relating to privacy, data protection, or information security may result in governmental investigations or enforcement actions, litigation, claims or public statements against us by consumer advocacy groups or others, and could result in significant liability or cause our customers to lose trust in us, which could cause them to cease or reduce use of our products and services and otherwise have an adverse effect on our reputation and business. Any similar failure or perceived failure by users of our products or services may also have an adverse effect on our reputation and business. In addition, legal, regulatory, contractual and other obligations as well as public concerns relating to privacy, data protection or information security could restrict our ability to store and process data as part of our solutions or otherwise impact our ability to provide our solutions in certain jurisdictions and may result in the loss of business opportunities from customers operating in, or seeking to expand into, those jurisdictions. Additionally, we are subject to SEC rules related to cybersecurity risk management, which may further increase our regulatory burden and the cost of compliance in such events.\n Table of Contents \n Our business could be adversely affected by trade tariffs or other trade barriers. \n Our business is subject to the imposition of tariffs and other trade barriers, which may make it more costly for us to import inventory from China and Hong Kong and certain product components from South Korea. The current presidential administration has imposed new tariffs on imports to the United States and may impose additional tariffs in the future. Other countries have, and in the future may, impose retaliatory tariffs. The resulting environment of retaliatory trade or other practices or additional trade restrictions or barriers could harm our ability to obtain inventory and product components or sell our products and services at prices customers are willing to pay, which could have a material adverse effect on our business, prospects, results of operations, and cash flows. Relatedly, trade policies could lead to an increasing number of competitors entering the United States, thereby creating more competition. If we experience cost increases as a result of existing or future tariffs and are unable to pass on such additional costs to our customers, or otherwise mitigate the costs, our business, prospects, financial condition, results of operations, and cash flows could be materially and adversely affected.\n Scrutiny and evolving expectations from customers, regulators, investors, and other stakeholders with respect to our environmental, social and governance practices may impose additional costs on us or expose us to new or additional risks. \n Public companies are facing scrutiny from customers, regulators, investors, and other stakeholders related to their environmental, social and governance (\"ESG\") practices and disclosure. Investor advocacy groups, investment funds and influential investors are also focused on these practices, especially as they relate to the environment, climate change, health and safety, supply chain management, diversity, labor conditions and human rights, both in our own operations and in our supply chain. Increased ESG-related compliance costs could result in material increases to our overall operational costs. Our ESG practices may not meet the standards of all of our stakeholders and advocacy groups may campaign for further changes. Additionally, different stakeholder groups have divergent views on ESG matters, which increases the risk that any action or lack thereof with respect to ESG matters may be perceived negatively by at least some stakeholders and adversely impact our reputation and business. Anti-ESG sentiment has gained some momentum across the United States, with several states having enacted or proposed \"anti-ESG\" policies or legislation or issued related legal opinions. The federal government has similarly taken action to curtail ESG initiatives. A failure, or perceived failure, to adapt to or comply with regulatory requirements or to respond to investor or stakeholder expectations and standards could negatively impact our business and reputation and have a negative impact on the trading price of our common stock.\n The impact of the Russian invasion of Ukraine, and the US-Iran war, and the international community ' s response have created substantial political and economic disruption, uncertainty, and risk. \n The short and long-term implications of Russia's invasion of Ukraine, and the war between the US and Iran are difficult to predict at this time. We continue to monitor any adverse impact that the outbreak of war in Ukraine and the subsequent institution of sanctions against Russia by the U.S. and several European and Asian countries, which has not caused any material harm to the Company to date; along with the war in Iran, may have on the global economy in general, on our business and operations and on the businesses and operations of our suppliers and customers. Such risks include, but are not limited to, adverse effects on macro-economic conditions, including inflation; disruptions to our global technology infrastructure, including through cyberattack, ransom attack, or cyber-intrusion; adverse changes in international trade policies and relations; our ability to maintain or increase our product prices; disruptions in global supply chains; our exposure to foreign currency fluctuations; and constraints, volatility, or disruption in the capital markets, any of which could negatively affect our business and financial condition. These and related actions, responses, and consequences that cannot now be predicted or controlled may contribute to world-wide economic reversals.\n There is a scarcity of and competition for acquisition opportunities. \n A component of our business plan is to acquire businesses and assets in the biometric and identity access management industry and other industries which we believe would complement our current offerings. There are a limited number of operating companies available for acquisition that we deem to be desirable targets. In addition, there is a very high level of competition among companies seeking to acquire these operating companies. Many established and well-financed entities are active in acquiring interests in companies that we may find to be desirable acquisition candidates. Many of these entities have significantly greater financial resources, technical expertise and managerial capabilities than us. Consequently, we will be at a competitive disadvantage in negotiating and executing possible acquisitions of these businesses. Even if we are able to successfully compete with these entities, this competition may affect the terms of completed transactions and, as a result, we may pay more or receive less favorable terms than we expected for potential acquisitions. We may not be able to identify operating companies that complement our strategy, and even if we identify a company that complements our strategy, we may be unable to complete an acquisition of such a company for many reasons, including:\n \n \n ●\n \n \n failure to agree on the terms necessary for a transaction, such as the purchase price;\n \n \n ●\n \n \n incompatibility between our operational strategies or management philosophies with those of the potential acquiree;\n \n \n ●\n \n \n competition from other acquirers of operating companies;\n \n \n ●\n \n \n lack of sufficient capital to acquire a profitable company; and\n \n \n ●\n \n \n unwillingness of a potential acquiree to work with our management.\n Table of Contents \n Risks related to acquisition financing. \n We have limited financial resources and our ability to make additional acquisitions without securing additional financing from outside sources is also limited. In order to continue to pursue our acquisition strategy, we may be required to obtain additional financing. We may obtain such financing through a combination of debt financing or the placement of debt and equity securities. We may finance some portion of our future acquisitions by either issuing equity or by using shares of our common stock for all or a portion of the purchase price for such businesses. In the event that our common stock does not attain or maintain a sufficient market value, or potential acquisition candidates are otherwise unwilling to accept our common stock as part of the purchase price for the sale of their businesses, we may be required to use more of our cash resources, if available, in order to maintain our acquisition program. If we do not have sufficient cash resources, we will not be able to complete acquisitions and our growth could be limited unless we are able to obtain additional capital through debt or equity financings.\n We may experience difficulties in integrating the operations, personnel and assets of any business we acquire which may disrupt our business, dilute stockholder value, and adversely affect our operating results . \n There can be no assurance that we will be able to identify, acquire or profitably manage any businesses or successfully integrate acquired businesses into the Company without substantial costs, delays or other operational or financial problems. Such acquisitions also involve numerous operational risks, including:\n \n \n ●\n \n \n difficulties in integrating operations, technologies, services and personnel;\n \n \n ●\n \n \n the diversion of financial and management resources from existing operations;\n \n \n ●\n \n \n the risk of entering new markets;\n \n \n ●\n \n \n difficulties in retaining the existing customers;\n \n \n ●\n \n \n the potential loss of existing or acquired strategic operating partners following an acquisition;\n \n \n ●\n \n \n the potential loss of key employees following an acquisition and the associated risk of competitive efforts from departures;\n \n \n ●\n \n \n assumed or unforeseen liabilities that arise in connection with the acquired business;\n \n \n ●\n \n \n possible legal disputes with the acquired company following an acquisition; and\n \n \n ●\n \n \n the inability to generate sufficient revenue to offset acquisition or investment costs.\n \n \n \n As a result, if we fail to properly evaluate and execute any acquisitions or investments, our business and prospects may be seriously harmed.\n To the extent we make any material acquisitions, our earnings may be adversely affected by non-cash charges relating to the amortization of intangible assets. \n Under applicable accounting standards, purchasers are required to allocate the total consideration paid in a business combination to the identified acquired assets and liabilities based on their fair values at the time of acquisition. The excess of the consideration paid to acquire a business over the fair value of the identifiable tangible assets acquired must be allocated among identifiable intangible assets including goodwill. The amount allocated to goodwill is not subject to amortization. However, it is tested at least annually for impairment. The amount allocated to identifiable intangible assets, such as customer relationships and the like, is amortized over the life of these intangible assets. We expect that this will subject us to periodic charges against our earnings to the extent of the amortization incurred for that period. Because our business strategy focuses, in part, on growth through acquisitions, our future earnings may be subject to greater non-cash amortization charges than a company whose earnings are derived solely from organic growth. As a result, we may experience an increase in non-cash charges related to the amortization of intangible assets acquired in our acquisitions. Our financial statements will show that our intangible assets are diminishing in value, even if the acquired businesses are increasing (or not diminishing) in value.\n RISKS RELATED TO OUR COMMON STOCK \n We have issued a substantial number of warrants exercisable into shares of our common stock which could result in substantial dilution to the ownership interests of our existing stockholders. \n As of the date of this report, approximately 794,073 shares of our common stock (as adjusted to reflect our 1-for-10 reverse stock split, which was effective April 30, 2026) were reserved for issuance upon exercise or conversion of outstanding stock options and warrants. The exercise or conversion of these securities will result in a significant increase in the number of outstanding shares and substantially dilute the ownership interests of our existing stockholders. \n Table of Contents \n An active trading market for our common stock may not be sustained. \n On May 13, 2026 trading of our common stock on the Nasdaq Capital Market was suspended which could adversely impact the trading and liquidity of our common stock. Our common stock currently trades on OTC Markets and an active trading market for our shares may not be developed on OTC Markets and if developed, sustained. If an active market for our common stock is not developed or sustained, it may be difficult for you to sell your shares without depressing the market price for the shares or sell your shares at all. Any inactive trading market for our common stock may also impair our ability to raise capital to continue to fund our operations by selling shares and may impair our ability to acquire other companies or technologies by using our shares as consideration. \n Trading of our common stock on the Nasdaq Capital Market was suspended on May 13, 2026. If we are not successful in our appeal of Nasdaq ' s decision and are unable to regain compliance with the continued listing requirements of The Nasdaq Stock Market, our Common Stock will be delisted and the price of our Common Stock and our ability to access the capital markets could be negatively impacted. \n On May 13, 2026 trading of our common stock on Nasdaq was suspended due to our failure to regain compliance with the minimum bid requirement and to timely file our periodic reports with the SEC. Our common stock currently trades on OTC Markets under the symbol \"BKYI\". On April 30, 2026, we effected a one-for-ten reverse stock split which restored our share price to a level in excess of Nasdaq's $1 minimum closing bid price requirement. Due to the timing of the reverse split, we were unable to maintain this share price level for 10 consecutive trading days prior to May 6, 2026 which resulted in our shares being suspended from trading on Nasdaq. The suspension and potential delisting of our common stock from Nasdaq could materially reduce the liquidity of our common stock and result in a corresponding material reduction in the price of our common stock as shares traded on the OTC Markets generally have substantially less liquidity and it can be more difficult for stockholders and broker/dealers to purchase and sell our shares in an orderly manner or at all. As a result, the trading price of our common stock may change quickly, and brokers may not be able to execute trades as quickly as they previously could when our common stock was listed on a national exchange.. Delisting could also harm our ability to raise capital through alternative financing sources on terms acceptable to us, or at all, and may result in the potential loss of confidence by investors, employees and fewer business development opportunities. .\n \n \n \n We have appealed Nasdaq's decision to suspend trading in our common stock and are currently working to regain compliance with all continued listing standards of the Nasdaq Capital Market. A hearing to consider our appeal is currently scheduled for June 16, 2026. There can be no assurance that our appeal will be successful or that our shares will not be delisted. \n We may need to raise additional funds in the future through issuances of securities and such additional funding may be dilutive to stockholders or impose operational restrictions. \n We may need to raise additional capital in the future to help fund our operations through sales of shares of our common stock or securities convertible into shares of our common stock, as well as issuances of debt. Such additional financing may be dilutive to our stockholders, and debt financing, if available, and may involve restrictive covenants which may limit our operating flexibility. If additional capital is raised through the issuance of shares of our common stock or securities convertible into shares of our common stock, the percentage ownership of existing stockholders will be reduced. These stockholders may experience additional dilution in net book value per share and any additional equity securities may have rights, preferences and privileges senior to those of the holders of our common stock.\n Because we do not expect to pay dividends for the foreseeable future, investors seeking cash dividends should not purchase our shares of common stock. \n We have never declared or paid any cash dividends on our common stock, and we do not anticipate paying any cash dividends on our common stock in the foreseeable future. Payment of any future dividends will be at the discretion of our board of directors after taking into account various factors, including but not limited to our financial condition, operating results, cash needs, growth plans and the terms of any credit agreements that we may be a party to at the time. Accordingly, investors seeking cash dividends should not purchase shares of our common stock. \n Provisions of our certificate of incorporation, bylaws and Delaware law may make a contested takeover of our Company more difficult. \n Certain provisions of our certificate of incorporation, bylaws and the General Corporation Law of the State of Delaware (\"DGCL\") could deter a change in our management or render more difficult an attempt to obtain control of us, even if such a proposal is favored by a majority of our stockholders. For example, we are subject to the provisions of the DGCL that prohibit a public Delaware corporation from engaging in a broad range of business combinations with a person who, together with affiliates and associates, owns 15% or more of the corporation's outstanding voting shares (an \"interested stockholder\") for three years after the person became an interested stockholder, unless the business combination is approved in a prescribed manner. Our certificate of incorporation also includes undesignated preferred stock, which may enable our board of directors to discourage an attempt to obtain control of us by means of a tender offer, proxy contest, merger or otherwise. Finally, our bylaws include an advance notice procedure for stockholders to nominate directors or submit proposals at a stockholders meeting. Delaware law and our charter may, therefore, inhibit a takeover. \n The trading price of our common stock may be volatile. \n The trading price of our shares has from time to time fluctuated widely and, in the future, may be subject to similar fluctuations. The trading price may be affected by a number of factors including the risk factors set forth in this Annual Report on Form 10-K as well as our operating results, financial condition, announcements of innovations or new products by us or our competitors, general conditions in the biometrics and access control industries, and other events or factors. We cannot assure you that any of the broker-dealers that currently make a market in our common stock will continue to serve as market makers or have the financial capability to stabilize or support our common stock. A reduction in the number of market makers or the financial capability of any of these market makers could also result in a decrease in the trading volume of and price of our shares. In recent years broad stock market indices, in general, and the securities of technology companies, in particular, have experienced substantial price fluctuations. Such broad market fluctuations may adversely affect the future-trading price of our common stock. \n Table of Contents \n ITEM 1B. UNRESOLVED STAFF COMMENTS \n Not applicable.\n ITEM 1C. CYBERSECURITY \n We take a defense-in-depth approach, leveraging multiple, layered security measures, to protect our data, our customers' data, our infrastructure, and our employees. We embed data protection throughout our operations and information technology programs, relying on multiple and various controls to prevent and detect threats, with the goal of safeguarding our assets, data and personnel.\n \n \n \n We evaluate cybersecurity risks as part of our overall enterprise risk management. A steering committee of senior executives meets quarterly to evaluate any changes to the Company's exposure to cybersecurity risks, discuss potential mitigation plans, and provide updates on mitigation efforts already underway. Our cybersecurity team keeps up to date on the latest threats and risks through multiple channels and is also involved in evaluating risks associated with any new proposed service providers. We employ a Cybersecurity Engineer, reporting directly to our Chief Technology Officer, who manages our cybersecurity team that is comprised entirely of security professionals with industry recognized certifications. Our Cybersecurity team is responsible for assessing and managing risks associated with both our internal operations and our use of third-party service providers and informing/gaining feedback from the cybersecurity steering committee.\n \n \n \n Additionally, our cybersecurity team maintains a comprehensive set of cybersecurity policies and standards, including a security incident response framework. The framework is a set of coordinated procedures and tasks that our incident response team executes to ensure timely and accurate reporting and resolution of computer security incidents. The framework details who, how and when appropriate persons or committees, including the Board of Directors and Audit Committee are kept informed on the status of potential cybersecurity incidents. A summary of recent incidents is also presented by the Chief Legal Officer (\"CLO\") at each regular Audit Committee meeting. Our policies and standards were developed in collaboration with a wide range of disciplines, including information technology, cybersecurity, legal, compliance and business. Our cybersecurity strategy and policies are continually reassessed to ensure they attempt to identify and proactively address the constant changes in the global threats. Decision makers such as the CLO, executive team, and Audit Committee are regularly kept up to date on cybersecurity trends. Ongoing collaboration with stakeholders throughout the business also helps to build continued awareness and visibility of future needs.\n \n \n \n We engage external vendors to assess the cybersecurity program as needed. An independent third party will perform annual multi-stage penetration testing of our IT environment.\n \n \n \n Our cybersecurity program is governed by the Audit Committee of our Board. The Audit Committee of the Board and the full Board will each receive quarterly updates on cybersecurity risks identified through the enterprise risk management processes described above.\n \n \n \n Notwithstanding our processes to oversee and identify risk from cybersecurity threats, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us. We identify nation state-sponsored threat actors and the rise in sophistication and proliferation of ransomware campaigns as top reasonable material risks to the business. The theft, unauthorized use or publication of our intellectual property and/or confidential business or personal information (whether through a breach of our own systems or the breach of a system of a third party that provides services to us) could harm our competitive or negotiating positions, reduce the value of our investment in research and development and other strategic initiatives, compromise our patent enforcement strategies or outlook, damage our reputation or otherwise adversely affect our business. To date there have not been any risks that have materially affected our operations.\n \n \n \n See Item 1A. \" RISK FACTORS \" for a discussion of cybersecurity risks.\n ITEM 2. PROPERTY \n We do not own any real estate. We conduct operations from leased premises in Eagan, Minnesota (1,994 square feet), Bedford, New Hampshire (3,364 square feet), and Holmdel, New Jersey (150 square feet). Internationally, we conduct operations from leased premises in Tsuen Wan, Hong Kong (1,098 square feet), Jiangmen, China (3,267 square feet), and Madrid, Spain (1,504 square feet). Our Eagan, Minnesota and Bedford, New Hampshire offices provide research and development, and customer support, for BIO-key software and PistolStar software, respectively. Our Holmdel, New Jersey location serves as our corporate headquarters. Our Hong Kong location is a small warehouse for finished goods as well as administrative and sales support. Our Jiangmen, China facility provides our hardware research and development, contract manufacturing and warehousing of raw materials, work-in-process, and finished goods. Our Madrid, Spain office serves as our sales organization for Europe, the Middle East, and parts Africa.\n ITEM 3. LEGAL PROCEEDINGS \n From time to time, we may be involved in litigation relating to claims arising out of our operations in the normal course of business. As of the date of this report, we are not a party to any pending lawsuit.\n ITEM 4. MINE SAFETY DISCLOSURES \n Not applicable.\n Table of Contents \n PART II \n ITEM 5. MARKET FOR REGISTRANT ' S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES \n Our common stock currently trades on the OTC Markets under the symbol \"BKYI\".\n Holders \n As of June 10, 2026, the number of stockholders of re...
View stock analysis, news, and events for Bio-key International, Inc.