The remote IT worker story no longer needs retelling. The laptop farms, the deepfaked interviews, and the state-sponsored operatives drawing salaries inside major companies are public record, and we have already covered what detecting fake IT workers actually takes and how the schemes reach the federal supply chain. The mechanics have stayed stable for years: the fraud works because verification usually runs on hardware the applicant controls. A virtual camera driver, a device emulator, or a proxy in front of the session defeats a software check without leaving much of a trace.
This article is about the part only we can describe. Trust Swiftly operates what we believe is the largest dedicated fleet of NIST IAL3 identity proofing hardware in the world: more than 200 controlled units, shipped Remote Kits and on-premise kiosks, with coverage across all 50 US states and 32+ countries. Below is why the standard demands controlled hardware, how the fleet removes the travel that has kept IAL3 rare, and what the units measure that a webcam cannot.
NIST Wrote Controlled Hardware Into the Standard
The controlled-hardware requirement comes from the standard itself. NIST SP 800-63A-4 states that IAL3 identity proofing "SHALL only be delivered as on-site attended." The proofing agent may be co-located with the applicant or attend the session through a CSP-controlled kiosk or device. In earlier revisions this remote-agent model was called Supervised Remote Identity Proofing; revision 4 folds it into on-site attended proofing, with additional requirements attached to the controlled device itself.
Those requirements are specific. All digital validation and verification of evidence must be performed by integrated scanners and sensors, not by an applicant's phone. The devices must be safeguarded against tampering through observation or monitoring, plus physical and digital tamper-prevention features, protected by baseline security comparable to at least FISMA moderate controls, and inspected periodically by trained technicians. The entire session runs over high-resolution video with a live proofing agent present for evidence collection, validation, and verification, and the agent is trained to identify signs of manipulation, coercion, and social engineering.
The standard also names the attack this architecture defends against. Its injection-prevention section requires providers to implement technical controls that increase confidence media is being produced by a genuine sensor, to analyze all submitted media for signs of forgery, and to introduce random human-in-the-loop cues during capture. NIST is candid that all types of remote identity proofing are in some way vulnerable to these attacks, and that even presentation attack detection does not cover every case. A sealed, instrumented capture path is how that expectation is met in practice.
More Than 200 Units, Deployed Where People Actually Work
Historically, reaching this bar meant sending an employee to an enrollment center, with the scheduling delays and travel that implies. The fleet inverts that model.
Remote Kits shipped to the individual. A pre-configured, cryptographically provisioned kit arrives by tracked carrier at a remote hire's home, across the 50 states and the 32+ countries we cover. The attended session itself takes as little as 15 minutes. The kit then returns on a prepaid label and is physically inspected and re-provisioned before it goes back into circulation. There is nothing to erase between users: the units are ephemeral by design and hold no session data stored locally on the device, so a kit in a courier van is hardware, not a briefcase of identities. The standard requires periodic inspection by trained technicians; ours are inspected after every deployment cycle, because equipment that travels deserves more scrutiny than equipment that does not.
On-premise kiosks for concentrated volume. For headquarters, cleared facilities, and large onboarding cohorts, fixed and portable kiosks handle steady throughput without per-session logistics. They run on isolated connectivity rather than the corporate network, and the same tamper, inspection, and monitoring regime applies.
Because a kit in transit takes days rather than weeks, organizations with urgent starts run an IAL2 pathway in parallel, at its own lower assurance level, and complete IAL3 when the hardware arrives, then bind phishing-resistant AAL3 authenticators in the same attended session. Every session produces the audit-ready evidence package a 3PAO or authorizing official will ask for, which is what FedRAMP High and defense authorization reviews actually examine.
Scale claims deserve scrutiny, so here is the basis for ours. The kiosk networks that publish larger location counts, including the retail networks and postal counters, operate at IAL2. The fingerprinting storefronts do not perform NIST identity proofing at all. The few providers that do operate IAL3-capable stations publish no fleet numbers and concentrate on fixed sites at partner venues, often a single station serving an entire state. In a large state, one fixed site can mean hours of driving each way; a kit that ships to the applicant makes the distance irrelevant. As far as public information allows us to determine, no one operates a larger dedicated IAL3 fleet, and no one publishes coverage that matches it.
The fleet is this large because the model requires it. A fixed-site vendor can cover its bookings with a handful of stations, since applicants absorb the travel and the waiting. A shipped kit works the other way: every unit in a courier van is a unit nobody can verify on, and transit, inspection, and re-provisioning all subtract from usable capacity. Meeting service-level commitments for a growing roster of customer companies and their new hires means holding enough hardware that a kit is always ready to ship the day it is requested. More than 200 units is what that arithmetic requires today. The fleet has grown steadily since the first kits shipped, and it keeps growing, because every new customer brings a workforce with it.
Hundreds of Datapoints, Most of Them Invisible
The deeper reason the fleet matters is instrumentation. A browser-based verification can read one camera stream and whatever the operating system chooses to report about it. A controlled unit is a different class of instrument, and each session on one is measured against hundreds of datapoints, most of which an applicant never sees and an attacker cannot reach.
Some of them we are comfortable describing. The units carry LiDAR, so the session captures the actual three-dimensional geometry of the scene; genuine depth, image, and motion readings agree with one another in ways that injected or replayed footage has to fabricate simultaneously, frame after frame. Infrared structured-light mapping measures the shape of a live face rather than the pixels of one. Position is never taken from a single source: satellite positioning, the surrounding Wi-Fi environment, the cellular path, and the network route the session actually travels are checked against each other, and round-trip timing physics sets distance bounds that a relay or VPN can lengthen but never shorten. Barometric pressure and device motion feed the same picture of the environment. Every reading arrives cryptographically bound to a specific, hardware-attested unit, so the measurements themselves cannot be quietly substituted.
We do not publish the complete signal inventory, the way the checks reinforce one another, or what triggers escalation, for the obvious reason. The architecture is the point: the signals are independent physical measurements, so an attacker who convincingly fakes one still has to fake the rest, in real time, in agreement, inside hardware they do not control. Defeating a software check requires one good tool. Defeating a sensor array requires a physics problem to go your way several times at once.
The sensor data goes to a person. Telemetry surfaces to the live proofing agent during the session, alongside what NIST already requires of them, and the agent decides what to do with it. This mirrors our position on nation-state-grade deepfake detection: layered evidence for a trained human, not a silent verdict from a closed box.
Silicone Masks Have Caught Up With Cameras
Injection is only the digital route. The physical route is simpler: instead of tampering with the video stream, the applicant wears a different face. Ultra-realistic silicone masks with hand-punched hair, eyebrows, and beards sell openly on mainstream marketplaces for around two thousand dollars, and the better ones photograph convincingly on an ordinary webcam. This is a product category with stock levels and customer reviews, not a spy-movie prop.
![]()
NIST anticipated this class of attack as well: during collection, the standard requires the proofing agent to view the biometric source for unexpected non-natural materials. Our units back that human inspection with physics, because living skin has properties no molded material reproduces. Skin scatters light beneath its surface; silicone reads flat. A face carries blood flow and holds a living temperature; a mask does neither, and thermal and infrared measurement register the difference even when the eye misses it. Real wrinkles deepen and release as a face moves; molded ones sit still. The live agent can also ask for movements and expressions a mask cannot follow.
As with the rest of the array, we do not say which of these checks run at which moment, or where the thresholds sit. It is enough for anyone considering borrowing a face to know the checks exist.
What the Fleet Does Not Do
Honest scoping matters at this assurance level. Identity proofing establishes that a real, present person matches valid evidence, that the evidence is authentic, including cryptographic verification of the chip in passports and other chip-enabled credentials, and that the authenticators issued afterward are bound to that person. It does not read intent. A correctly identified employee can still go on to do harm, demeanor is not a security control, and no sensor array changes that. What the fleet removes is the impersonation layer: the proxy interviewee, the borrowed identity, the injected camera, the mask, the operator who was never in the country they claimed. Programs that need the rest of the insider-threat picture should treat proofing as one control among several, a topic we cover in our work on hidden insider threats.
High Assurance Without the Travel
For years the practical obstacle to IAL3 was not the standard but the trip: a distant enrollment site, an appointment backlog, a workday lost to driving. More than 200 controlled units, with coverage across all 50 states and 32+ countries, remove the trip without touching the assurance bar. The sessions take minutes, the evidence holds up in front of assessors, and nobody spends a day on the interstate to prove who they are.
Explore our turnkey IAL3 verification solution, read our guide to choosing an IAL3 solution, or talk to us about deploying kits and kiosks for your workforce.