Updated

May 1, 2025

Reading Time

13 min

You can learn more about Contrary Research and our repository of private company research here!

Eric Tarczynski sat down with Rick Song, co-founder and CEO of Persona, in May 2025, shortly after the company raised a $200 million Series D. The conversation covered what Persona means by a verified identity layer, why its strategy stayed the same from 2019 onward, how it balances businesses and consumers, how it detects AI-generated fraud, and how Song expected identity to shift toward continuous attestation and verified agents acting on a person's behalf.

Five Key Takeaways

  1. Persona's strategy held steady while verification methods changed: At Persona's first board meeting after its Series D, which closed at a $2 billion valuation in April 2025, Song presented the company's strategy decks from every year since 2019 and said they were effectively the same. He argued that identity methods keep evolving, from Social Security numbers to 2FA to government IDs, biometrics and mobile driver's licenses, and that Persona was built to bring those methods together on one platform.

  2. The business is almost entirely business-facing: Song said 99% of Persona's focus was on the business side, but that consumers are the ones who move through its flows, which he put at hundreds of millions of people a year. He said the consumer investment may not be core to the business, though he called it core to the problem Persona is solving, with the aim of making people as comfortable submitting personal information online as they became with entering a credit card.

  3. AI fraud detection relies on context as much as the image: Song called the view that AI had made image-based verification worthless too extreme. He described Persona's approach as an ensemble that looks at the raw image for artifacts, the environment and behavior of the capture, and population-level anomalies, and said the contest with fraudsters would keep evolving the way payments fraud has.

  4. Identity is moving toward continuous attestation: Drawing on the history of card fraud, Song expected identity to shift from one-time credentials to confidence built from a person's prior verifications across services. He predicted that the relevant question online would move from whether someone is human to who they are.

  5. Agents should carry verified identities from the start: Song argued that AI agents should carry an identity from the start, tied to the person they act for, with a phone prompt to confirm high-stakes actions. He compared Persona to AWS for personal information, saying Persona does not own customer data, and framed consumer ownership of identity as the safeguard against the layer becoming surveillance.

Full Transcript

Building a Verified Identity Layer

E

Eric

For those who might be less familiar with Persona, what do you do and why is it important for the world?

R

Rick

At our core, we build a platform that enables both businesses and consumers, and I want to talk about it that way because we serve both halves. This is what we mean when we talk about building the verified identity layer. The reason we call it a layer is that we operate at this interface between businesses and consumers.

For businesses, what we offer is a complete suite of all the verification technologies they need to build their ideal way to know who's behind the screen. The real person: not just an email, not just an identifier, not a username, but who it is as recognized by your government ID or whatever. Who are you in the physical world, and any way in which they want to have high confidence that this person is who they say they are. On top of that, we help them manage the personal information. We create a suite of tools to do all the operational tasks, from making decisions about them to longer-term security purposes around that personal information, and anything they really need around interfacing with PII and real people.

For consumers, our goal is to create an experience and interface in which they can easily verify themselves. And ideally, long term, they'll control the identity and create a portable identity, so that no matter where they are, they're able to continually re-verify themselves in a more seamless, yet also more secure, way.

E

Eric

Walk me through what the product evolution has looked like over time for Persona.

R

Rick

It's interesting, because a lot has and has not changed. When we raised our Series D and had our first board meeting, I did a bit of a cheeky thing. I took our strategy decks for the past five years and presented all five of them, just the one summary slide: "This is our strategy since 2019, 2020, 2021, 2022, 2023, and 2024." And I went through them, and it's effectively the same thing, because the core of identity hasn't fundamentally changed.

Whenever anyone joins the company, I always like to tell them that identity is one of the simplest problems, one you almost think of first. That's why there are so many competitors and so many companies in the space. It's like payments. The moment the internet existed, the first idea immediately was, "How can I make money off this?" And the second idea is, "Who is making the money, and who is on the other side of every single transaction?" That means this is a really storied space, too. We're not a disruptive business in a space where the technology hasn't existed and people haven't been able to do things. People have done identity in a lot of ways for a long time.

The initial genesis of the idea for us was that identity is also ever-evolving. Since the earliest days, you would have your SSN, and you'd put that in. Later on, that would evolve into these back-of-envelope questions. Then people started doing more around 2FA, using a phone to look things up. It's continual evolution. Today, it's a lot of submitting a government ID and biometrics. But for us, the Persona idea was that this will probably continue evolving. Today we have a lot of new technology around digital IDs, mDLs, and all these new innovations governments are spearheading. We wanted to create a platform to piece all of this together, because every single business out there is continually thinking about each one of these. How does it fit together for my business? How does this all work? We want to bring all that together for our customers.

So on one half, we've been constantly building out new verification technologies since day one. But on the second half, the product was never really a single product. Our core idea was always a consolidation of sorts: how can we bring everything together? Because identity, in our eyes, was only going to get ever more sophisticated and ever more complex.

Businesses First, Consumers Over Time

E

Eric

You mentioned the two pieces of the puzzle for you: the enterprise offering and the individual consumer offering. Did you start with both of those in the beginning, or did you pick one? And which, if either, is more important to the success of the business?

R

Rick

Ever since the earliest days, I would say we are 99% on the business side, and we started like that from the start. The reason we say layer, though, is that the folks who actually use the product are consumers, on behalf of our businesses. A business would deploy it, and it would create a Plaid-esque pop-up that a consumer interfaces with. As consumers use Persona more and more, and I think we have hundreds of millions of folks going through Persona a year now, we want to offer ways in which consumers can also control their data more. At the end of the day, maybe it's not core to our business, but it's core to the idea of what we're trying to solve, which is how we can have a more seamless, more private identity for any use case out there.

I don't think that's going to change. We will continue to build our business offering tools and verification technologies for businesses to integrate and operate on. On the individual side, our goal is to continually invest in ways for consumers to know who has access to their data, maybe redact it, and simplify how they have control of it.

I oftentimes say that 20 years ago, in the early 2000s, making an online payment was one of the scariest things in the world. Putting your credit card information online was just so deeply insecure. Today, no one thinks twice about it. The technology itself hasn't fundamentally changed, but the security of how people manage your credit card information has fundamentally been just complete. For some of these major institutions, like a Stripe or Square, the last time any data has been leaked is never. For PII, I don't think we feel that way today. When you put in your SSN, there's this immediate sense that your data might be breached. So we believe that benefiting the consumer will continually create comfort around how you verify and how you submit data online.

From AI Deception to Agent Identity

E

Eric

The advent of AI is obviously deeply important to the work you do, and in many ways it's something you try to identify and stamp out. Walk me through what, if anything, you're doing to combat what I'll call AI-induced deception today.

R

Rick

I'll talk about this in three stages. The first is immediate. I wouldn't say AI has made image-based recognition completely worthless. I think that's too extreme of a take. Some folks say it can generate anything in the tracks there. But if you look at actually capturing an image, capturing a selfie, capturing a government ID, the entry has always mattered. A while back, people would say, "Given that all data has been breached and leaked, you can just copy and paste SSNs in." And then people started realizing that the behavioral signals are almost, if not just as, important as the data itself.

I think the same thing remains true for government IDs and biometrics. The evolution of how to detect AI right now is an ensemble model. There's the raw data itself, the image, which sometimes has artifacts or mistakes. There's the environment and all the ways in which you're capturing it. And finally, at a population level, there's detecting trends that make this a highly anomalous identity with high risk associated with it, and bringing all of these together.

But in a lot of ways, we believe that today you still need to collect information. At the end of the day, much of proof of identity continues to be a combination of something you know, something you own, or something you are. We continue doing that, but we also layer it with additional context, because the act itself is sometimes as interesting as the data you're sharing. So that's the today answer: we have to continue to improve that technology. Is it a constant battle of us trying to improve and fraudsters quickly adapting? Yes, and it'll continue like that. Like payments fraud, it's an ever-evolving space. At its very core, it's security and cybersecurity, and security is an ever-evolving space.

The second stage is more about what it means to be human online long term. We think the space is going to increasingly move from one-time transactional credentials to, hopefully, a longer-term model where you prove who you are through your previous activities as well.

I'll give an analogy to payments again. Twenty years ago, the best way to know if a payment was real was your credit card number. If you sent me your credit card number, then hopefully the transaction was real. What ended up happening, though, is that credit card numbers leak and people make false transactions, so it was a huge deal. Today, we're not worried about folks breaching, and we're also not nearly as worried about our credit card number being leaked. When it happens, you immediately get notified, and there's an entire process, because it's based off all your previous transactions.

We think identity is moving in the same direction. The best way to know who you are is not, "I submitted a government ID, I sent in this biometric this one time." I think the future has to be one where it's, "I've verified myself before, I can do a little less this time, but I'm attesting again that I'm me." Let's say I ordered some alcohol, later signed up to be a delivery driver, opened a new OpenAI account, signed up for a Coursera course, and am trying to attest to my degree. All these interactions, longer term, will really be what creates the confidence that you are who you are: the continuous attestation that you are who you are.

The third evolution is much longer term: the question of what the future of AI means for the internet. This is probably the most thought-provoking one. If we believe agents are going to increasingly navigate the internet on our behalf, I don't think the right thing is to make agents prove who they are. Rather, maybe the agents themselves should have an associated identity from the get-go, a verified agent that is acting on my behalf. In a dream world, it would almost be like, "Hey agent, please go make this DoorDash delivery for me." What happens immediately is I get a push notification on my phone saying, "Are you who you say you are?" I can immediately say yes, and then it continues the action on my behalf.

In my eyes, that's where the evolution of this space will go. A core of what we believe right now is that the question of whether you are human or not is probably, long term, no longer going to be the relevant question. It's always going to be, "Who are you?" Attestation, consistently re-proving who you are at various junctures throughout your online journey, is the future. And that's the right path forward as we think about identity verification and security.

The only tricky thing there is how we make sure we do that in a way that doesn't leak everything about us. How does this not become surveillance? That's why we also believe so heavily in the idea of self-sovereignty, an ownership aspect. Going back to the earlier question of why we're investing on the consumer side, that's a big part of it. Persona doesn't own any customer data whatsoever. We may warehouse it and help create infrastructure for folks to manage it. But one thing we oftentimes compare ourselves to is AWS for personal information. If I build my service on AWS, AWS is the one powering and managing all the services, but it's my data, it's my code, it's all of that. It's the same with us. We build identity infrastructure. We're not building a network that tracks everyone's activities online. Our goal is to give everyone else the tools to do it, and ideally that also means giving consumers the tools to own their identity and create a profile for themselves that they can continually use everywhere else.

Additional Reading

Important Disclosures

This material has been distributed solely for informational and educational purposes only and is not a solicitation or an offer to buy any security or to participate in any trading strategy. All material presented is compiled from sources believed to be reliable, but accuracy, adequacy, or completeness cannot be guaranteed, and Contrary LLC (Contrary LLC, together with its affiliates, “Contrary”) makes no representation as to its accuracy, adequacy, or completeness.

The information herein is based on Contrary beliefs, as well as certain assumptions regarding future events based on information available to Contrary on a formal and informal basis as of the date of this publication. The material may include projections or other forward-looking statements regarding future events, targets or expectations. Past performance of a company is no guarantee of future results. There is no guarantee that any opinions, forecasts, projections, risk assumptions, or commentary discussed herein will be realized. Actual experience may not reflect all of these opinions, forecasts, projections, risk assumptions, or commentary.

Contrary shall have no responsibility for: (i) determining that any opinions, forecasts, projections, risk assumptions, or commentary discussed herein is suitable for any particular reader; (ii) monitoring whether any opinions, forecasts, projections, risk assumptions, or commentary discussed herein continues to be suitable for any reader; or (iii) tailoring any opinions, forecasts, projections, risk assumptions, or commentary discussed herein to any particular reader’s objectives, guidelines, or restrictions. Receipt of this material does not, by itself, imply that Contrary has an advisory agreement, oral or otherwise, with any reader.

Contrary is registered with the Securities and Exchange Commission as an investment adviser under the Investment Advisers Act of 1940. The registration of Contrary in no way implies a certain level of skill or expertise or that the SEC has endorsed Contrary. Investment decisions for Contrary clients are made by Contrary. Please note that, although Contrary manages assets on behalf of Contrary clients, Contrary clients may take any position (whether positive or negative) with respect to the company described in this material. The information provided in this material does not represent any investment strategy that Contrary manages on behalf of, or recommends to, its clients.

Different types of investments involve varying degrees of risk, and there can be no assurance that the future performance of any specific investment, investment strategy, company or product made reference to directly or indirectly in this material, will be profitable, equal any corresponding indicated performance level(s), or be suitable for your portfolio. Due to rapidly changing market conditions and the complexity of investment decisions, supplemental information and other sources may be required to make informed investment decisions based on your individual investment objectives and suitability specifications. All expressions of opinions are subject to change without notice. Investors should seek financial advice regarding the appropriateness of investing in any security of the company discussed in this presentation.

Please see www.contrary.com/legal for additional important information.

© 2026 Contrary Research · All rights reserved

Privacy Policy

By navigating this website you agree to our privacy policy.