At a border checkpoint, a camera reads your face in under a second. A database somewhere confirms who you are, or thinks it does. You move on, or you don’t. What happens in that second, and what happens to the data afterward, is exactly what the public deserves to understand.
That database is called HART: Homeland Advanced Recognition Technology. DHS developed it to replace IDENT, a legacy biometric system, and the upgrade is not modest. Planning documents projected roughly 260 million identities stored in the system. That number exceeds the entire population of Brazil. The modalities go beyond fingerprints, including face images and iris scans, with plans to add voice, DNA profiles, and physical markers like scars and tattoos. This is not a filing cabinet. It is a multimodal biometric repository, and the records it holds are not the kind you reset the way you’d reset a hacked Netflix password.
What HART Actually Is
The system’s architecture is more expansive than a routine government technology upgrade.
Northrop Grumman won approximately $95 million to build the first two increments of the system. HART was designed to run on Amazon Web Services’ GovCloud infrastructure. Each biometric category it stores represents a different way to identify a person across different conditions and locations.
Unlike a leaked password, you cannot change your face. A database leak exposing millions of biometric records would leave those individuals permanently vulnerable in ways no password reset could fix.
That permanence is what makes governance so consequential. The technology’s capabilities are documented. The questions are what surrounds them.
The Error Isn’t Just Technical. It’s Who Bears It.
Demographic disparities in facial-recognition accuracy are not an edge-case concern; they are a documented pattern with real consequences.
NIST evaluated hundreds of facial-recognition algorithms and found that false-positive rates for Asian and African American faces often ran 10 to 100 times higher than for Caucasian faces in one-to-one verification. That means the system incorrectly confirms that two different people are the same person. The range varies by algorithm and image quality, so it is not a universal verdict on every tool in use. The U.S. Commission on Civil Rights documented those disparities in a 2024 report on facial-recognition technology, specifically noting heightened consequences when erroneous matches occur in border and immigration contexts. Community resistance to automated surveillance infrastructure has grown in parallel with these documented accuracy concerns.
The distinction between one-to-one verification and a one-to-many search matters here. Checking whether two photos match is a different problem than scanning one face against millions of records. One-to-many searches can produce different error distributions, and the operational consequences scale accordingly.
A shareholder resolution filed with the SEC flagged additional concerns: risks to privacy, First Amendment rights, immigrant communities, and algorithmic racial bias connected to Northrop Grumman’s role in building the system. These are documented advocacy positions, not established findings of misconduct. They point, however, to real questions that procurement documents alone cannot answer.
What the System Still Owes the Public
The governance questions surrounding HART are not rhetorical; they are the difference between a legitimate identity system and an unaccountable one.
The core problem is the absence of clear, public answers to basic questions. How long are records retained? Which agencies can query the database, and under what authority? How does someone challenge a false match? Do independent audits test real-world demographic performance across actual deployments? Cases of secretly tracking users without meaningful oversight illustrate exactly how quickly that accountability gap can widen when governance frameworks lag behind technical deployment.
Governments have long verified travelers crossing their borders, and identity infrastructure at this scale is not inherently wrong. What is harder to defend is projecting a system touching the records of roughly 260 million people, storing biometric identifiers that are generally far more difficult to replace or revoke than passwords, without a governance architecture proportionate to that reach.
Your face is not a password. Treating it like one, without the oversight to match, is the accountability gap HART still needs to close.




























