02Industries · Payments

Approve the payment, not the phish

When your risk engine escalates a transaction, the challenge should be stronger than a typed code. SenseCrypt turns approval into a live-face ceremony bound to the exact merchant and amount.

01The ceremony

From risk signal to signed approval

  1. Risk engine requests step-up

    Your policy decides when to ask

  2. CIBA request is created

    Merchant, amount, action, expiry

  3. Customer sees the exact request

    Live face plus intent, on their own phone

  4. Checkout gets the signed result

    Approval or denial, plus an audit reference

02The outcomes

Why payment providers pick SenseCrypt

For your customers

Approval that names the request

Each prompt shows the verified app and the exact action being approved. Only the enrolled person's live face can grant it.

Backchannel confirmation, built in

Your server starts the approval over CIBA. The customer confirms on their own device while checkout waits for the signed result.

No code left to capture

Interception is an attack on things in transit, and nothing secret is in transit. The code was never sent.

Step up only when it matters

Keep low-risk payments one-step. Escalation stays your call, and SenseCrypt supplies the strong step.

Your checkout, their phone

Buyers approve in the authenticator app on the phone they already carry, or inside your own app with the embedded SDK. The device at checkout needs no enrollment.

For your workforce

Ops and fraud teams, same platform

Your internal consoles ride the same IdP, with roles, scopes, and every action on the audit trail.

For partners & B2B

Merchant portals, per tenant

Each merchant gets an isolated tenant with its own users and branding: SSO you offer, not build.

03The failure modes

What gets in the way today

Codes transit channels you don't control

SMS and email one-time codes are phished, SIM-swapped, and relayed at scale. They are still the default step-up.

Friction is measured in abandoned carts

Every extra code typed at checkout costs completed payments; every reset costs a returning customer.

Push fatigue is the new phishing

Users tap Approve to make prompts go away. Attackers count on exactly that.

3-D Secure friction, your problem

Challenge flows bolted onto checkout cut completion. The customer blames your brand, not the issuer.

Account takeover pays for itself

Stored cards make every account worth taking over, and stuffed passwords are the cheapest way in.

A different challenge on every channel

Web, app, and in-store each authenticate differently. Users feel the inconsistency, and fraud exploits it.

04The compliance map

What the regulator sees

Possession of the enrolled device plus a live face gives you two independent factors, a strong foundation for SCA step-up, without an OTP in sight.

PSD2 SCA — dynamic linking (RTS Art. 5)

Each approval names the amount and the payee, and the signed result is specific to both. That supports the dynamic-linking requirement in Article 5 of the EBA's technical standards for strong customer authentication.

Read the source

NIST SP 800-63B — phishing resistance

A code the customer types can be relayed, which is why NIST SP 800-63B excludes manually entered one-time codes from phishing resistance. SenseCrypt replaces the typed code with a live-face approval bound to the enrolled device.

Read the source

Face matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)

PSD2 SCA GDPR PDPA
Built from the same three solutions: Customer identity Workforce SSO B2B SaaS

Make approval the strongest step in the flow

Passwordless, phishing-resistant confirmation, wired in through CIBA.