How it works

Passwordless Authentication Without Storing Biometric Data

SenseCrypt is a passwordless identity provider that signs users in by face while storing no face image and no biometric template — only a sealed, non-reversible face token. The face match runs on the device, so the server never receives your face, and the one artifact kept is a token that even Seventh Sense, SenseCrypt's maker, cannot reverse.

On this page
  1. How can you have face login without storing biometric data?
  2. What does "template-free face authentication" actually mean?
  3. Where does the face match happen — on the device or in the cloud?
  4. Is SenseCrypt's face recognition and liveness independently proven?
  5. How do passkeys and face verification work together?
  6. Does template-free face login store a biometric template?
  7. What standards, protocols, and sign-in methods does SenseCrypt support?
  8. How much does it cost, and how do I try it?
  9. Why does storing no biometric template matter for your risk profile?
  10. Frequently asked questions

How can you have face login without storing biometric data?

SenseCrypt enables face login without storing biometric data by matching your face on your device and keeping only a sealed, unlinkable, non-reversible face token — never a face image and never a biometric template. The token contains no PII and cannot be reversed back into a face.

Because the comparison happens on the device and the server side holds only a non-reversible token, there is no central store of faces to breach, sell, or subpoena.

Enroll from a photo on file

You register from an existing photo, so no separate biometric database is built.

Sign in by face

At login you present your live face to the device camera.

Match on the device

Face matching runs locally on the device, not in the cloud.

Store only a token

The system persists a sealed, non-reversible face token — no image, no template, no raw biometric.

What does "template-free face authentication" actually mean?

Template-free face authentication means the identity provider verifies your face without ever creating or storing a reusable biometric template or face image. SenseCrypt is built to this model: the only stored value is a sealed token that is non-reversible and contains no personal data.

This matters because a biometric template is the durable, sensitive asset in most face systems — it can be stolen, correlated across services, and it cannot be reissued the way a password can. SenseCrypt removes that asset from existence.

No face image is stored

There is no picture of your face on the server.

No biometric template is stored

There is no reusable, matchable template to steal or correlate.

Only a sealed, non-reversible token is kept

The token is unlinkable, carries no PII, and cannot be turned back into a face.

Biometric-blind by design

Even Seventh Sense, SenseCrypt's maker, cannot reverse the token into a face or template.

Where does the face match happen — on the device or in the cloud?

The face match happens on the device, not in the cloud. Your live face is compared locally, so raw biometric data never travels to SenseCrypt's servers and there is no server-side face database to protect.

On-device matching is the mechanical reason the "no stored biometrics" claim holds. If the face were matched server-side, the server would need the face; because it is matched on the device, the server only ever sees the sealed token.

Is SenseCrypt's face recognition and liveness independently proven?

Yes. SenseCrypt's face recognition is evaluated in the NIST FRTE (Face Recognition Technology Evaluation) program under its own developer name since 2021, and its liveness / presentation-attack detection holds iBeta ISO 30107-3 certification. These are independent, third-party validations, not self-reported claims.

Template-free storage protects the data; NIST FRTE and iBeta ISO 30107-3 prove the recognition and liveness are strong enough to trust the login itself.

NIST FRTE (Face Recognition Technology Evaluation)

SenseCrypt's face recognition has been entered under its own name (developer ID seventhsense-000) since 2021, so accuracy is measured by the U.S. National Institute of Standards and Technology, not by the vendor.

iBeta ISO 30107-3 (Presentation Attack Detection)

SenseCrypt's liveness detection is independently certified at Level 1 and Level 2 to resist presentation (spoofing) attacks such as photos, video replays, and masks.

How do passkeys and face verification work together?

SenseCrypt is a full identity provider built on real FIDO2/WebAuthn passkeys (ES256): the passkey proves the device, and a live-face check proves the person. On the passkey path it is phishing-resistant because WebAuthn binds the credential to the site's origin.

This two-factor split is the point. A device unlock confirms that a device was unlocked — it does not, on its own, confirm which live person did it. SenseCrypt adds an on-device, template-free face check so you verify the live person, not just the device, while keeping the phishing-resistance of WebAuthn.

Does template-free face login store a biometric template?

No — template-free face login stores no biometric template and no face image. The table below contrasts common passwordless approaches on the two questions buyers care about: whether the live person is verified, and whether a biometric template or image is stored.

The row that exposes SenseCrypt's wedge is "Stores a biometric template or face image?" — its answer is a clean No for a server-side face IdP, keeping only a sealed, non-reversible token. That is a materially different privacy posture from storing a template. The other rows are approach-level generalizations; specific vendor behavior varies and should be confirmed per product.

What standards, protocols, and sign-in methods does SenseCrypt support?

SenseCrypt speaks the enterprise identity stack: OIDC, OAuth 2.0 (with PKCE + PAR), SAML 2.0, SCIM 2.0, and CIBA, with RBAC, audit logs, and multi-tenant isolation. It integrates through standard metadata files and discovery URLs, so it can act as the IdP of record rather than only an authenticator.

  • Simple QR + face in the SenseCrypt app.
  • FIDO2 passkeys via a roaming authenticator.
  • Simple Webcam for enterprise deployments (contact sales@seventhsense.ai).
  • Solutions span customer identity (CIAM), workforce SSO, and B2B SaaS SSO.

How much does it cost, and how do I try it?

SenseCrypt is priced at a flat $1 per user per month, with a 30-day free trial and no credit card required. You can run a live demo in about 60 seconds at sensecrypt.com/try-it-live.

  • Pricing: flat $1 per user per month.
  • Trial: 30 days, no card.
  • Live demo: roughly 60 seconds at /try-it-live.

Why does storing no biometric template matter for your risk profile?

Credential and phishing attacks remain a dominant breach vector, and passwordless, phishing-resistant login attacks that vector directly: FIDO2/WebAuthn binds each credential to the site's origin so a lookalike page cannot harvest a usable secret.

Biometric systems add a second risk: the stored template. A reusable template is a permanent, un-resettable secret — if it leaks, it cannot be reissued the way a password can. SenseCrypt sidesteps that storage risk entirely by keeping no template and no image, so there is simply nothing biometric on the server to lose.

How passwordless approaches compare on live-person verification and biometric storage (approach-level generalization; confirm per named vendor before publishing)

Authentication approachVerifies the live person (not just the device)?Stores a biometric template or face image?Phishing-resistant?
SenseCrypt (template-free face authentication)YesNo — only a sealed, non-reversible tokenYes (on the passkey path)
Legacy / server-side face recognitionYesYes — stores a template or imageVaries
Device-only biometric unlock + passkeys (e.g. Face ID / Windows Hello)No — confirms device unlock; biometric stays on the deviceNo server-side storeYes
Password + SMS/email OTPNoNoNo

Frequently asked questions

Does SenseCrypt store my face or a face image?

No. SenseCrypt stores no face image and no biometric template — only a sealed, unlinkable, non-reversible face token that contains no PII.

Can the stored token be reversed back into my face?

No. The face token is non-reversible by design; even Seventh Sense, SenseCrypt's maker, cannot reverse it into a face or biometric template.

Where is my face actually matched?

On your device. Face matching runs locally, so raw biometric data is never sent to or held on SenseCrypt's servers.

Is the face recognition independently tested?

Yes. SenseCrypt's face recognition is evaluated in the NIST FRTE program under its own name since 2021, and its liveness holds iBeta ISO 30107-3 (Presentation Attack Detection) certification at Levels 1 and 2.

How does this work with passkeys?

SenseCrypt is built on real FIDO2/WebAuthn passkeys (ES256). The passkey proves the device through WebAuthn origin binding, and an on-device, template-free live-face check proves the person — so you verify the live person, not just the device, while staying phishing-resistant on the passkey path.

What identity standards does it support, and what does it cost?

OIDC, OAuth 2.0 (with PKCE + PAR), SAML 2.0, SCIM 2.0, and CIBA, plus RBAC, audit logs, and multi-tenant isolation, integrated via standard metadata files and discovery URLs. Pricing is a flat $1 per user per month with a 30-day free trial and no card.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.