FIDO2 / WebAuthn passkeys

Real passkeys prove the device. The live face proves the person

SenseCrypt is built on real FIDO2/WebAuthn passkeys (ES256). The passkey proves the device you hold, and a live-face check proves the person holding it. Two proofs, one sign-in.

How it works

A passkey and a live face, in one ceremony

Possession is the passkey's home turf. SenseCrypt adds the inherence factor, so the sign-in confirms who is present rather than only which device is present.

Passkeys prove the device

A passkey is an ES256 key pair bound to the device you enrolled. It proves you hold that device, and the private key never leaves it. SenseCrypt runs on real FIDO2/WebAuthn passkeys, not a password behind the scenes.

The live face proves the person

A passkey alone cannot tell who is holding the device. SenseCrypt adds a live-face check, so a sign-in proves the person, not only possession of the device.

Three ways to sign in

One platform, three front doors

The FIDO2 passkey path is the phishing-resistant one. Simple QR and Simple Webcam trade that origin binding for a different fit; pick the door that matches the deployment.

Simple QR

Mobile app

Scan the QR on screen, then complete a quick face scan in the SenseCrypt mobile app. The face is matched on your own device in the app.

FIDO2 passkeys

Roaming authenticator

Phishing-resistant path

Sign in with a real FIDO2/WebAuthn passkey (ES256) held in the SenseCrypt roaming authenticator app. WebAuthn origin binding ties the sign-in to the real site, so a look-alike domain cannot replay it.

Phishing resistance

Phishing-resistant on the passkey path

On the FIDO2/WebAuthn passkey path, the browser and authenticator enforce the origin, so a stolen or replayed credential does not work against a look-alike domain.

WebAuthn origin binding ties each passkey to the real site, so a credential cannot be replayed against a look-alike domain.
There is no shared password, OTP, or push prompt for an attacker to intercept, relay, or fatigue.
Phishing resistance here is a property of the passkey path. The Simple QR flow uses a different ceremony and does not rely on WebAuthn origin binding.

No password to phish

Passwords get phished, replayed, and stuffed. A passkey is a device-bound key pair, so there is no reusable secret to hand over, and the live-face check keeps a stolen device from standing in for its owner.

Aligned with NIST assurance

The passkey path aligns with NIST SP 800-63B AAL3-style assurance (self-assessed, not a certification): a hardware-backed authenticator, paired with verification of the live person.

Your biometrics

Matched on your own device, in the app

In the Simple QR and passkey flows, your face is matched on your own device in the SenseCrypt app. For enterprise deployments, a Simple Webcam option matches on a trusted customer workstation instead, so that match runs on the workstation rather than on your phone (contact sales@seventhsense.ai).

We never store your face image or biometric template, only a sealed, unlinkable, non-reversible token derived from your face that even we cannot reverse, and which contains no PII.

Built on open standards

The specs it is evaluated against

Real FIDO2/WebAuthn passkeys with ES256 signing, issued through a standards-based identity provider that speaks OpenID Connect and OAuth 2.0.

Keep your passkeys. Add the person

Sign in with a real FIDO2 passkey and a live-face check, phishing-resistant on the passkey path.