On this page
What SenseCrypt adds
Daon sells biometrics into an identity stack that a customer already runs. SenseCrypt is the identity stack, and the face is how a user gets in. Hold on to that difference while you read the rest of this page, because the feature lists overlap and the shapes do not.
One service runs the face ceremony and issues the token your application reads. That removes an integration seam. It also removes a choice, and that is the trade you are being asked to make.
The match runs on the phone
Capture and comparison both stay on the user's handset. The server keeps no face image and no face template, so there is no gallery to breach and none to inventory when an auditor asks what biometric data you hold.
Each face token is spent once
A sign-in consumes one single-use face token. Record that traffic and replay it, and the second attempt is refused. The tokenization is patent-pending.
Nothing for a fake login page to collect
Sign-in asks for no password and no code read off a screen. A one-time PIN appears once in a user's life with the product, when they bind a new device, sent by email and also by SMS when a mobile number is on file.
The protocols ship with the face
OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0, and CIBA come from the same service that runs the ceremony. You are not keeping a biometric product and an identity provider in step with each other.
Where each fits
Daon has been in this market since 1999, and the scope shows it. Its IdentityX platform covers identity proofing and onboarding as well as biometric authentication, across more than one modality, sold into banking, travel and other sectors that audit their vendors hard. Breadth like that gets bought for a reason.
Read what follows as a description of what we gave up to build a narrow product, not as a complaint about a wide one.
Daon covers more of the identity lifecycle
Proofing a new customer against a document and authenticating a returning one are separate jobs. A vendor that does both can quote you for both, and a long record in regulated industries is worth something to a procurement team that has to defend the choice.
SenseCrypt is one method, hardened
Face only, with no password path parked behind it. Having nothing softer to fall back to is what makes the front door hard. It is also what makes it inflexible, and both of those are true at the same time.
You can federate instead of migrating
SenseCrypt attaches to the identity provider you run today as an external IdP over OIDC or SAML. Your directory, your policies and your application integrations stay put, so you can route one application or one pilot group through face login and leave everyone else alone.
Roles are emitted, your app enforces them
SenseCrypt writes roles and permissions into the token and your application decides what they permit. Inside SenseCrypt, a default-closed group gate runs at sign-in and capability checks guard the admin console routes.
How to decide between them
A comparison grid lets two products tick the same row for completely different reasons, and ours is no exception. Four questions get you further than the grid will.
Ask them of us as well. Our answers sit under each one, so you can hold what a salesperson tells you against what is written here.
Is the job the onboarding or the sign-in
If you have to prove who a new customer is before an account exists, that is identity proofing, and it is a category of its own. SenseCrypt does the returning-user half. Count the other half in your comparison rather than assuming it comes along.
What stays on the server after enrollment
Ask for the list, not the reassurance. SenseCrypt keeps no face image and no face template. A sealed face token is persisted, and we would rather name it than round it down to nothing.
What does recovery look like
The reset path is usually softer than the front door it guards. SenseCrypt has no password to reset. Binding a new device uses a one-time PIN sent by email, and by SMS when a mobile number is on file, and that PIN never appears in a normal sign-in.
How many modalities do you actually need
One method costs less to operate and leaves fewer soft edges. Several methods reach more people. Name the user groups that cannot put a face in front of a camera before you decide that flexibility is optional.
Standards, controls, and pricing in SenseCrypt
List price is one dollar per user per month on a 20-seat minimum, and that is the starting line rather than the invoice. Signing keys held under KMS custody add twenty dollars per key per month, and each tenant or custom domain past the three included costs ten dollars per month. Customer identity deployments meter monthly active users, so an account that does not sign in during a month does not bill for it.
The trial runs 30 days and asks for no card. Below is what the product carries as it ships.
- Protocols: OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 for provisioning, and CIBA
- CIBA: the backchannel push starts a device-bound face ceremony on the phone, not a tap to approve
- Controls: roles and permissions in the token, multi-tenant isolation, and audit logs
- Liveness: iBeta ISO 30107-3 certified at Level 1 and Level 2, which covers presentation attacks at the camera; app attestation and device authenticity checks block virtual-camera and SDK injection
- Face recognition: entered the NIST evaluation in 2021 (then FRVT, later split into FRTE and FATE), maintained through our latest submissions
SenseCrypt and Daon across common identity dimensions.
| Dimension | SenseCrypt | Daon |
|---|---|---|
| Primary sign-in method | Passwordless face login | Varies by plan |
| Biometric data on server | None; face matching on-device | Varies by plan |
| Open standards | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, CIBA | Supported |
| Phishing-resistant by design | Yes; no password or shared code to enter | Varies by plan |
| Pricing model | One dollar per user per month (20-seat minimum) | Varies by plan |
Frequently asked questions
How is SenseCrypt different from Daon?
SenseCrypt is a full identity provider with passwordless face login. It matches the face on the device and stores no face image and no face template. Daon is an established provider of biometric and passwordless authentication; review its public information for its own details.
Does SenseCrypt store my face on a server?
No. SenseCrypt matches the face on the device. It stores no face image and no face template, and uses a single-use face token.
Which open standards does SenseCrypt support?
SenseCrypt supports OIDC and OAuth 2.0 (with PKCE and PAR), SAML 2.0, SCIM 2.0, and CIBA. It also adds RBAC, multi-tenant isolation, and audit logs.
Related