On this page
What SenseCrypt adds
FaceTec sells the face. You license the technology, embed it in an application you own, and then build everything around it: the session, the token your services trust, the directory, the protocol your apps speak. SenseCrypt ships that surrounding work as the product, and the face is simply how a user opens it.
One service runs the capture and issues the OIDC token your application reads, so there is no seam between them for your team to own. That buys you an integration you no longer have to write. It also takes away a choice, and that trade decides most of these evaluations.
Matching happens on the handset
Capture and comparison both stay on the user's phone. No face image and no face template reach the server, so there is no gallery to defend and nothing to describe when an auditor asks what biometric data you hold.
One face token, spent once
A sign-in consumes a single-use face token. Record that traffic and send it again and the replay is refused. The tokenization is patent-pending.
Nothing a fake sign-in page can harvest
There is no password and no code to type when a user signs in. A one-time PIN appears only to bind a new device, sent by email and also by SMS when a mobile number is on file.
The protocol surface comes with it
OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 and CIBA belong to the same service that runs the ceremony. Your application talks to an identity provider instead of to a camera SDK plus whatever you wrote around it.
Where each fits
FaceTec's business is one hard problem done well: 3D face liveness and matching, licensed to other vendors rather than sold as a directory or a sign-in service. The company also runs a public spoof bounty, which is a more confident way to talk about liveness than most of this market manages. None of that competes with what SenseCrypt sells.
We sell the sign-in itself. Narrower in one dimension, much wider in another. Read the points below as a description of the shape we chose, not as a shortcoming in the shape FaceTec chose.
A component leaves your stack alone
If you already run a directory, a session layer and a token service, dropping in a liveness SDK changes one part and nothing else. Buying an identity provider moves where sign-in lives, which is a larger decision than a procurement line suggests.
SenseCrypt is one method with nothing softer behind it
Face is the only way in, with no password path parked as a fallback. Having nothing weaker to fall back on is what makes the front door hard, and it is also what makes it rigid.
Federation avoids the migration
SenseCrypt attaches to the identity provider you run today as an external IdP over OIDC or SAML. Your directory, policies and app integrations stay put, so you can route one application or one pilot group through face login and leave everybody else where they are.
Roles are emitted; your app enforces them
SenseCrypt writes roles and permissions into the token and your application decides what they permit. Inside SenseCrypt, a default-closed group gate runs at sign-in and capability checks guard the admin console routes.
Questions worth asking before you choose
The table further down lets two very different products tick the same row for reasons that have nothing in common. Four questions separate them faster than any grid will.
Put them to us as well. Our answers sit under each one, so you can hold what a salesperson tells you against what is written here.
Are you buying a component or a sign-in
An SDK is a part; an identity provider is a system. Price the engineering that has to wrap the part, because that work is real and it never shows up on the SDK quote.
What is left on the server after enrollment
Ask for the list, not the reassurance. SenseCrypt keeps no face image and no face template. A sealed face token is persisted, and we name it, because saying 'nothing' would be the wrong claim.
What does the liveness certificate actually cover
Ours is iBeta ISO 30107-3 at Level 1 and Level 2, which tests presentation attacks held up at the camera. It says nothing about a virtual camera or an injected video stream. Ask any vendor the same question about theirs.
How does a user get back in on a new phone
Recovery is where passwordless deployments usually go soft. SenseCrypt has no password to reset. Binding a new device uses a one-time PIN sent by email, and by SMS when a mobile number is on file, and that PIN never appears in a normal sign-in.
Standards, controls, and pricing in SenseCrypt
List price is one dollar per user per month on a 20-seat minimum, and that is the starting line rather than the invoice. A signing key held under KMS custody adds twenty dollars per key per month, and each tenant or custom domain past the three included costs ten dollars per month. Customer identity deployments meter monthly active users, so an account that never signs in during a month does not bill for that month.
The trial runs 30 days and asks for no card. Below is what the product carries as it ships.
- Protocols: OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 for provisioning, and CIBA
- CIBA: the backchannel push starts a device-bound face ceremony on the phone, not a tap to approve
- Controls: roles and permissions in the token, multi-tenant isolation, and audit logs
- Liveness: iBeta ISO 30107-3 certified at Level 1 and Level 2, covering presentation attacks at the camera; app attestation and device authenticity checks block virtual-camera and SDK injection
- Face recognition: entered the NIST evaluation in 2021 (then FRVT, later split into FRTE and FATE), maintained through our latest submissions
SenseCrypt and FaceTec across common identity dimensions.
| Dimension | SenseCrypt | FaceTec |
|---|---|---|
| Primary sign-in method | Passwordless face login | Varies by plan |
| Biometric data on server | None; face matching on-device | Varies by plan |
| Open standards | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, CIBA | Supported |
| Phishing-resistant by design | Yes; no password or shared code to enter | Varies by plan |
| Pricing model | One dollar per user per month (20-seat minimum) | Varies by plan |
Frequently asked questions
Is SenseCrypt an identity provider?
Yes. SenseCrypt is a full identity provider. It supports OIDC, OAuth 2.0 (with PKCE and PAR), SAML 2.0, SCIM 2.0, and CIBA. It adds RBAC, multi-tenant isolation, and audit logs.
Does SenseCrypt store a face image or template on the server?
No. SenseCrypt matches the face on the device. It stores no face image and no face template. It uses a single-use face token, and the tokenization is patent-pending.
How much does SenseCrypt cost?
SenseCrypt costs one dollar per user per month, with a 20-seat minimum. A 30-day free trial is available, and it needs no card.
Related