On this page
What SenseCrypt adds
Both products put a face at the front of the sign-in, so that fact on its own settles nothing. What separates them is the shape of the system around the face: where the comparison runs, what stays on a server after enrollment, and whether the biometric is the whole front door or one method among several.
SenseCrypt is the identity provider itself. Your applications collect tokens from it over the protocols they already speak, and the face ceremony is how a user proves they are present.
The match runs on the user's phone
Capture and comparison both stay on the device. The server holds no face image and no face template, so there is no gallery for an attacker to take and none for you to account for in an audit.
Every sign-in spends a face token
The token is single-use. Record the traffic, replay it, and it fails. The tokenization is patent-pending.
The user has nothing to type
No password, and no code read off a screen or out of a text message. A convincing fake login page has nothing to collect from the user. That is the entire basis of the phishing-resistance claim, and it is why we are willing to make it.
One product, not a biometric wired to an IdP
OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0, and CIBA come from the same service that runs the face ceremony. There is no second vendor to keep in step.
Where each fits
Keyless built its name as an independent vendor of privacy-preserving biometric authentication. Since January 2026 it is part of Ping Identity, so what you are evaluating is a biometric line inside a large enterprise identity platform rather than a company you contract with on its own. That is not a criticism of either party. It does change who answers your questions.
SenseCrypt is smaller and deliberately narrower. One sign-in method, run end to end, with the identity protocols in the same box.
Keyless is now Ping's biometric line
The acquisition closed in January 2026. If face biometrics is why you are in the conversation, ask which Ping plan carries it and how it is packaged, because that answer now comes from Ping.
SenseCrypt is narrow on purpose
One method, hardened, with no password path left behind it to undo the result. That is a strength when phishing is your live risk and a constraint when it is not.
Federate instead of migrating
SenseCrypt connects to your current identity provider as an external IdP over OIDC or SAML. Your directory, your policy, and your application integrations stay exactly where they are.
Roles are emitted, your app enforces them
SenseCrypt writes roles and permissions into the token and your application decides what they allow. SenseCrypt itself runs a default-closed group gate at sign-in and capability checks on the admin console routes.
What the Ping acquisition changes for your shortlist
If your evaluation of Keyless started before January 2026, part of it is out of date. We will not guess at Ping's roadmap or packaging, and you should distrust any vendor page that does. Put the questions to Ping directly and hold out for specific answers.
These are the four we would take into that call. Our own answers are underneath each one, so you can hold us to the same standard.
Which plan carries the biometric line
Packaging inside a large platform is rarely the packaging the standalone product had. Get the module, the tier, and the price in writing before you build a business case on it.
Where does the face match run
On the device, or in a vendor cloud. That one answer sets the blast radius of a breach. SenseCrypt matches on the device, so no face image travels anywhere to be compared.
What is left on the server after enrollment
Ask for a list, not a reassurance. SenseCrypt keeps no face image and no face template. A sealed face token is persisted, and we would rather name that than round it down to nothing.
How does a user get back in
A strong front door counts for little if the recovery path is softer. SenseCrypt has no password to reset. A one-time PIN appears once in the lifecycle, when a user binds a new device, sent by email and also by SMS when a mobile number is on file. It is never part of a normal sign-in.
Standards, controls, and pricing in SenseCrypt
List price is one dollar per user per month on a 20-seat minimum. Read that as the starting line and not the bill: signing-key custody in KMS costs twenty dollars per key per month, and each tenant or custom domain past the first three adds ten dollars per month. Customer identity deployments bill on monthly active users, not on every account ever registered.
The trial runs 30 days and asks for no card. What follows is what the product carries inside it.
- Protocols: OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 for provisioning, and CIBA
- CIBA: the backchannel push starts a device-bound face ceremony on the phone, not a tap to approve
- Controls: roles and permissions in the token, multi-tenant isolation, and audit logs
- Liveness: iBeta ISO 30107-3 certified at Level 1 and Level 2, which covers presentation attacks at the camera; app attestation and device authenticity checks block virtual-camera and SDK injection
- Face recognition: entered the NIST evaluation in 2021 (then FRVT, later split into FRTE and FATE), maintained through our latest submissions
SenseCrypt and Keyless across common identity dimensions.
| Dimension | SenseCrypt | Keyless |
|---|---|---|
| Primary sign-in method | Passwordless face login | Varies by plan |
| Biometric data on server | None; face matching on-device | Varies by plan |
| Open standards | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, CIBA | Supported |
| Phishing-resistant by design | Yes; no password or shared code to enter | Varies by plan |
| Pricing model | One dollar per user per month (20-seat minimum) | Varies by plan |
Frequently asked questions
How is SenseCrypt different from Keyless?
Both use face biometrics. Keyless is now Ping Identity's biometric line, after the acquisition closed in January 2026. SenseCrypt is a full identity provider. It adds OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, and CIBA, plus RBAC, multi-tenant isolation, and audit logs.
Where does SenseCrypt store my biometric data?
SenseCrypt stores no face image and no face template. It matches the face on the device and uses a single-use face token.
How much does SenseCrypt cost?
SenseCrypt costs one dollar per user per month, with a 20-seat minimum. There is a 30-day free trial, and you do not need a card.
Related