Compare

SenseCrypt vs 1Kosmos

SenseCrypt and 1Kosmos both offer biometric, passwordless sign-in. This page shows what SenseCrypt does and where each product fits.

On this page
  1. What SenseCrypt adds
  2. Where each fits
  3. What to ask both vendors
  4. Standards, controls, and pricing in SenseCrypt
  5. Frequently asked questions

What SenseCrypt adds

1Kosmos and SenseCrypt both sign a user in with a biometric, so whether a vendor does face is not the useful question. Ask where the match runs, and what is left on the server once enrollment is done. Those two answers set the ceiling on what a breach can cost you.

SenseCrypt gives the same answer every time, because it has one sign-in method and nothing sits behind it as a fallback. A user enrolls from a photo already on file. After that, signing in means looking at the camera.

The match runs on the phone

Capture and comparison both happen on the user's own device. The server keeps no face image and no face template, so there is no gallery for an attacker to steal or for you to defend in an audit.

The token dies when it is used

Each sign-in spends a single-use face token. A replayed copy is worthless because the token is already spent. The tokenization is patent-pending.

There is no secret to phish

Sign-in uses no password and no shared code. The user has nothing to type into a convincing fake login page and nothing to read out to a caller, which is what makes the flow phishing-resistant rather than merely quick.

It is the identity provider, not an add-on

Your applications integrate with SenseCrypt the same way they integrate with any standards-based IdP. Face login is not a second system you have to keep in step with the first one.

Where each fits

Both products aim at the same outcome, so counting features will not settle this. 1Kosmos reaches wider: it pairs passwordless biometric sign-in with identity verification, and its published architecture stores identity data on a distributed ledger. That suits a program that must establish who a person is before it ever signs them in.

SenseCrypt is narrower on purpose. It owns the sign-in moment, and it does that one way.

1Kosmos reaches across the lifecycle

Verification and authentication inside one platform is worth real money when onboarding has to prove identity from scratch. Ask how the pieces you actually need are packaged in the plan you are quoted.

SenseCrypt is narrow by choice

One method, hardened, with no password path left behind it to undo the result. That is a strength when phishing is your real risk. It is a constraint when it is not.

You can put SenseCrypt behind your current IdP

SenseCrypt federates into an existing identity provider as an external IdP over OIDC or SAML. Your directory, your policy, and your application integrations stay where they are, and face login arrives as a connection rather than a migration.

Roles are emitted, not enforced for you

SenseCrypt puts roles and permissions into the token and your application decides what they allow. SenseCrypt itself enforces a default-closed group gate at sign-in and capability checks on the admin console routes.

What to ask both vendors

No vendor website will settle this for you, and ours is no exception. Put the same four questions to both sides and hold out for specific answers instead of category words. Write the replies next to each other. The differences show up fast.

Our answers are below, in the same words we would give you on a call.

Where does the face match run

On the device or on a server is the largest single difference in what a breach can cost you. SenseCrypt matches on the device, so no face image travels to a server to be compared.

What is on the server after enrollment

Ask for the exact list, not a reassurance. SenseCrypt keeps no face image and no face template. It does persist a sealed face token, and we would rather name that than round it down to nothing.

What is a captured session worth

If someone records the traffic, can they use what they recorded? The SenseCrypt face token is single-use, so a replay arrives dead. Ask the same of any vendor whose flow carries a reusable credential.

What can the recovery path undo

A strong front door helps little if a helpdesk reset opens a weaker one. SenseCrypt has no password to reset. A one-time PIN appears once in the lifecycle, when a user binds a new device, sent by email and also by SMS when a mobile number is on file. It is never part of a normal sign-in.

Standards, controls, and pricing in SenseCrypt

SenseCrypt costs one dollar per user per month, on a 20-seat minimum. That is the list price and not the whole bill, so budget the parts outside it: signing-key custody in KMS adds twenty dollars per key per month, and each tenant or custom domain past the first three costs ten dollars per month. Customer identities bill as monthly active users, not as registered accounts.

The trial runs 30 days and takes no card. Here is what the product carries inside it.

  • Protocols: OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 for provisioning, and CIBA
  • CIBA: the backchannel push starts a device-bound face ceremony, not a tap to approve
  • Controls: multi-tenant isolation and audit logs
  • Liveness: iBeta ISO 30107-3 certified at Level 1 and Level 2, which covers presentation attacks at the camera; app attestation and device authenticity checks block virtual-camera and SDK injection
  • Face recognition: entered the NIST evaluation in 2021 (then FRVT, later split into FRTE and FATE), maintained through our latest submissions

SenseCrypt and 1Kosmos across common identity dimensions.

DimensionSenseCrypt1Kosmos
Primary sign-in methodPasswordless face loginVaries by plan
Biometric data on serverNone; face matching on-deviceVaries by plan
Open standardsOIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, CIBASupported
Phishing-resistant by designYes; no password or shared code to enterVaries by plan
Pricing modelOne dollar per user per month (20-seat minimum)Varies by plan

Frequently asked questions

How does SenseCrypt sign a user in?

SenseCrypt uses passwordless face login as the primary method. The face match runs on the device. The server keeps no face image and no face template, and each sign-in uses a single-use face token.

Which standards does SenseCrypt support?

SenseCrypt supports OIDC, OAuth 2.0 with PKCE and PAR, SAML 2.0, SCIM 2.0, and CIBA. It also adds RBAC, multi-tenant isolation, and audit logs.

What does SenseCrypt cost?

SenseCrypt costs one dollar per user per month, with a 20-seat minimum. You can start with a 30-day free trial and no card.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.