On this page
What SenseCrypt adds
1Kosmos and SenseCrypt both sign a user in with a biometric, so whether a vendor does face is not the useful question. Ask where the match runs, and what is left on the server once enrollment is done. Those two answers set the ceiling on what a breach can cost you.
SenseCrypt gives the same answer every time, because it has one sign-in method and nothing sits behind it as a fallback. A user enrolls from a photo already on file. After that, signing in means looking at the camera.
The match runs on the phone
Capture and comparison both happen on the user's own device. The server keeps no face image and no face template, so there is no gallery for an attacker to steal or for you to defend in an audit.
The token dies when it is used
Each sign-in spends a single-use face token. A replayed copy is worthless because the token is already spent. The tokenization is patent-pending.
There is no secret to phish
Sign-in uses no password and no shared code. The user has nothing to type into a convincing fake login page and nothing to read out to a caller, which is what makes the flow phishing-resistant rather than merely quick.
It is the identity provider, not an add-on
Your applications integrate with SenseCrypt the same way they integrate with any standards-based IdP. Face login is not a second system you have to keep in step with the first one.
Where each fits
Both products aim at the same outcome, so counting features will not settle this. 1Kosmos reaches wider: it pairs passwordless biometric sign-in with identity verification, and its published architecture stores identity data on a distributed ledger. That suits a program that must establish who a person is before it ever signs them in.
SenseCrypt is narrower on purpose. It owns the sign-in moment, and it does that one way.
1Kosmos reaches across the lifecycle
Verification and authentication inside one platform is worth real money when onboarding has to prove identity from scratch. Ask how the pieces you actually need are packaged in the plan you are quoted.
SenseCrypt is narrow by choice
One method, hardened, with no password path left behind it to undo the result. That is a strength when phishing is your real risk. It is a constraint when it is not.
You can put SenseCrypt behind your current IdP
SenseCrypt federates into an existing identity provider as an external IdP over OIDC or SAML. Your directory, your policy, and your application integrations stay where they are, and face login arrives as a connection rather than a migration.
Roles are emitted, not enforced for you
SenseCrypt puts roles and permissions into the token and your application decides what they allow. SenseCrypt itself enforces a default-closed group gate at sign-in and capability checks on the admin console routes.
What to ask both vendors
No vendor website will settle this for you, and ours is no exception. Put the same four questions to both sides and hold out for specific answers instead of category words. Write the replies next to each other. The differences show up fast.
Our answers are below, in the same words we would give you on a call.
Where does the face match run
On the device or on a server is the largest single difference in what a breach can cost you. SenseCrypt matches on the device, so no face image travels to a server to be compared.
What is on the server after enrollment
Ask for the exact list, not a reassurance. SenseCrypt keeps no face image and no face template. It does persist a sealed face token, and we would rather name that than round it down to nothing.
What is a captured session worth
If someone records the traffic, can they use what they recorded? The SenseCrypt face token is single-use, so a replay arrives dead. Ask the same of any vendor whose flow carries a reusable credential.
What can the recovery path undo
A strong front door helps little if a helpdesk reset opens a weaker one. SenseCrypt has no password to reset. A one-time PIN appears once in the lifecycle, when a user binds a new device, sent by email and also by SMS when a mobile number is on file. It is never part of a normal sign-in.
Standards, controls, and pricing in SenseCrypt
SenseCrypt costs one dollar per user per month, on a 20-seat minimum. That is the list price and not the whole bill, so budget the parts outside it: signing-key custody in KMS adds twenty dollars per key per month, and each tenant or custom domain past the first three costs ten dollars per month. Customer identities bill as monthly active users, not as registered accounts.
The trial runs 30 days and takes no card. Here is what the product carries inside it.
- Protocols: OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 for provisioning, and CIBA
- CIBA: the backchannel push starts a device-bound face ceremony, not a tap to approve
- Controls: multi-tenant isolation and audit logs
- Liveness: iBeta ISO 30107-3 certified at Level 1 and Level 2, which covers presentation attacks at the camera; app attestation and device authenticity checks block virtual-camera and SDK injection
- Face recognition: entered the NIST evaluation in 2021 (then FRVT, later split into FRTE and FATE), maintained through our latest submissions
SenseCrypt and 1Kosmos across common identity dimensions.
| Dimension | SenseCrypt | 1Kosmos |
|---|---|---|
| Primary sign-in method | Passwordless face login | Varies by plan |
| Biometric data on server | None; face matching on-device | Varies by plan |
| Open standards | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, CIBA | Supported |
| Phishing-resistant by design | Yes; no password or shared code to enter | Varies by plan |
| Pricing model | One dollar per user per month (20-seat minimum) | Varies by plan |
Frequently asked questions
How does SenseCrypt sign a user in?
SenseCrypt uses passwordless face login as the primary method. The face match runs on the device. The server keeps no face image and no face template, and each sign-in uses a single-use face token.
Which standards does SenseCrypt support?
SenseCrypt supports OIDC, OAuth 2.0 with PKCE and PAR, SAML 2.0, SCIM 2.0, and CIBA. It also adds RBAC, multi-tenant isolation, and audit logs.
What does SenseCrypt cost?
SenseCrypt costs one dollar per user per month, with a 20-seat minimum. You can start with a 30-day free trial and no card.
Related