Compare

SenseCrypt vs Veridium

SenseCrypt and Veridium both provide biometric authentication. This page shows what SenseCrypt gives you and where each product fits.

On this page
  1. What SenseCrypt adds
  2. Where each fits
  3. Four questions to take into both calls
  4. Standards, controls, and pricing in SenseCrypt
  5. Frequently asked questions

What SenseCrypt adds

Both products authenticate people with biometrics, and that is where the resemblance ends. Veridium sells biometric authentication into organizations that already run an identity stack, and it offers more than one biometric method. SenseCrypt is the identity stack: one method, and the identity provider underneath it.

So the face ceremony and the token your application receives come out of the same service. That removes an integration seam. It also removes a choice, which is the trade you are being asked to make.

The match runs on the user's phone

The camera and the comparison both stay on the handset. The server keeps no face image and no face template, so there is no gallery for an attacker to take and none for you to inventory when a regulator asks.

The face token is spent once

Each sign-in consumes a single-use face token. Record the traffic, replay it, and the second attempt is rejected. The tokenization is patent-pending.

Nothing for a fake login page to collect

There is no password, and no code to read off a screen or out of a text message. Take the shared secret out of the flow and a phishing kit has nothing to harvest. That is the whole basis of the phishing-resistance claim.

The protocols come from the same product

OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0, and CIBA are served by the service that runs the face ceremony. You are not keeping a biometric product and an identity provider in step with each other.

Where each fits

Veridium is an independent vendor of multi-modal biometric authentication for the enterprise, best known for capturing fingerprints with an ordinary phone camera. Modality choice earns its keep when your workforce is not uniform. Gloves on a plant floor, a camera taped over on a trading desk, a job that never puts a face in front of a lens: if that is your population, the ability to pick a different biometric per group is worth more than anything else on this page.

SenseCrypt does not give you that choice, and we would rather say so on the way in than on the way out.

Veridium is still independent

Keyless went to Ping Identity in a deal that closed in January 2026. Veridium did not go anywhere. If you would rather contract with the company that builds the product and keep a direct line to its roadmap, that counts in its favour.

One method carries different risk than several

A multi-modal product keeps several capture paths, several enrollment flows, and several failure modes healthy at once. A single-method product keeps one of each, hardened, with nothing softer parked behind it. Neither shape wins in the abstract. They fail differently and they cost different amounts to operate.

Federate instead of migrating

You do not have to replace anything to try this. SenseCrypt attaches to your current identity provider as an external IdP over OIDC or SAML, so the directory, the policy, and every application integration stay where they are.

Roles are emitted, your app enforces them

SenseCrypt writes roles and permissions into the token, and your application decides what they permit. Inside SenseCrypt, a default-closed group gate runs at sign-in and capability checks guard the admin console routes.

Four questions to take into both calls

A feature grid flattens everything into ticks, ours included, and two products can tick the same row for completely different reasons. Four questions get you further than any grid will.

Ask them of us as well. Our answers sit under each one, so you can hold whatever we say on a call against what is written here.

Where does the biometric match run

On the device, or in a vendor cloud. Nothing else moves the blast radius of a breach as much. SenseCrypt compares on the handset, so no face image travels anywhere to be matched.

What survives on the server after enrollment

Ask for the list, not the reassurance. SenseCrypt keeps no face image and no face template. A sealed face token is persisted, and we would rather name it than round it down to nothing.

Which users does the method leave out

Every biometric excludes somebody. Face login needs a phone with a camera and a user willing to enroll it. Ask each vendor to name the group it cannot serve, and be suspicious of any answer that is nobody.

How does a locked-out user get back in

Recovery is usually the softest part of a hard front door. SenseCrypt has no password to reset. A one-time PIN appears once in a user's lifecycle, when they bind a new device, sent by email and also by SMS when a mobile number is on file. It is never part of a normal sign-in.

Standards, controls, and pricing in SenseCrypt

List price is one dollar per user per month on a 20-seat minimum. Read that as the starting line and not the invoice: signing keys under KMS custody cost twenty dollars per key per month, and each tenant or custom domain past the first three adds ten dollars per month. Customer identity deployments meter monthly active users, not every account ever registered.

The trial runs 30 days and asks for no card. Below is what the product carries as it ships.

  • Protocols: OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 for provisioning, and CIBA
  • CIBA: the backchannel push starts a device-bound face ceremony on the phone, not a tap to approve
  • Controls: roles and permissions in the token, multi-tenant isolation, and audit logs
  • Liveness: iBeta ISO 30107-3 certified at Level 1 and Level 2, which covers presentation attacks at the camera; app attestation and device authenticity checks block virtual-camera and SDK injection
  • Face recognition: entered the NIST evaluation in 2021 (then FRVT, later split into FRTE and FATE), maintained through our latest submissions

SenseCrypt and Veridium across common identity dimensions.

DimensionSenseCryptVeridium
Primary sign-in methodPasswordless face loginVaries by plan
Biometric data on serverNone; face matching on-deviceVaries by plan
Open standardsOIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, CIBASupported
Phishing-resistant by designYes; no password or shared code to enterVaries by plan
Pricing modelOne dollar per user per month (20-seat minimum)Varies by plan

Frequently asked questions

How is SenseCrypt different from Veridium?

SenseCrypt is a full identity provider with passwordless face login as the primary sign-in method. It supports OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, and CIBA. Veridium is an established provider of biometric and passwordless authentication.

Does SenseCrypt store biometric data?

No. SenseCrypt matches the face on the device. It stores no face image and no face template, and it uses a single-use face token.

What does SenseCrypt cost?

SenseCrypt costs one dollar per user per month, with a 20-seat minimum. There is a 30-day free trial, and no card is needed.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.