Feature

Face Login: passwordless biometric sign-in

Face login is passwordless biometric sign-in from SenseCrypt. A user signs in by face, not by password. The sign-in binds to the device, so it is phishing-resistant.

On this page
  1. What face login is
  2. How face login works
  3. What changes when the password goes away
  4. Certifications and evaluation
  5. How to turn it on
  6. Frequently asked questions

What face login is

Face login replaces the password with two things a phishing site cannot obtain: a live face, and a device the user bound in advance. You enroll a person from a photo you already hold. From then on they sign in by looking at their own phone.

Be clear about what that proves. Face login authenticates the enrolled person. It is not identity proofing, KYC, or age verification. Whether the enrolled person is who they claim to be was decided when you accepted their photo.

Nothing for the user to type

There is no password and no shared code at sign-in. A fake login page can copy every pixel of ours and still collect nothing, because the user holds no secret to give it.

The enrolled device is half the proof

A face on its own signs nobody in. The request is signed by the device the user bound, so a photo pulled off a social profile has nowhere to be presented.

One enrollment, every connected app

The same enrollment carries into each application you connect over OIDC or SAML. Users learn one sign-in motion, and you write the support article once.

How face login works

Enrollment starts from a photo on file, so most users never sit through a capture session. That photo becomes a face token, and the phone keeps what it needs to compare a live capture against it.

At sign-in the camera capture and the comparison both happen on the handset. What travels to the server is a single-use token and a device-bound signature. No face image goes anywhere.

Matching runs on the device

Your servers never receive a face to compare. There is no gallery on them for an attacker to take, and none for you to inventory when a regulator asks.

Each sign-in spends one token

The face token is single-use. Record the traffic, replay it, and the second attempt is rejected. The tokenization is patent-pending.

What the server does keep

No face image and no face template. A sealed face token is persisted, and we would rather name that than round it down to nothing.

What changes when the password goes away

Two effects are worth planning around. Credential phishing stops working against your sign-in, because there is no credential to hand over. And the reset queue drains, because there is nothing left to forget.

Neither is free. You are asking every user to carry an enrolled phone with a working camera, and you are removing the fallback they are used to. Settle that before the rollout, not during it.

Phishing has nothing to catch

Credential phishing works by persuading a person to type a secret into the wrong site. Take the secret away and the attack has no payload left to steal.

The reset queue goes away

Password resets are one of the larger hidden costs of password authentication. This removes the cause rather than automating the cure.

Recovery runs through a bound device

There is no self-service face recovery flow. A user on a lost or new device re-binds with a one-time PIN, sent by email and also by SMS when a mobile number is on file, or proves possession of their email through the CIBA flow.

Certifications and evaluation

Two claims get blurred together in this market, so we keep them apart. Our liveness detection is certified. Our face recognition is evaluated, and we will not call it certified, because no such certification exists to hold.

Read the scope as closely as the level.

  • Liveness: iBeta ISO 30107-3 certified at Level 1 and Level 2
  • Face recognition: Seventh Sense entered the NIST evaluation in 2021 (then FRVT, later split into FRTE and FATE) and has maintained it through our latest submissions
  • Level 1 and Level 2 are iBeta program tiers, not ISO grades. ISO/IEC 30107-1 holds the taxonomy, and 30107-3 specifies how presentation attack detection is tested and reported
  • Capture is 2D RGB from an ordinary front camera. There is no depth sensor

How to turn it on

Start on the 30-day trial. It takes no card, and you can enroll real users from photos you already hold, so the pilot tells you something a sandbox would not.

Price the rollout on the whole line, not the headline rate.

One dollar per user per month, list price

A 20-seat minimum applies, so the smallest bill is twenty dollars a month. Customer identity deployments bill monthly active users rather than every account ever registered.

The parts outside the per-user rate

Signing-key custody in KMS costs twenty dollars per key per month. Each tenant and each custom domain past the first three adds ten dollars per month.

Enroll from the photos you have

A badge photo or an HR record photo is usually enough. The rollout does not have to begin with a capture campaign.

Frequently asked questions

Does SenseCrypt store my face?

No. Face matching runs on-device. SenseCrypt stores no face image and no face template. A face becomes a single-use face token.

Is face login phishing-resistant?

Yes. At sign-in, you enter no password and no shared code. So a phishing page has nothing to capture or replay. The proof is a live face and a device-bound signature.

Is face login identity proofing or KYC?

No. Face login authenticates the enrolled person. It is not identity proofing, KYC, or age verification.

What certification does the liveness detection hold?

The liveness detection holds iBeta ISO 30107-3 certification, Level 1 and Level 2.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.