Use case

Account recovery on a lost or new device

SenseCrypt has no password, so there is no password to reset. When a user loses a device or moves to a new one, the user re-binds that device with a one-time PIN, then signs in by face again. SenseCrypt emails the PIN, and also sends it by SMS when the user's profile has a mobile number.

On this page
  1. Recovery is where accounts are actually lost
  2. What recovery looks like without a password
  3. What changes
  4. Who it fits
  5. Frequently asked questions

Recovery is where accounts are actually lost

Recovery gets a fraction of the attention that login gets and takes more of the attacks. It runs constantly, because people forget passwords, and it almost always falls back to something weaker than the thing it is rescuing: an emailed link, a code, or a person on a help desk making a judgment call under time pressure.

An attacker who cannot beat your login does not have to. They go around it.

The reset path becomes the login path

If a reset link can set a new password, whoever controls the inbox controls the account. Your login is only ever as strong as your recovery.

Help desk resets are social-engineered

A caller with a plausible story and a few public details is hard for a person to refuse. Every manual override is a policy you cannot test and cannot audit properly.

The volume alone is expensive

Password resets are one of the largest single categories of support ticket, and each one costs staff time whether it is legitimate or not.

What recovery looks like without a password

There is no password, so there is nothing to reset. What a user can genuinely lose is the device, because the device holds the key material that makes their sign-in work.

So recovery is a device re-bind rather than a credential reset, and it is gated on proving control of contact details that were already on the account. Nothing that comes out of the flow is reusable.

A one-time PIN gates the re-bind

SenseCrypt emails a one-time PIN, and also sends it by SMS when the profile has a mobile number. The user enters it once, on the new device, to bind that device to the account.

The CIBA email proof is the alternative gate

A user can instead prove control of the account email through the CIBA flow. The outcome is the same: the new device becomes a bound device.

A face alone does not recover an account

There is no self-service face recovery. A face presented on an unbound device proves nothing, because the device key is half of what makes a sign-in valid.

After the re-bind, sign-in is ordinary again

The user signs in by face on the new device, exactly as before. The server still keeps no face image and no face template.

What changes

Recovery stops being the soft underbelly, because the flow no longer hands out anything an attacker can use twice. The PIN binds one device, once, and is worthless to anyone who is not holding that device.

The support numbers change shape too. The biggest ticket category simply stops existing.

One-time, one device, one use

The PIN authorizes a specific device binding and is spent doing it. It is not a login credential and it cannot be replayed into a session.

No password reset tickets

What is left is genuine device loss and device replacement, which is a much smaller and more predictable number.

Most users finish it alone

The PIN arrives at the address already on file and the user completes the re-bind on the new device. No queue, no call, no agent making a judgment call.

Who it fits

If your recovery volume is large enough to have its own staffing plan, this is the use case that pays for itself first. One dollar per user per month with a 20-seat minimum, and a 30-day trial that takes no card.

  • Customer identity (CIAM) teams.
  • Workforce single sign-on (SSO) teams.
  • B2B SaaS teams with many tenants.

Frequently asked questions

How does account recovery work in SenseCrypt?

SenseCrypt has no password to reset. On a lost or new device, the user re-binds the device with a one-time PIN, then signs in by face again. SenseCrypt stores no face image and no face template on the server.

How does SenseCrypt gate a new-device re-bind?

SenseCrypt emails a one-time PIN, and also sends it by SMS when the user's profile has a mobile number. A user can also prove control of the email through the CIBA flow.

Does account recovery need a help desk?

Not usually. A user re-binds the device alone with the emailed one-time PIN. This cuts help desk tickets and their cost.

Does SenseCrypt verify a user's identity documents?

No. SenseCrypt authenticates the enrolled person. It is not identity proofing or a document check.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.