Use case

Deepfake and spoof protection

SenseCrypt protects a face login from deepfakes and spoof attacks. A deepfake or a photo on a screen is a presentation attack. SenseCrypt uses on-device liveness detection to reject a fake face. App attestation and device authenticity checks block injected video.

On this page
  1. A match is not proof of a person
  2. How SenseCrypt blocks a fake face
  3. Certified liveness detection
  4. Injection attacks fail at the device check
  5. What SenseCrypt confirms, and what it does not
  6. The outcome, and who it fits
  7. Frequently asked questions

A match is not proof of a person

Face recognition answers one question: does this face match the enrolled one. It does not answer whether a live human is standing at the camera, and an attacker who has your user's face has plenty of ways to supply the first without the second.

Faces are public. They are on the badge, on the company page, on every social feed. Treat the recognition score as the easy half of the problem.

  • A printed photo of a face
  • A video of a face on a screen
  • A paper mask or a 3D mask
  • A deepfake face on a display

How SenseCrypt blocks a fake face

Liveness detection runs beside the match, on the device, and decides whether what the camera sees behaves like skin in real light. Capture is 2D RGB, so there is no depth sensor to depend on and no special hardware to buy for the device to be usable.

That constraint matters. It means the check has to earn its result from texture and light rather than from a sensor most of your users would not have.

The check runs where the camera is

Liveness and matching both run on the user's own device. The server never receives the frames, and it keeps no face image and no face template.

2D RGB, no depth sensor

The check works from an ordinary camera, which is why it runs on phones and laptops your users already own rather than on a short list of certified handsets.

A screen is a screen

A deepfake has to be shown to the camera somehow, and a display reflects and renders differently from a face. That is the property the check reads, so a synthetic face on a screen fails for the same reason a photo does.

Only a spent token leaves the device

The result of a passing ceremony is a patent-pending single-use face token. There is nothing durable in flight for an attacker to collect and reuse.

Certified liveness detection

Every vendor says its liveness detection works. The only version of that claim worth anything is one an accredited lab has tried to break under a published method. ISO/IEC 30107-3 is that method: it specifies how presentation attack detection is tested and reported, while the taxonomy of attack types lives in ISO/IEC 30107-1.

SenseCrypt liveness holds iBeta certification against 30107-3 at Level 1 and Level 2. Those levels are iBeta program tiers, not levels defined by the standard, and what separates them is the effort and money an attacker is assumed to spend.

Read the scope of that certification carefully. It covers a presentation attack at the camera, such as a screen replay, a printed photo, or a mask. It does not cover an injection attack, where a tool feeds prepared frames past the camera through a virtual camera or an SDK bypass. An injection attack is a separate class, and SenseCrypt blocks it with separate controls.

Level 1 covers low-cost artifacts

Printed photos, a face played on a phone screen, a paper mask. Cheap to produce, and the attacks that almost every real user will ever meet.

Level 2 covers made-to-measure artifacts

Silicone and 3D-printed masks and high-quality replicas built for a specific target. Slower and more expensive to make, and still rejected.

The result is pass or fail

A lab reports a clear outcome against a defined attack set, which is something you can check for yourself rather than take on trust.

Injection attacks fail at the device check

The injection path stops at the device check, before face capture starts. Sign-in runs only inside the SenseCrypt app on an enrolled phone, not in a browser tab with a webcam. A browser cannot prove what its camera saw, because anyone can compile one from source and make it report whatever frames they choose.

App attestation and device authenticity checks verify the app and the device at every sign-in. A tool that fakes the camera must first defeat those checks.

  • App attestation confirms the genuine SenseCrypt app.
  • Hardware-backed device keys confirm the enrolled device.
  • The key can sign only while the device is unlocked.
  • A virtual camera, an emulator, or a modified app fails these checks.
  • A jailbreak cannot unlock the device to use the key for signing.

What SenseCrypt confirms, and what it does not

Be precise about the job this does, because the words in this market are used loosely. SenseCrypt answers one question: is the live person at this camera the person who enrolled on this account. It does not answer who that person is in the world.

It authenticates, it does not identify

The comparison is one to one against the enrolled user. There is no search across a population and no claim about identity beyond the account.

Recognition is NIST-evaluated

Face recognition entered the NIST evaluation in 2021, then FRVT, later split into FRTE and FATE, and is maintained through our latest submissions. Evaluated, not certified.

Not identity proofing, KYC, or age checking

There is no document check, no data-source lookup, and no age estimate. If you have to prove who a person is before they get an account, that step belongs upstream of enrollment.

The outcome, and who it fits

Tested liveness is what lets you put a face login in front of something that matters. An attacker holding your user's photo, a recorded video, or a generated face gets no further than the camera, and the user still signs in by looking at it.

One dollar per user per month with a 20-seat minimum, and a 30-day trial that takes no card.

  • Customer identity (CIAM) with a high-trust sign-in
  • Workforce single sign-on (SSO) for staff
  • B2B SaaS SSO for business customers

Frequently asked questions

Does SenseCrypt detect deepfakes?

A deepfake on a screen is a presentation attack. SenseCrypt uses liveness detection to reject a fake face at the camera. Its liveness detection holds iBeta ISO 30107-3 certification.

What certification does the liveness detection hold?

The SenseCrypt liveness detection holds iBeta ISO 30107-3 certification. It covers Level 1 and Level 2 presentation-attack detection.

Does the certification cover an injection attack?

No. The iBeta ISO 30107-3 certification covers a presentation attack at the camera, such as a screen or a printed photo. SenseCrypt blocks an injection attack separately: app attestation and hardware-backed device keys verify the app and the enrolled device at every sign-in, so a virtual camera, an emulator, or a modified app fails before the face check runs.

Is this age verification or identity proofing?

No. SenseCrypt authenticates the enrolled person by face. It is not identity proofing, KYC, or age verification.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.