Whitepapers

The SenseCrypt whitepaper series

Seven papers for the people who have to evaluate this: security reviewers, identity architects, and the teams who own the recovery flow. Each one is written to be checked against the running system, not believed.

Cover of the SenseCrypt whitepaper From face image to face token 01 · Face Data, Demystified

From face image to face token

A taxonomy for biometric storage: raw image, template, encrypted template, cancellable transform, and face token. What each one yields when the database leaks.

Read the summary
Cover of the SenseCrypt whitepaper Keep your passkeys. Add the person 02 · Beyond Possession

Keep your passkeys. Add the person

Passkeys prove an unlocked device, not the person holding it. How SenseCrypt carries passkey-grade possession inside one ceremony and verifies the live person on top.

Read the summary
Cover of the SenseCrypt whitepaper The case for never building the biometric database 03 · Quantum Readiness

The case for never building the biometric database

Harvest now, decrypt later meets a credential valid for a lifetime. Why the face token uses symmetric and hash primitives only, and where the quantum claim stops.

Read the summary
Cover of the SenseCrypt whitepaper The helpdesk is the new perimeter 04 · Social Engineering

The helpdesk is the new perimeter

Why recovery and support calls became the working attack, what deepfaked voice and video did to verification by recognition, and how a CIBA check closes the flow.

Read the summary
Cover of the SenseCrypt whitepaper Biometrics on day one 05 · Deployment

Biometrics on day one

Authentication programs fail on enrollment, not cryptography. How batch minting from photos on file starts coverage at 100 percent, and how the lifecycle stays anchored to the directory.

Read the summary
Cover of the SenseCrypt whitepaper Built for your security review 06 · Architecture

Built for your security review

An architecture walkthrough for reviewers: what a full database compromise yields, why there is no OP-side SSO session, refresh-family revocation, and anti-enumeration as an invariant.

Read the summary
Cover of the SenseCrypt whitepaper Trust on first use, proof ever after 07 · Bootstrapping Identity

Trust on first use, proof ever after

Deployments with no face images on file bootstrap through SCIM shells or domain-gated self-signup. What gates the first use, and what the first use leaves behind.

Read the summary

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.