Face Data, Demystified Paper 01 of 07

From face image to face token

Biometric representations sit on a spectrum of privacy risk, from the raw image at one end to protected constructions that retain nothing about the face at the other. This paper gives evaluators the vocabulary to place any vendor on that spectrum, and explains why a face token sits off the spectrum entirely.

PDF, 6 pages Free, no card

Unlinkable. Irreversible. Revocable. Renewable. Properties of the mathematics, not promises in a policy.

Why the vocabulary matters

Every face verification product answers one question: is this the same person. What separates them is what is left in the database afterward, and that is exactly where vendor language goes soft. Raw images, templates, encrypted templates, and genuinely protected constructions carry sharply different risk, yet the words for them get used almost interchangeably in a data sheet.

The cost of that softness lands on you. Without the vocabulary you are comparing adjectives, and the vendor with the better copywriter wins. With it, one questionnaire places any vendor on a map, and the answer stops depending on which word the vendor preferred.

What the paper establishes

The paper walks the spectrum from raw capture to face token in one pass, then hands you the single question that does most of the work in an assessment. Ask it the moment a vendor says protected, and the conversation either gets specific or it ends.

It is a primer, not a product tour. A taxonomy that only works when it is pointed at us is not a taxonomy, so this one is built to survive being pointed anywhere.

  • Why template, embedding, and feature vector are three names for one artifact, and what the stored numbers can do
  • What encryption at rest actually defends against, and the question to ask the moment a vendor says encrypted
  • How ISO/IEC 24745 splits genuine protection into two families, and why the difference is the sharpest question in an assessment
  • A side-by-side table of what a breach of each artifact yields, and whether it can be revoked
  • Where the SenseCrypt face token sits, and why that placement follows from its construction

Who it is for

Security reviewers and privacy counsel who have to assess a face verification vendor, and who would rather ask five sharp questions than read five data sheets. The taxonomy is vendor-neutral. The closing checklist works against a competitor's architecture as well as it works against ours.

It will not tell you whether a vendor's accuracy is good enough for your population. That is a different question, settled by evaluation data rather than by architecture, and this paper stays out of it on purpose.

Frequently asked questions

Is this paper specific to SenseCrypt?

The first two thirds are not. The taxonomy, the ISO/IEC 24745 families, and the breach-yield table apply to any face verification product, and the paper is written so you can run them against a competitor. The last section places the SenseCrypt face token on the same map.

How long is it?

Six pages, including two diagrams and a comparison table. It is written to be read in one sitting before a vendor call.

Do I need a cryptography background?

No. The paper explains each construction before it uses it. The one section that names primitives does so precisely enough for a cryptographer to check, and the argument around it does not depend on following that detail.

Related reading

More in this series

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.