The need
Customer identity (CIAM) must stay easy and secure.
Passwords cause friction, resets, and abandoned sign-ups.
Attackers phish passwords, steal OTPs, and abuse push prompts.
You need a phishing-resistant sign-in for every customer.
- High sign-in friction lowers sign-up completion.
- Passwords and OTPs raise support cost.
- Account takeover harms trust and revenue.
- Personal data needs careful handling.
What SenseCrypt provides
SenseCrypt is a full identity provider (IdP) for your customer apps.
It supports OpenID Connect (OIDC) and OAuth 2.0 with PKCE and PAR.
It also supports SAML 2.0, SCIM 2.0, and CIBA.
Face login replaces the password for every customer.
The sign-in is phishing-resistant. A customer enters no password and no shared code. A phishing page has nothing to capture or replay. The proof is a live face plus a device-bound signature.
- Passwordless face login for every customer.
- OIDC, OAuth 2.0 (PKCE, PAR), SAML 2.0, SCIM 2.0, and CIBA.
- RBAC, multi-tenant isolation, and audit logs.
- Flat price of one dollar per user per month.
How it works
A customer enrolls once from a photo on file.
Patent-pending face tokenization turns the face into a single-use face token.
Face matching runs on-device at each sign-in.
SenseCrypt stores no biometric data on the server.
Liveness holds iBeta ISO 30107-3 certification (L1 and L2).
The sign-in binds to the customer device, so it resists phishing.
- Enroll once from a photo on file.
- Sign in by face on the customer device.
- On-device face matching keeps data off the server.
- The NIST FRTE evaluates SenseCrypt face recognition since 2021.
The outcome
Customers sign in fast, with no password to forget.
You cut password resets and support cost.
Phishing-resistant sign-in lowers account takeover risk.
You keep clear audit logs for every event.
- Lower sign-in friction and higher completion.
- Fewer password resets and less support load.
- Stronger protection from phishing and account takeover.
- Clear audit logs for every sign-in.
Frequently asked questions
Does SenseCrypt store customer face images?
No. Face matching runs on-device. Patent-pending face tokenization turns a face into a single-use face token. SenseCrypt stores no biometric data on the server.
Is SenseCrypt an identity-proofing or KYC service?
No. SenseCrypt authenticates the enrolled person by face login. It is not KYC, identity-proofing, or age verification.
How does face login resist phishing?
A customer enters no password and no shared code at sign-in. The proof is a live face plus a device-bound signature. The sign-in binds to the customer device. An attacker has nothing to phish.
What does SenseCrypt cost for CIAM?
SenseCrypt costs one dollar per user per month, flat. A 30-day free trial needs no card.
Related