10Industries · Gaming

Keep the account with the player

Game accounts hold purchases, progress, and payment details, and automated traffic keeps testing them. SenseCrypt removes the password and asks for the player's live face again before anything valuable changes hands.

01The ceremony

Every high-stakes action, one live face

  1. Player starts a guarded action

    Withdrawal, trade, purchase, or account change

  2. CIBA request is created

    Action, amount, expiry

  3. Player sees the exact request

    Live face plus intent, on their own phone

  4. Game server gets the signed result

    Approval or denial, plus an audit reference

02The outcomes

What game platforms get from SenseCrypt

For your customers

Nothing to stuff

Player accounts have no password behind them, so credentials spilled in someone else's breach can't be replayed here.

No password to reset

A lost or new phone is re-bound with a one-time PIN sent to the contact details already on the account. Then the player signs in by face again.

A live-face gate on what matters

Before a withdrawal, a high-value trade, or a change to payment details, the prompt names the exact request, and only the enrolled player's live face can approve it.

Passkeys where phishing is the threat

On the passkey path, sign-in runs a passkey ceremony bound to your site's address, so a look-alike page cannot relay a player's sign-in.

Step up only when it matters

Keep everyday play one-step. Your server decides which actions escalate, and SenseCrypt supplies the strong step.

For your workforce

Support and live-ops, same platform

Your internal consoles ride the same IdP, with roles, scopes, and every action on the audit trail.

For partners & B2B

Partner portals, per tenant

Each studio, publisher partner, or reseller gets an isolated tenant with its own users and branding.

03The failure modes

What gets in the way today

Stuffed around the clock

Passwords reused from other sites get tested against player accounts by bots, at a scale no support team can watch.

Recovery is the back door

A reset granted to a convincing story hands the account to whoever tells it best.

Inventories worth stealing

Items, currency, and progress trade for real money, which makes every account worth taking over.

A code away from a withdrawal

SMS one-time codes can be phished or SIM-swapped, and a relayed code approves a withdrawal as readily as the player would.

Shared screens, shared sessions

A console or family PC stays signed in, and whoever picks up the controller next inherits the account.

Friction costs players

Every extra step at sign-in or checkout is a moment where a player closes the game instead.

04The compliance map

What the regulator sees

No passwords to stuff, and no face image or template on file, only sealed, unlinkable tokens that even we cannot reverse into a face and that carry no PII. There is no password database for a breach to spill.

NIST SP 800-63B — phishing resistance (passkey path)

NIST SP 800-63B names WebAuthn as an example of a standard that provides phishing resistance through verifier name binding. On the passkey path, sign-in runs a passkey ceremony bound to your site's address, so a look-alike page cannot relay it. QR sign-in does not carry this property.

Read the source

GDPR — data minimisation (Art. 5(1)(c))

Players verify without any stored face image or template, so the only thing held is a sealed, unlinkable token that even we cannot reverse into a face and that holds no PII. That supports GDPR's data-minimization principle.

Read the source

Face matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)

GDPR CCPA PDPA
Built from the same three solutions: Customer identity Workforce SSO B2B SaaS

Make account takeover the hard part

Try a real sign-in in the live demo first; it takes about a minute.