10Industries · Gaming
Keep the account with the player
Game accounts hold purchases, progress, and payment details, and automated traffic keeps testing them. SenseCrypt removes the password and asks for the player's live face again before anything valuable changes hands.
01The ceremony
Every high-stakes action, one live face
Player starts a guarded action
Withdrawal, trade, purchase, or account change
CIBA request is created
Action, amount, expiry
Player sees the exact request
Live face plus intent, on their own phone
Game server gets the signed result
Approval or denial, plus an audit reference
02The outcomes
What game platforms get from SenseCrypt
Nothing to stuff
Player accounts have no password behind them, so credentials spilled in someone else's breach can't be replayed here.
No password to reset
A lost or new phone is re-bound with a one-time PIN sent to the contact details already on the account. Then the player signs in by face again.
A live-face gate on what matters
Before a withdrawal, a high-value trade, or a change to payment details, the prompt names the exact request, and only the enrolled player's live face can approve it.
Passkeys where phishing is the threat
On the passkey path, sign-in runs a passkey ceremony bound to your site's address, so a look-alike page cannot relay a player's sign-in.
Step up only when it matters
Keep everyday play one-step. Your server decides which actions escalate, and SenseCrypt supplies the strong step.
Support and live-ops, same platform
Your internal consoles ride the same IdP, with roles, scopes, and every action on the audit trail.
Partner portals, per tenant
Each studio, publisher partner, or reseller gets an isolated tenant with its own users and branding.
03The failure modes
What gets in the way today
Stuffed around the clock
Passwords reused from other sites get tested against player accounts by bots, at a scale no support team can watch.
Recovery is the back door
A reset granted to a convincing story hands the account to whoever tells it best.
Inventories worth stealing
Items, currency, and progress trade for real money, which makes every account worth taking over.
A code away from a withdrawal
SMS one-time codes can be phished or SIM-swapped, and a relayed code approves a withdrawal as readily as the player would.
Shared screens, shared sessions
A console or family PC stays signed in, and whoever picks up the controller next inherits the account.
Friction costs players
Every extra step at sign-in or checkout is a moment where a player closes the game instead.
04The compliance map
What the regulator sees
No passwords to stuff, and no face image or template on file, only sealed, unlinkable tokens that even we cannot reverse into a face and that carry no PII. There is no password database for a breach to spill.
NIST SP 800-63B — phishing resistance (passkey path)
NIST SP 800-63B names WebAuthn as an example of a standard that provides phishing resistance through verifier name binding. On the passkey path, sign-in runs a passkey ceremony bound to your site's address, so a look-alike page cannot relay it. QR sign-in does not carry this property.
Read the sourceGDPR — data minimisation (Art. 5(1)(c))
Players verify without any stored face image or template, so the only thing held is a sealed, unlinkable token that even we cannot reverse into a face and that holds no PII. That supports GDPR's data-minimization principle.
Read the sourceFace matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)
Make account takeover the hard part
Try a real sign-in in the live demo first; it takes about a minute.