07Industries · Government
Public services that know the person, not the password
Citizens reach services from any device, and staff work shared counters and case systems. SenseCrypt signs both in with a live face and files every sign-in and approval under a named person.
01The ceremony
From the photo on file to a named session
Photo the service already verified
The source of trust behind the account
Live-person enrollment
Activate once on their own phone; no password ever exists
Named sign-in or approval
Portal, case system, or a request that needs step-up
Signed result + audit event
OIDC or SAML, with a person-level log
02The outcomes
What public services get from SenseCrypt
Services without passwords
Citizens approve sign-in on the phone they already carry. There is no password to forget, reset, or reuse from another site.
One identity across your services
Permits, payments, bookings, records: one directory and one passwordless sign-in for every citizen-facing app that speaks OIDC or SAML.
Step-up that names the request
Before a change of bank details or a claim is submitted, the prompt names the exact request, and only the account holder's live face can approve it.
No password to reset
A lost or new phone is re-bound with a one-time PIN sent to the contact details already on the account. Then the citizen signs in by face again.
Shared counters, named sessions
Staff scan the on-screen code and glance at their own phone. The counter PC needs no enrollment and holds no credentials.
Joiners and leavers, same day
SCIM keeps the directory in sync on its own: new staff are provisioned before they arrive, and leavers are revoked the day they leave.
Least privilege, by role
Roles and scopes keep casework, finance, and records systems on separate permissions, assigned once in one place.
Contractor portals, isolated
Each contractor or partner organization gets a tenant of its own: users, roles, branding, and audit trail kept separate.
03The failure modes
What gets in the way today
Passwords borrowed from everywhere else
A password reused from a shopping or email account turns a leak on some other site into a way into public services.
Shared counters, shared logins
Front-desk and contact-center staff rotate through shared PCs, and a session left open is the fastest login in the room.
Recovery that trusts a story
A reset granted over the phone authenticates whoever tells the most convincing story, not the person the account belongs to.
Oversight asks for names
Auditors and inspectors ask who opened a case or approved a payment. A shared credential has no name to give.
Every stored secret is a liability
Each store of passwords or personal data a service keeps is one more thing to defend, disclose, and justify.
Contractor access outlives the contract
Contractor and supplier logins linger after the engagement ends, and nobody owns switching them off.
04The compliance map
What the regulator sees
No passwords to leak, and no face image or template on file, only sealed, unlinkable tokens that even we cannot reverse into a face and that carry no PII. Every sign-in and approval lands on an audit trail that names the person.
NIST SP 800-207 — Zero Trust Architecture
Every sign-in is a fresh verification of the named person, and a shared counter or office network grants no trust on its own. That maps to the Zero Trust tenets that network location alone does not imply trust and that access is granted per session, with least privilege.
Read the sourceGDPR — data minimisation (Art. 5(1)(c))
Citizens and staff verify without any stored face image or template, so the only thing held is a sealed, unlinkable token that even we cannot reverse into a face and that holds no PII. That supports GDPR's data-minimization principle.
Read the sourceFace matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)
Put a name on every public-sector session
Try a real sign-in in the live demo, then pilot one service on the free 30-day trial.