09Industries · Insurance

Pay the policyholder, not the impersonator

Claims move money, and agents, adjusters, and brokers all touch policy data. SenseCrypt ties onboarding, payout approval, and staff sign-in to a live face, and files every approval as audit evidence.

01The ceremony

From the onboarding photo to an approved payout

  1. Photo from onboarding

    The identity check you already ran

  2. Live-person enrollment

    Activate once on their own phone; no password ever exists

  3. Payout named in full

    Claim, payee, amount

  4. Signed result + audit event

    OIDC or CIBA, with a person-level log

02The outcomes

What insurers get from SenseCrypt

For your customers

Policyholders in without passwords

Policyholders sign in on the phone in their pocket to check cover, file a claim, or update details. There is no password to forget between renewals.

Onboard from the photo you verified

The photo from your identity check becomes the enrollment, so new policyholders are passwordless from the first day of cover.

Payouts that name the payee

Before a payout or a change of bank details, the prompt names the payee and the amount, and only the policyholder's live face can approve it.

No password to reset

A lost or new phone is re-bound with a one-time PIN sent to the contact details already on the account. Then the policyholder signs in by face again.

For your workforce

Agents and adjusters, one sign-in

Staff and field adjusters approve sign-in on their own phone for every policy, claims, and billing system that speaks OIDC or SAML.

Joiners and leavers, same day

SCIM keeps the directory in sync on its own: new agents are provisioned before they start, and leavers are revoked the day they leave.

Least privilege, by role

Roles and scopes keep underwriting, claims, and finance systems on separate permissions.

For partners & B2B

Broker portals, isolated per firm

Each broker or partner firm gets a tenant of its own: users, roles, branding, and audit trail kept separate.

03The failure modes

What gets in the way today

The payout follows the login

Take over a policyholder's account, change the bank details, and the next payout lands somewhere else.

Recovery by what anyone can find

A reset gated on a policy number and a date of birth authenticates whoever holds those details, not the policyholder.

Agents outside your walls

Independent agents and broker staff need policy data, and their logins sit outside your joiner-leaver process.

Adjusters on every kind of device

Field work runs from cars, client homes, and borrowed screens, and each one is another place a password gets typed.

Every approval must be evidenced

Auditors and regulators ask who approved a claim and when. A shared credential has no name to give.

Codes are a weak lock on a payout

SMS one-time codes can be phished or SIM-swapped, and a relayed code approves a transfer as readily as the policyholder would.

04The compliance map

What the regulator sees

No password vault to breach, and no face image or template on file, only sealed, unlinkable tokens that even we cannot reverse into a face and that carry no PII. For payout approvals, possession of the enrolled phone plus a live face gives you two independent factors.

NYDFS 23 NYCRR 500.12 — multi-factor authentication

New York's cybersecurity regulation requires the insurers and other companies it covers to use multi-factor authentication for any individual accessing their information systems, with limited exemptions. Signing in on the enrolled phone pairs possession of that phone with a live face, two independent factors, which supports that requirement.

Read the source

GDPR — data minimisation (Art. 5(1)(c))

Policyholders and staff verify without any stored face image or template, so the only thing held is a sealed, unlinkable token that even we cannot reverse into a face and that holds no PII. That supports GDPR's data-minimization principle.

Read the source

Face matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)

NYDFS Part 500 GDPR PDPA CCPA
Built from the same three solutions: Customer identity Workforce SSO B2B SaaS

Approve the payout for the right person

Walk a live-face approval through the live demo, then pilot one claim flow on the free 30-day trial.