02Industries · Payments
Approve the payment, not the phish
When your risk engine escalates a transaction, the challenge should be stronger than a typed code. SenseCrypt turns approval into a live-face ceremony bound to the exact merchant and amount.
01The ceremony
From risk signal to signed approval
Risk engine requests step-up
Your policy decides when to ask
CIBA request is created
Merchant, amount, action, expiry
Customer sees the exact request
Live face plus intent, on their own phone
Checkout gets the signed result
Approval or denial, plus an audit reference
02The outcomes
Why payment providers pick SenseCrypt
Approval that names the request
Each prompt shows the verified app and the exact action being approved. Only the enrolled person's live face can grant it.
Backchannel confirmation, built in
Your server starts the approval over CIBA. The customer confirms on their own device while checkout waits for the signed result.
No code left to capture
Interception is an attack on things in transit, and nothing secret is in transit. The code was never sent.
Step up only when it matters
Keep low-risk payments one-step. Escalation stays your call, and SenseCrypt supplies the strong step.
Your checkout, their phone
Buyers approve in the authenticator app on the phone they already carry, or inside your own app with the embedded SDK. The device at checkout needs no enrollment.
Ops and fraud teams, same platform
Your internal consoles ride the same IdP, with roles, scopes, and every action on the audit trail.
Merchant portals, per tenant
Each merchant gets an isolated tenant with its own users and branding: SSO you offer, not build.
03The failure modes
What gets in the way today
Codes transit channels you don't control
SMS and email one-time codes are phished, SIM-swapped, and relayed at scale. They are still the default step-up.
Friction is measured in abandoned carts
Every extra code typed at checkout costs completed payments; every reset costs a returning customer.
Push fatigue is the new phishing
Users tap Approve to make prompts go away. Attackers count on exactly that.
3-D Secure friction, your problem
Challenge flows bolted onto checkout cut completion. The customer blames your brand, not the issuer.
Account takeover pays for itself
Stored cards make every account worth taking over, and stuffed passwords are the cheapest way in.
A different challenge on every channel
Web, app, and in-store each authenticate differently. Users feel the inconsistency, and fraud exploits it.
04The compliance map
What the regulator sees
Possession of the enrolled device plus a live face gives you two independent factors, a strong foundation for SCA step-up, without an OTP in sight.
PSD2 SCA — dynamic linking (RTS Art. 5)
Each approval names the amount and the payee, and the signed result is specific to both. That supports the dynamic-linking requirement in Article 5 of the EBA's technical standards for strong customer authentication.
Read the sourceNIST SP 800-63B — phishing resistance
A code the customer types can be relayed, which is why NIST SP 800-63B excludes manually entered one-time codes from phishing resistance. SenseCrypt replaces the typed code with a live-face approval bound to the enrolled device.
Read the sourceFace matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)
Make approval the strongest step in the flow
Passwordless, phishing-resistant confirmation, wired in through CIBA.