Solution

Workforce SSO, passwordless by face

SenseCrypt gives your workforce a passwordless sign-in by face. Workforce single sign-on (SSO) must protect every app behind one sign-in. Passwords cause resets, lockouts, and help-desk tickets. Face login removes the password. It also resists phishing. An employee enrolls from a photo on file. Then the employee signs in by face. Face matching runs on-device. SenseCrypt stores no biometric data on the server.

The need

Workforce SSO must protect many apps behind one sign-in.

Passwords cause resets, lockouts, and help-desk tickets.

Attackers phish passwords, steal OTPs, and abuse push prompts.

You need a phishing-resistant sign-in for every employee.

  • Password resets raise help-desk cost.
  • Phishing and OTP theft breach workforce accounts.
  • Weak or shared passwords widen the attack surface.
  • Onboarding and offboarding need fast user provisioning.

What SenseCrypt provides

SenseCrypt is a full identity provider (IdP) for your workforce apps.

It supports OIDC, OAuth 2.0 with PKCE and PAR, and SAML 2.0.

SCIM 2.0 provisions and de-provisions employee accounts.

CIBA supports decoupled approval flows.

Face login gives one passwordless sign-in for every app.

  • Passwordless face login across all workforce apps.
  • OIDC, OAuth 2.0 (PKCE, PAR), SAML 2.0, and CIBA.
  • SCIM 2.0 for automatic user provisioning.
  • RBAC and audit logs for access control.

How it works

You connect SenseCrypt to your apps through open standards.

SenseCrypt uses OIDC discovery URLs and SAML 2.0 metadata files.

There is no proprietary connector and no app-store listing.

An employee signs in by face on the device.

Liveness holds iBeta ISO 30107-3 certification (L1 and L2).

The sign-in binds to the device, so it resists phishing.

  • Connect apps with OIDC discovery URLs and SAML 2.0 metadata.
  • Provision users with SCIM 2.0.
  • Employees sign in by face on-device.
  • The NIST FRTE evaluates SenseCrypt face recognition since 2021.

The outcome

Employees reach every app with one face login.

You remove passwords and cut help-desk tickets.

Phishing-resistant sign-in blocks common account attacks.

SCIM 2.0 keeps access current from hire to exit.

  • One fast passwordless sign-in for staff.
  • Fewer resets and lower help-desk cost.
  • Strong protection from phishing and account takeover.
  • Automatic provisioning and clean audit logs.

Frequently asked questions

How does SenseCrypt connect to my apps?

SenseCrypt uses open standards only. It connects through OIDC discovery URLs and SAML 2.0 metadata files. There is no proprietary connector.

Does SenseCrypt provision and remove accounts?

Yes. SCIM 2.0 provisions accounts at hire. It also de-provisions accounts at exit.

Why is face login phishing-resistant?

An employee enters no password and no shared code at sign-in. The proof is a live face plus a device-bound signature. The sign-in binds to the device. An attacker has nothing to phish.

Where does face matching run?

Face matching runs on-device. SenseCrypt stores no biometric data on the server. Liveness holds iBeta ISO 30107-3 certification at L1 and L2.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.