The problem: a fake face at the camera
A face login must confirm a real, live person. But a match alone does not prove a live person is at the camera. An attacker can show a fake face instead.
A deepfake is one form of this attack. The attacker plays a deepfake video on a screen. A photo, a video, or a mask works the same way.
- A printed photo of a face
- A video of a face on a screen
- A paper mask or a 3D mask
- A deepfake face on a display
How SenseCrypt blocks a fake face
SenseCrypt is a passwordless identity provider (IdP). A user signs in by face. Face matching runs on-device. SenseCrypt adds liveness detection to the sign-in.
Liveness detection confirms a real, live person at the camera. It reads texture, depth, and light from the face. It rejects a photo, a video, a mask, or a deepfake on a screen.
- Face matching runs on-device.
- Liveness detection separates a live face from a fake face.
- The check rejects a photo, a video, or a mask.
- The check rejects a deepfake shown on a screen.
Certified liveness detection
A vendor claim needs independent proof. An accredited lab tests liveness detection against the ISO/IEC 30107-3 standard. The lab reports a clear pass or fail result.
The SenseCrypt liveness detection holds iBeta ISO 30107-3 certification. This certification covers Level 1 and Level 2 presentation-attack detection.
- Level 1 covers simpler attacks, such as a printed photo.
- Level 2 covers stronger attacks, such as a custom 3D mask.
- An accredited lab reports a clear pass or fail result.
- SenseCrypt stores no biometric data on the server.
What SenseCrypt confirms, and what it does not
SenseCrypt authenticates the enrolled person. It confirms that the live person matches the enrolled face. It is not identity proofing, KYC, or age verification.
Face recognition matches the face. Liveness detection confirms a live person. Together they stop a fake face at the sign-in.
- It confirms the enrolled person by face.
- The NIST FRTE evaluates its face recognition.
- It is not identity proofing or KYC.
- It is not age verification.
The outcome, and who it fits
Certified liveness detection raises trust in a face login. An attacker cannot pass with a photo, a mask, or a deepfake. A user still signs in fast by face.
This use case fits customer identity (CIAM), workforce SSO, and B2B SaaS SSO. SenseCrypt costs one dollar per user per month, flat. A 30-day free trial needs no card.
- Customer identity (CIAM) with a high-trust sign-in
- Workforce single sign-on (SSO) for staff
- B2B SaaS SSO for business customers
- A 30-day free trial needs no card.
Frequently asked questions
Does SenseCrypt detect deepfakes?
A deepfake on a screen is a presentation attack. SenseCrypt uses liveness detection to reject a fake face at the camera. Its liveness detection holds iBeta ISO 30107-3 certification.
What certification does the liveness detection hold?
The SenseCrypt liveness detection holds iBeta ISO 30107-3 certification. It covers Level 1 and Level 2 presentation-attack detection.
What is the difference between liveness detection and presentation attack detection?
The two terms share one goal. Presentation attack detection (PAD) is the formal term in ISO/IEC 30107-3. Liveness detection is the common name.
Is this age verification or identity proofing?
No. SenseCrypt authenticates the enrolled person by face. It is not identity proofing, KYC, or age verification.
Related