Seventh Sense
Enterprise workforceINDUSTRIES / ENTERPRISE

Kill the password.
Keep your IAM.

SenseCrypt IdPLaunched
Add passwordless access alongside your existing FIDO/WebAuthn and SAML/OAuth systems. SenseCrypt supports person-bound recovery with verified-contact and device-key checks, and human-authorized credentials for AI agents.
01Coexistence

Add a person-bound factor to your existing IAM.

Add a person-bound factor to your existing IAM through OIDC or SAML. You do not replace your identity provider to remove passwords — you add a person-bound factor where it matters most, starting with privileged access, and expand on your own schedule. Phone sign-in runs the live face check on the enrolled phone. Administrator photo provisioning processes the image transiently in the minting service; licensed on-premises webcam capture runs inside the customer deployment.

YOUR DIRECTORYENROLLED PHONELIVE FACE MATCHSENSECRYPT IDPYOUR APPSOPENID CONNECTLEGACY APPSSAML 2.01SCIM 2.02FACE SIGN-IN3COEXISTENCE · NOT RIP-AND-REPLACEYOUR DIRECTORYENROLLED PHONELIVE FACE MATCH1SCIM 2.02FACE SIGN-INSENSECRYPT IDP3YOUR APPSOPENID CONNECTLEGACY APPSSAML 2.0COEXISTENCENOT RIP-AND-REPLACE
Standards federationYour directory provisions people over SCIM 2.0 and stays the source of truth. Sign-in is a live face match on the enrolled phone. Applications federate over OpenID Connect and SAML 2.0, so your estate coexists with SenseCrypt IdP instead of being replaced.
02Recovery & accountability

Identity that stays with the person.

01

Person-bound recovery with a verified contact route.

Recovery binds a replacement device after verified-mailbox PIN and new device-key checks; the original enrolled face is still required at sign-in. If the mailbox or enrollment reference is unavailable, the supported administrator recovery process applies.

02

Make agent authority traceable to a person.

KYA lets a verified human authorize an agent certificate with a defined model identity, scope and expiry.

Your responsibilities
  • Enforcing the delegated permissions in the consuming application.
  • Verifying each agent’s signed actions.
  • Applying revocation from the human to the agent.
03Relevant solutions

Choose products for your deployment.

01

SenseCrypt IdP

Passwordless SSO. Phone methods verify the live person and enrolled device.

02

SenseCrypt KYA

Make every AI agent answerable to a verified human.

03

SenseCrypt PKI

Person-bound signing for privileged operations.