One core. Many doors.
Product-specific key lifecycles.
SenseCrypt brings electronic identity, signing, passwordless access, selective disclosure, agent authorization and personal security apps onto one cryptographic foundation.
Find the product for your use case.
Availability is specific to each product. Explore the architecture and deployment requirements before you build.
SenseCrypt IdP
LaunchedSenseCrypt IdP connects live face checks to your existing identity protocols for passwordless access.
SenseCrypt eID
AvailableIssue a digital credential that can be checked against its holder, even from a printed QR. Offline use requires a prepared supported verifier and trusted issuer material.
SenseCrypt PKI
AvailableYour live biometric generates post-quantum PKI key-pairs in memory. Store the public keys. Private keys exist only during face sign or face decapsulate and are never stored.
SenseCrypt ZKP
Design partnershipsProve an age threshold, residency or entitlement while withholding the underlying personal details. SenseCrypt ZKP is open to design partnerships and is not yet generally available.
SenseCrypt KYA
Early accessRecord an AI agent’s human authorizer, permissions and expiry. SenseCrypt KYA is in early access; connected applications must enforce those permissions.
Lume Auth
AvailableKeep authenticator codes, passwords and private notes in Lume Auth. A live face scan unlocks your encrypted vault without a master password. Chat is included: end-to-end encrypted messaging with contact keys bound to enrolled people and a live face scan to open protected conversations.
Derived signing keys need no database. Other records remain.
SenseCrypt PKI generates private keys from a live biometric for face sign or face decapsulate, then discards them. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Each product has its own enrollment and infrastructure record requirements.
One live person. A family of products.
Four layers, read bottom to top.
In PKI: your live biometric generates post-quantum key-pairs in memory → face sign or face decapsulate uses the private key → the private key is discarded. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them. IdP tenant signing keys have a separate retained, encrypted lifecycle.
A standard camera plus our own presentation-attack detection checks the capture within the method’s evaluated scope.
Biometric-bound, post-quantum, ZK-capable, unlinkable, and person-bound — properties vary across the product family. ZKP is offered through design partnerships; IdP federation still uses classical cryptography.
Credentials for people and AI agents.
SenseCrypt credentials are bound to a person. While the enrolled phone’s companion app serves as the trust anchor (outside of enterprise webcam flows), the target device—whether a browser, kiosk, or shared terminal—requires no enrollment. This keeps friction low while maintaining high assurance via the enrolled phone. In standard flow, IdP recovery requires verified email, a new device key and a face token. That same human root now extends forward: with KYA, a verified human acts as the certificate authority for the AI agents working on their behalf, and revocation cascades from human to agent.
See the evidence.
See the full proof inventoryBiometric recognition evaluated in NIST FRTE under Seventh Sense's own name since 2021.
SenseCrypt Face PKI supports FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA).
Four SenseCrypt patent families filed (PCT), plus a granted US patent.
Public developer documentation at docs.sensecrypt.com.
Platform features
Explore face login, OIDC, SAML, SCIM, roles and tenant isolation. Financial-grade flows are supported through FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.
Browse the featuresHow we compare
SenseCrypt set against Auth0, Okta, Entra ID, Ping and the biometric vendors — including the cases where another tool is the better fit.
See the comparisons