Seventh Sense
The platformSenseCrypt / System architecture

One core. Many doors.
Product-specific key lifecycles.

SenseCrypt brings electronic identity, signing, passwordless access, selective disclosure, agent authorization and personal security apps onto one cryptographic foundation.

Why one primitive

Derived signing keys need no database. Other records remain.

SenseCrypt PKI generates private keys from a live biometric for face sign or face decapsulate, then discards them. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Each product has its own enrollment and infrastructure record requirements.

The architecture, in one view

One live person. A family of products.

Four layers, read bottom to top.

04
Layer 4

Connect to your existing infrastructure

OIDCSAMLFIDO / WebAuthn
02
Layer 2 · the SenseCrypt core — availability varies by product

In PKI: your live biometric generates post-quantum key-pairs in memory → face sign or face decapsulate uses the private key → the private key is discarded. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them. IdP tenant signing keys have a separate retained, encrypted lifecycle.

01
Layer 1 · capture & liveness

A standard camera plus our own presentation-attack detection checks the capture within the method’s evaluated scope.

YOUR DIRECTORYENROLLED PHONELIVE FACE MATCHSENSECRYPT IDPYOUR APPSOPENID CONNECTLEGACY APPSSAML 2.01SCIM 2.02FACE SIGN-IN3COEXISTENCE · NOT RIP-AND-REPLACEYOUR DIRECTORYENROLLED PHONELIVE FACE MATCH1SCIM 2.02FACE SIGN-INSENSECRYPT IDP3YOUR APPSOPENID CONNECTLEGACY APPSSAML 2.0COEXISTENCENOT RIP-AND-REPLACE
Standards federation: keep your directory as the SCIM source of truth and connect applications through OIDC or SAML. IdP uses classical ES256 for OIDC federation, and supports FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.

Biometric-bound, post-quantum, ZK-capable, unlinkable, and person-bound — properties vary across the product family. ZKP is offered through design partnerships; IdP federation still uses classical cryptography.

One human root

Credentials for people and AI agents.

SenseCrypt credentials are bound to a person. While the enrolled phone’s companion app serves as the trust anchor (outside of enterprise webcam flows), the target device—whether a browser, kiosk, or shared terminal—requires no enrollment. This keeps friction low while maintaining high assurance via the enrolled phone. In standard flow, IdP recovery requires verified email, a new device key and a face token. That same human root now extends forward: with KYA, a verified human acts as the certificate authority for the AI agents working on their behalf, and revocation cascades from human to agent.

01

Biometric recognition evaluated in NIST FRTE under Seventh Sense's own name since 2021.

02

SenseCrypt Face PKI supports FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA).

03

Four SenseCrypt patent families filed (PCT), plus a granted US patent.

04

Public developer documentation at docs.sensecrypt.com.

Explore the details

Platform features

Explore face login, OIDC, SAML, SCIM, roles and tenant isolation. Financial-grade flows are supported through FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.

Browse the features

How we compare

SenseCrypt set against Auth0, Okta, Entra ID, Ping and the biometric vendors — including the cases where another tool is the better fit.

See the comparisons