01
Proofing and sign-in are different jobs
Both companies put a face in front of an authentication event, so that checkbox distinguishes nothing. authID reaches further up the lifecycle, covering the moment a new person has to be proved against a document as well as the moment a returning person has to be recognized. SenseCrypt only does the second job.
The other difference is what surrounds the face. authID supplies biometric capability to a stack the customer is already operating. Here the stack is the product: applications collect tokens from the very service that ran the ceremony, over protocols they already speak.
Neither shape is better in the abstract. They are different purchases with different integration costs, and knowing which one you are making saves a quarter.
Face verification runs on the user's phone
Capture, liveness and matching stay on the enrolled phone for both mobile-app methods. There is no face image sent to a server for comparison and no gallery on the other end of the request.
Standard identity protocols are included
The product that runs the face scan is also the one serving OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 and CIBA. No seam divides a biometric service from an identity provider, because only one service exists. Financial-grade flows support FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.
Routine sign-in uses no shared secret
Nothing is typed and nothing is dictated: no password, no digits copied from a screen or a text message. The product's only PIN exists to pair a new handset, arriving by email with an SMS copy where the record holds a mobile number. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.
Where phishing resistance applies
On the passkey path, real FIDO2/WebAuthn passkeys (ES256) and origin binding are what make the claim true. We state it at that path rather than across the platform. Phone sign-in also combines a live face check with a key bound to the enrolled device.
02
What the server holds
Send both vendors the same question and compare the answers as lists. Ours: IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.
The retained face token is quantum-safe, sealed, biometric-free and disposable. No face images or templates are retained in the documented phone flow. Tokens are tenant-bound and stored alongside the required account records.
ISO/IEC 24745:2022 frames what a protected biometric reference should guarantee, and ISO/IEC 30136:2018 frames how such protection is measured. Working to those properties is what lets us call the platform biometric-blind without qualifying it later.
Quantum-safe, revocable and renewable face token
The construction uses NIST 140-3 approved symmetric and hash primitives exclusively: AES-256-GCM, HKDF-SHA256, SHA-256. No proprietary or non-approved cryptographic primitives are used anywhere. Nothing in the token construction depends on a public-key assumption that a quantum computer would break.
Hybrid post-quantum TLS in transit
Sessions negotiate hybrid post-quantum TLS (X25519MLKEM768), which is the transport-side answer to traffic recorded today and attacked much later.
Published independent testing
Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021, at https://pages.nist.gov/frvt/reportcards/11/seventhsense_000.html.
Patent-pending face tokenization and Face PKI
Face tokenization and Face PKI are patent-pending.
03
Choose the right fit
Longer tenure in this market and a wider span of the identity lifecycle both belong to authID. Where the hard problem is establishing who a person is at the point of onboarding, that reach earns its price. Packaging varies by plan, so make a quote name the modules it actually includes.
Our purchase is narrower: one moment, one method, applied to everyone, with nothing gentler waiting behind it. The narrowness is the security argument rather than a gap in the roadmap.
A useful test: write down whether the incident you are trying to prevent happens at account opening or at sign-in. The answer usually names the vendor.
Identity proofing is outside this product's scope
SenseCrypt does not verify a person against a document. It binds a face to an account whose legitimacy you have already established by other means.
Federate rather than migrate
An OIDC or SAML 2.0 registration puts SenseCrypt behind whatever provider you run now, which is why directories, policies and integrated applications all stay untouched.
Tokens carry roles. Your application enforces them.
The token carries roles and permissions; deciding what they permit is the receiving application's job. Within the product itself, sign-in passes a default-closed group gate and console routes sit behind capability checks.
04
Four questions for your vendor assessment
A feature comparison, this one included, will tell a buyer less than four direct questions asked of both companies. Insist on specifics in the replies; category words are what vendors reach for when the specific answer is awkward.
Ours are set out beneath each question, phrased as we would phrase them across a table.
Where does face verification run?
A handset, or a vendor's servers. Nothing else does more to set the blast radius of a breach. For both mobile-app methods, the comparison runs on the enrolled phone.
What remains after enrollment?
IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Include each retained artifact in the security and privacy review.
What can an attacker reuse from a captured session?
Origin binding on the passkey path means an assertion harvested through a lookalike domain will not validate against the real one. Put the same question to any flow whose credential can be used twice. Phone sign-in also combines a live face check with a key bound to the enrolled device.
How does account recovery work?
Recovery is where hardened front doors usually soften. Nothing here can be reset, because no password exists, and the PIN that pairs a replacement handset never features in a normal sign-in. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.
05
Included capabilities and pricing
Seats are a dollar a month, twenty at a minimum, and that figure opens an estimate rather than closing it. Non-exportable signing keys in a managed key service cost twenty dollars per key per month, and the key cannot be copied out by anyone, including us. Tenants and custom domains beyond the three an account already includes add ten dollars a month each, and customer identity deployments bill on monthly active users rather than on every account ever created.
The trial runs thirty days and asks for no card. Two operating limits are worth knowing before the proof of concept rather than during it: end-user authentication keeps no operator-side single sign-on session, so each application sign-in is its own ceremony, and the hash-chained tamper-evident log covers console and administrative actions while end-user sign-ins are recorded in a separate read-only activity stream that is not part of that chain.
- OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126)
- SAML 2.0 identity provider, and SCIM 2.0 (RFC 7644) provisioning for users and groups
- FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone.
- Roles and permissions in the token, a default-closed group gate at sign-in, capability checks on console routes
- Liveness detection tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2
- Tenant isolation, with three tenants or custom domains per account included.
06
Compare the details
| Dimension | SenseCrypt | authID |
|---|---|---|
| Product shape | Identity provider with one sign-in flow | Biometric identity verification and authentication products |
| Identity proofing | Not in scope | Part of the published portfolio, see vendor documentation |
| Where face verification runs | On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows. | See vendor documentation |
| Stored on the server after enrollment | Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. | See vendor documentation |
| Phishing resistance | On the passkey path, via FIDO2/WebAuthn origin binding | See vendor documentation |
| Application protocols | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA | See vendor documentation |
| List price | One dollar per user per month, twenty-seat minimum | Varies by plan |
Product shape
- SenseCrypt
- Identity provider with one sign-in flow
- authID
- Biometric identity verification and authentication products
Identity proofing
- SenseCrypt
- Not in scope
- authID
- Part of the published portfolio, see vendor documentation
Where face verification runs
- SenseCrypt
- On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.
- authID
- See vendor documentation
Stored on the server after enrollment
- SenseCrypt
- Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.
- authID
- See vendor documentation
Phishing resistance
- SenseCrypt
- On the passkey path, via FIDO2/WebAuthn origin binding
- authID
- See vendor documentation
Application protocols
- SenseCrypt
- OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA
- authID
- See vendor documentation
List price
- SenseCrypt
- One dollar per user per month, twenty-seat minimum
- authID
- Varies by plan
07
Frequently asked questions
How does SenseCrypt differ from authID?
Both use face biometrics. authID covers identity verification as well as authentication, selling capability into a stack the customer already runs. SenseCrypt is the identity provider itself: one sign-in ceremony, with OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA served by the same product that runs the face scan.
Where does SenseCrypt keep face data?
It does not keep face data in the form the question implies. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment. The face is matched on the user's enrolled phone for both mobile-app methods.
Is SenseCrypt phishing-resistant?
On the passkey path, yes: those are real FIDO2/WebAuthn passkeys and origin binding ties them to your real site, so a lookalike page cannot use what it captures. The QR path carries no password and no shared code, which removes the thing a phishing kit collects, but the phishing-resistance claim itself belongs to the passkey path. Phone sign-in also combines a live face check with a key bound to the enrolled device.
Can SenseCrypt onboard a brand new customer?
It can enroll one, but it cannot prove one. Enrollment binds a face to an account you have already accepted as legitimate. Document checks, data source verification and the rest of identity proofing are a different category of product, and we would rather say so than let a diagram imply otherwise.
What does SenseCrypt cost?
One dollar per user per month with a twenty-seat minimum, plus twenty dollars per month for each non-exportable signing key in a managed key service and ten dollars per month for each tenant or custom domain past the three included. The thirty-day trial takes no card.