01
Identity lifecycle or focused sign-in?
A customer buying Daon already operates an identity stack and is fitting biometrics into it, along with the front half of the lifecycle: a new person proved against a document, onboarded, then recognized on every subsequent visit. SenseCrypt is the stack itself, built for the last of those jobs, and a face is how it opens.
Keep that shape in mind through the rest of the page, because the feature lists converge while the products do not. Here, one service runs the ceremony and mints the token an application reads, which deletes an integration seam and a choice in the same stroke.
None of that weakens the case for treating sign-in as a product in its own right. The 2026 Verizon Data Breach Investigations Report found credentials present in 28 percent of breaches, and however rigorous the proofing at account opening, it does nothing for the thousandth sign-in.
Face verification runs on the phone
For both mobile-app methods, capture, liveness and comparison remain on the user's own phone. Nothing accumulates into a gallery, so there is none to breach and none to enumerate when an auditor asks what biometric data the organization holds.
Identity protocols are included
The ceremony and the protocol endpoints belong to a single service: OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 and CIBA. There is no second system to integrate first and then maintain. Financial-grade flows support FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.
Nothing to type at sign-in
No password, and no digits copied off a screen. Across an entire account lifetime a user sees one PIN, at the moment a device is paired, delivered by email with a parallel SMS where a mobile number is held.
Phishing resistance, scoped to the passkey path
Real FIDO2/WebAuthn passkeys (ES256) with origin binding are what make that path phishing-resistant. We keep the claim attached to the mechanism that delivers it.
02
What the server retains
Regulated buyers ask this question with a compliance framework open on the desk, which is the right way to ask it. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.
The retained face token is quantum-safe, sealed, biometric-free and disposable. No face images or templates are retained in the documented phone flow. Tokens are tenant-bound and stored alongside the required account records. ISO/IEC 24745:2022 is the reference for those properties, and ISO/IEC 30136:2018 for measuring the protection.
The result is a shorter biometric section in a risk register. There is no gallery to exfiltrate, biometric-free face tokens and account records to assess in a data subject request, and sealed, biometric-free, disposable face tokens and account records to assess on exit, which is why we describe the platform as biometric-blind.
Quantum-safe, revocable and renewable face token
The construction uses NIST 140-3 approved symmetric and hash primitives exclusively: AES-256-GCM, HKDF-SHA256, SHA-256. No proprietary or non-approved cryptographic primitives are used anywhere. There is no public-key assumption inside the token for a future quantum computer to undo.
Hybrid post-quantum TLS in transit
Traffic runs over hybrid post-quantum TLS (X25519MLKEM768). For institutions working to the US NSM-10 timetable and the NIST FIPS 203/204/205 series, that is one migration item already closed.
Published independent testing
Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021: https://pages.nist.gov/frvt/reportcards/11/seventhsense_000.html.
Patent-pending face tokenization and Face PKI
Face tokenization and Face PKI are patent-pending.
03
Compare scope and track record
More of the identity lifecycle sits inside Daon's scope than ours, across several modalities, backed by a long record in sectors that audit their suppliers rigorously. Establishing that a new customer is genuine and recognizing a returning one are two jobs, and a supplier holding both can price both in a single quote.
What follows is an account of what we traded away to build something narrow, not a complaint about anyone who built something wide.
One method, hardened, with no password path in reserve. The absence of anything gentler to retreat to is precisely what makes the front door hard, and precisely what makes it rigid. Both of those hold simultaneously.
Evaluate deployment experience
A supplier with decades of regulated deployments behind it is easier to defend to a risk committee. That is not a technical argument, and it is often the decisive one.
Proofing is outside our scope
SenseCrypt does not verify a person against a document. Enrollment binds a face to an account you have already accepted, so the onboarding half has to be bought or built elsewhere.
Federate rather than migrate
Registered as an external IdP over OIDC or SAML 2.0, SenseCrypt sits behind the provider you operate today, which lets a single application or a single pilot group move while nothing else does.
04
Questions for your evaluation
Any grid, the one further down included, will award identical ticks to products that earned them for unrelated reasons. Four questions do the separating that a table cannot.
Put them to us too. Each answer below is what we would say in a meeting, written out here so the two versions can be held against each other.
Identity proofing or authentication?
Establishing that a new customer is genuine before any account exists is identity proofing, and it is a discipline in its own right. We handle the returning-user half only, so the other half needs counting into any comparison rather than assuming it arrives free.
What remains after enrollment?
Ask for an itemized inventory. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow.
How recovery works
A reset route is nearly always softer than the door it stands beside. Here there is nothing to reset, because no password exists, and the PIN that pairs a replacement handset never appears in a normal sign-in. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.
Which biometric methods do you need?
A single method is cheaper to run and leaves fewer soft edges; several methods reach more people. Before treating flexibility as optional, write down which employee groups cannot put a face in front of a camera.
05
Controls, boundaries and cost
Seats cost a dollar a month against a floor of twenty, which opens an estimate rather than closing it. Non-exportable signing keys in a managed key service add twenty dollars per key per month, and the key cannot be copied out by anyone, including us. Tenants and custom domains beyond the three an account already carries cost ten dollars a month each, and customer identity deployments meter monthly active users, so a month with no sign-in produces no charge for that account.
The trial runs thirty days and asks for no card. Two boundaries a regulated buyer should know before the security questionnaire arrives: end-user authentication keeps no operator-side single sign-on session, so each application sign-in is its own ceremony and the only browser session in the product belongs to the admin console; and the hash-chained tamper-evident log covers console and administrative actions, while end-user sign-ins are recorded in a separate read-only activity stream that is not hash-chained and has no customer-facing verification endpoint.
- OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126)
- SAML 2.0 identity provider, and SCIM 2.0 (RFC 7644) provisioning for users and groups
- FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone.
- Roles and permissions in the token, a default-closed group gate at sign-in, capability checks on console routes
- Liveness detection tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2
- Tenant isolation, with three tenants or custom domains per account included.
06
Compare the details
| Dimension | SenseCrypt | Daon |
|---|---|---|
| Product shape | Identity provider with one sign-in flow | Platform spanning proofing, onboarding and biometric authentication |
| Identity proofing | Not in scope | Included in the published platform; see vendor documentation. |
| Biometric modalities | Face only | Multiple methods; see vendor documentation. |
| Where face verification runs | On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows. | See vendor documentation |
| Stored on the server after enrollment | Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. | See vendor documentation |
| Application protocols | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA | See vendor documentation |
| List price | One dollar per user per month, twenty-seat minimum | Varies by plan |
Product shape
- SenseCrypt
- Identity provider with one sign-in flow
- Daon
- Platform spanning proofing, onboarding and biometric authentication
Identity proofing
- SenseCrypt
- Not in scope
- Daon
- Included in the published platform; see vendor documentation.
Biometric modalities
- SenseCrypt
- Face only
- Daon
- Multiple methods; see vendor documentation.
Where face verification runs
- SenseCrypt
- On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.
- Daon
- See vendor documentation
Stored on the server after enrollment
- SenseCrypt
- Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.
- Daon
- See vendor documentation
Application protocols
- SenseCrypt
- OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA
- Daon
- See vendor documentation
List price
- SenseCrypt
- One dollar per user per month, twenty-seat minimum
- Daon
- Varies by plan
07
Frequently asked questions
How is SenseCrypt different from Daon?
Daon covers identity proofing, onboarding and multi-modal biometric authentication, sold into a stack the customer already runs. SenseCrypt is a standards-based identity provider with one face-based sign-in ceremony, matching on the user's enrolled phone and storing no face image or biometric template. Review Daon's own published material for its details rather than a competitor's summary.
Can SenseCrypt handle customer onboarding?
It can enroll a user but it cannot prove one. Document verification and data source checks are a separate discipline that SenseCrypt does not perform. If both jobs are in scope, budget for both rather than expecting a sign-in product to cover onboarding.
Does SenseCrypt store a face on a server?
No. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment. That token is persisted and requires the configured authorized processing boundary.
What evidence is available for a security questionnaire?
Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021, and the report card is public. The design targets the protected biometric reference properties in ISO/IEC 24745:2022, measured as ISO/IEC 30136:2018 describes.
What does the audit log cover?
Administrative actions in the console are written to a hash-chained, tamper-evident log. End-user sign-ins are recorded separately in a read-only activity stream that is not part of that chain, and there is no customer-facing interface for verifying the chain yourself. It is better to know that before a questionnaire asks than after.