Seventh Sense
Compare

SenseCrypt
Technical library

Biometric vendors

SenseCrypt vs FaceTec

FaceTec licenses 3D face liveness and matching technology to other vendors, and publishes a spoof bounty program against it. SenseCrypt is an identity provider whose only sign-in is a face scan completed in a companion app. This is a comparison between a component and a system, which is the first thing to settle.

7 sectionsSeventh Sense / SenseCrypt
On this page

01

A liveness component or an identity provider?

What FaceTec licenses is the face itself. A customer embeds the technology inside an application they own and then supplies everything that surrounds it: the session, the token internal services agree to trust, the directory, the protocol the applications speak. All of that surrounding material is what SenseCrypt sells, with the face serving as the way in.

Capture and token issuance happen inside a single service here, so no seam exists between them for an engineering team to own. Work that would otherwise be written and then maintained simply disappears, and so does a decision that team used to get to make. That trade settles most of these evaluations.

Deepfakes are why the question of what a face component actually covers has become sharper. In February 2024 a finance employee at the engineering firm Arup authorized transfers of about 25 million US dollars after a video call with deepfaked colleagues. That attack targeted a human decision rather than a biometric sensor, but it is the reason buyers now ask exactly which attacks a liveness certificate covers.

Face verification runs on the phone

Across both mobile-app methods, capture, liveness and comparison remain on the user's handset. Neither a face image nor a biometric template ever arrives at the server, which leaves no gallery to defend and none to account for.

Protocol endpoints included

OIDC and OAuth 2.0 (PKCE and pushed authorization requests included), SAML 2.0, SCIM 2.0 and CIBA are endpoints on the same service that runs the ceremony. An application talks to an identity provider, not to an SDK plus whatever was built around it. Financial-grade flows support FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.

Injection is a separate control

A presentation attack is held up at the camera; an injection attack bypasses the camera entirely. Sign-in runs inside the SenseCrypt app on an enrolled phone, with app attestation and device authenticity checks at every ceremony.

Where phishing resistance applies

Real FIDO2/WebAuthn passkeys (ES256) with origin binding are what make that path phishing-resistant. The claim stays attached to the mechanism rather than spreading across the product.

02

What a liveness certificate covers

Liveness detection in SenseCrypt is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. That standard governs presentation attack detection testing: artifacts presented at the sensor, such as a printed photograph, a screen replay, or a mask.

It does not speak to a virtual camera or an injected video stream, and no ISO/IEC 30107-3 result should be read as though it did. Those attacks are addressed by different controls, which is why the two are described separately here rather than merged into one reassuring sentence.

Face recognition, as opposed to liveness, is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021. The report card is public at https://pages.nist.gov/frvt/reportcards/11/seventhsense_000.html, and NIST evaluates algorithms rather than certifying them, which is why we say NIST-evaluated and never anything stronger.

Presentation attacks, at the camera

ISO/IEC 30107-3:2023 defines how presentation attack detection is tested, and iBeta is the laboratory that ran ours at Levels 1 and 2.

Injection attacks, past the camera

Handled by requiring the ceremony to run inside the SenseCrypt app on an enrolled device, with app attestation and device authenticity checks performed at each sign-in.

Recognition, evaluated separately

Liveness and recognition are different problems with different evidence. Conflating a liveness certificate with recognition accuracy is the most common error in this category of comparison.

03

What each product includes

FaceTec's whole business is a single hard problem, solved well and then licensed broadly. The company also opens its liveness technology to a spoof bounty anyone can attempt, a more confident posture than this market usually adopts. None of it overlaps with what we sell.

An organization already running its own directory, its own sessions and its own token service can drop a liveness component into an application and disturb nothing else. Buying an identity provider relocates the sign-in itself, and that is a heavier decision than the procurement line makes it look.

So the shape here is narrower on one axis and considerably wider on another. Take the points below as an account of the shape we picked, not as a deficiency in the one FaceTec picked.

Integrate a component into your existing system

An SDK license alters a single part of a system that stays yours. Everything surrounding that part also stays yours, including the pieces teams routinely underestimate.

An identity provider manages sign-in

SenseCrypt issues the tokens, holds the enrolled users, and runs the ceremony. That is less code for you to write and more of the flow outside your direct control.

Federation instead of a migration

Registered as an external IdP over OIDC or SAML 2.0, SenseCrypt sits behind the provider already in place, so a single application or group can move while everything else holds still.

04

Four questions before you decide

In the table further down, two products with almost nothing in common can earn the same tick for entirely unrelated reasons. Four questions pull them apart faster than any grid will.

Ask us as well as them. Each answer sits under its question here, so whatever gets said on a call can be measured against something written.

A component or a complete sign-in system?

An SDK is a part. An identity provider is a system. Put a number on the engineering that has to surround that part, because the work is real and no license quote will show it.

What remains after enrollment?

Ask for an itemized inventory. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow.

What does the liveness test cover?

Ours comes from iBeta testing to ISO/IEC 30107-3 Levels 1 and 2, covering artifacts held up in front of the camera. Ask every vendor the same about theirs, then ask a second question about injected streams.

How does replacement-phone recovery work?

Passwordless deployments tend to soften at exactly this point. No password exists to be reset, and the PIN that pairs a new handset never features in a normal sign-in. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.

05

Integration surface, limits and price

SenseCrypt is a standards-based identity provider, so what your application integrates against is an OIDC or SAML endpoint rather than a camera SDK. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.

A seat costs a dollar a month, with twenty as the smallest order. A non-exportable signing key in a managed key service adds twenty dollars per key per month, and the key cannot be copied out by anyone, including us. Tenants and custom domains past the three included in every account are ten dollars per month each, customer identity deployments meter monthly active users, and the thirty-day trial takes no card.

Two limits, named rather than implied: end-user authentication keeps no operator-side single sign-on session, so each application sign-in is a fresh ceremony and the only browser session in the product belongs to the admin console; and the hash-chained tamper-evident log covers administrative actions there, while end-user sign-ins are recorded in a separate read-only activity stream that is not hash-chained.

  • OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126)
  • SAML 2.0 identity provider, and SCIM 2.0 (RFC 7644) provisioning for users and groups
  • FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone.
  • Real FIDO2/WebAuthn passkeys (ES256) through the companion app acting as a FIDO CTAP 2.1 roaming authenticator
  • Liveness detection tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2
  • Multi-tenant isolation, roles and permissions in the token, a default-closed group gate at sign-in

06

Compare the details

SenseCrypt and FaceTec, dimension by dimension
DimensionSenseCryptFaceTec
What you buyAn identity provider and the sign-in ceremony inside itFace liveness and matching technology, licensed as a component
Who builds the session and token layerSenseCryptThe integrating vendor or customer
Where face verification runsOn the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.Depends on the integration, see vendor documentation
Stored on the server after enrollmentQuantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.Depends on the integration
Liveness testingTested by iBeta to ISO/IEC 30107-3 Levels 1 and 2See vendor documentation
Application protocolsOIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBANot applicable to a component
List priceOne dollar per user per month, twenty-seat minimumLicensed, varies by agreement

What you buy

SenseCrypt
An identity provider and the sign-in ceremony inside it
FaceTec
Face liveness and matching technology, licensed as a component

Who builds the session and token layer

SenseCrypt
SenseCrypt
FaceTec
The integrating vendor or customer

Where face verification runs

SenseCrypt
On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.
FaceTec
Depends on the integration, see vendor documentation

Stored on the server after enrollment

SenseCrypt
Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.
FaceTec
Depends on the integration

Liveness testing

SenseCrypt
Tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2
FaceTec
See vendor documentation

Application protocols

SenseCrypt
OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA
FaceTec
Not applicable to a component

List price

SenseCrypt
One dollar per user per month, twenty-seat minimum
FaceTec
Licensed, varies by agreement

07

Frequently asked questions

Is SenseCrypt an identity provider or a biometric SDK?

An identity provider. It supports OpenID Connect and OAuth 2.0 (RFC 6749) with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 and CIBA, alongside role-based access control, multi-tenant isolation, and a hash-chained, tamper-evident log covering console and administrative actions. The face ceremony is how a user proves presence inside that provider rather than a component you embed in your own application. Financial-grade flows support FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.

Can we license the SenseCrypt face technology on its own?

The product described on this site is the identity provider. If your requirement is a face component inside an application you own, say so directly at sales@seventhsense.ai rather than assuming the answer from a comparison page.

What does the iBeta result cover?

Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2, which addresses presentation attacks at the camera: printed photographs, screen replays, masks. It does not cover injected video streams. Those are handled by running the ceremony inside the SenseCrypt app on an enrolled phone, with app attestation and device authenticity checks at each sign-in.

Why does the page not quote accuracy numbers?

Because a false accept or false reject figure is meaningless without the dataset, the threshold and the operating point behind it. Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021, and the public report card is the honest place to look at measured performance.

What does the server store about a face?

IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.

How much engineering does an integration take?

An OIDC or SAML integration, of the kind your team has probably done before. That is the practical difference against licensing a component: the session layer, the token service and the directory already exist, so the work is configuration and claim mapping rather than building the surrounding system.

Next step

The next level of detail depends on your stack, so the fastest route is a conversation.