01
Compare two approaches to biometric privacy
Keyless publishes an approach built on secure multi-party computation, and describes privacy properties that follow from it. SenseCrypt takes a different route to a related goal: a sealed token derived from the face, with the comparison itself performed on the user's enrolled phone.
Both are worth reading in the vendor's own words rather than in a competitor's summary, which is why this page describes ours precisely and points you at theirs. Marketing adjectives converge in this category; the architecture does not.
The other difference is scope. Keyless is a biometric authentication technology. SenseCrypt is the identity provider around it, issuing the tokens your applications already know how to consume.
Face verification runs on the phone
For both mobile-app methods, capture, liveness and matching run on the user's own phone. The enterprise webcam method matches from the webcam instead, and it is arranged separately through sales@seventhsense.ai.
Sign-in and federation in one product
A single service issues the OIDC and OAuth 2.0 endpoints (with PKCE and pushed authorization requests), the SAML 2.0 metadata, SCIM 2.0 and CIBA, and that same service runs the ceremony. Nothing has to be held at a matching version with anything else. Financial-grade flows support FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.
Passkeys provide origin-bound phishing resistance
Real FIDO2/WebAuthn passkeys (ES256) presented by the companion app as a roaming authenticator, with origin binding doing the work. That is the claim, at the path where it holds.
No password anywhere in the system
Nothing exists that a helpdesk could reset. The product issues exactly one PIN, and it does one job, pairing a replacement handset: emailed, and texted as well where the record holds a mobile number. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.
02
What the server holds after enrollment
When two vendors both describe themselves as privacy-preserving, the way to separate them is to ask each for the list of what persists and to read the two lists side by side. Ours: IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.
The retained face token is quantum-safe, sealed, biometric-free and disposable. No face images or templates are retained in the documented phone flow. Tokens are tenant-bound and stored alongside the required account records. ISO/IEC 24745:2022 describes those properties for a protected biometric reference, and ISO/IEC 30136:2018 describes how they are measured.
Because the token is sealed and tenant-bound, an exfiltration of the SenseCrypt datastore must be assessed for exposed references and account records. That is the whole content of the term biometric-blind, and it is a narrower statement than it first appears.
Quantum-safe, revocable and renewable face token
The construction uses NIST 140-3 approved symmetric and hash primitives exclusively: AES-256-GCM, HKDF-SHA256, SHA-256. No proprietary or non-approved cryptographic primitives are used anywhere.
Hybrid post-quantum TLS in transit
Traffic runs over hybrid post-quantum TLS (X25519MLKEM768), which addresses harvest-now-decrypt-later on the wire while the NIST FIPS 203/204/205 series settles the primitives.
Testing you can check
Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021: https://pages.nist.gov/frvt/reportcards/11/seventhsense_000.html.
Patent-pending face tokenization and Face PKI
Face tokenization and Face PKI are patent-pending.
03
Confirm the current product offering
Keyless is now part of a large enterprise identity platform, which changes what you are buying and who supports it. For an organization that already holds a Ping relationship, adding a biometric line inside an existing contract is a materially easier purchase than onboarding a new vendor, and that advantage is real regardless of the technology underneath.
What we sell is smaller and deliberately less: a single ceremony, carried from capture to issued token by one service, with the identity protocols already inside it.
Neither of those is a technical argument. They are procurement facts, and procurement facts decide more evaluations than architecture does.
Check the product and contract scope
Buying inside an existing platform relationship is faster than approving a new supplier. If that is decisive for you, it should be said early rather than discovered at the security review stage.
Confirm which offering includes biometrics
A capability folded into a large platform is seldom packaged the way it was when the company stood alone. Before a business case rests on it, have the module, the tier and the price confirmed in writing.
Consider federation with your existing provider
SenseCrypt attaches to the identity platform you already run as an external IdP over OIDC or SAML 2.0, so evaluating it does not require displacing anything.
04
What to check after an acquisition
If your evaluation of Keyless started before it joined Ping, part of it needs redoing. We will not guess at another company's roadmap or packaging, and you should be wary of any vendor page that does.
What is worth doing is sending one identical set of four questions to each company and reading the written replies together. Ours are set out underneath, which puts them on the record alongside anyone else's.
Which plan includes biometric authentication?
Ask Ping directly for the module, the tier and the term. A capability inside a platform is priced by that platform, not by the company that built it.
Where does face verification run?
On the user's device or somewhere else. SenseCrypt matches on the enrolled phone for both mobile-app methods, and states the exception: the enterprise webcam method matches from a webcam.
What persists after enrollment
IdP retains quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys, are held as well. It does not retain any face images or templates in the documented phone flow.
Who supports production incidents?
After an acquisition, support paths and escalation routes change. Ask who you call at three in the morning, and get the answer before signing rather than after.
05
Protocols, boundaries and pricing
Seats cost a dollar a month, with twenty as the smallest order, which opens an estimate rather than settling it. Non-exportable signing keys in a managed key service are twenty dollars per key per month, and the key cannot be copied out by anyone, including us. Past the three tenants or custom domains an account already carries, each additional one is ten dollars a month, and customer identity deployments meter monthly active users.
The trial runs thirty days and takes no card. Two limits, named in advance: end-user authentication keeps no operator-side single sign-on session, so each application sign-in is its own ceremony and the only browser session in the product belongs to the admin console; and the hash-chained tamper-evident log covers administrative actions, while end-user sign-ins go to a separate read-only activity stream that is not part of that chain.
- OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126)
- SAML 2.0 identity provider, and SCIM 2.0 (RFC 7644) provisioning for users and groups
- FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone.
- Real FIDO2/WebAuthn passkeys (ES256) via the companion app acting as a roaming authenticator
- Liveness detection tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2
- Multi-tenant isolation, roles and permissions in the token, a default-closed group gate at sign-in
06
Compare the details
| Dimension | SenseCrypt | Keyless |
|---|---|---|
| Product shape | Identity provider with one sign-in flow | Biometric authentication technology, now part of Ping Identity |
| Where face verification runs | On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows. | See vendor documentation |
| Stored on the server after enrollment | Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. | See vendor documentation |
| Phishing resistance | On the passkey path, via FIDO2/WebAuthn origin binding | See vendor documentation |
| Application protocols | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA | See vendor documentation |
| Purchased from | Seventh Sense, as an independent product | Ping Identity, as part of its portfolio |
| List price | One dollar per user per month, twenty-seat minimum | Varies by plan |
Product shape
- SenseCrypt
- Identity provider with one sign-in flow
- Keyless
- Biometric authentication technology, now part of Ping Identity
Where face verification runs
- SenseCrypt
- On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.
- Keyless
- See vendor documentation
Stored on the server after enrollment
- SenseCrypt
- Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.
- Keyless
- See vendor documentation
Phishing resistance
- SenseCrypt
- On the passkey path, via FIDO2/WebAuthn origin binding
- Keyless
- See vendor documentation
Application protocols
- SenseCrypt
- OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA
- Keyless
- See vendor documentation
Purchased from
- SenseCrypt
- Seventh Sense, as an independent product
- Keyless
- Ping Identity, as part of its portfolio
List price
- SenseCrypt
- One dollar per user per month, twenty-seat minimum
- Keyless
- Varies by plan
07
Frequently asked questions
Keyless is part of Ping now. Does that change the comparison?
It changes the purchase more than the technology. You are evaluating a biometric line inside a large identity platform rather than an independent supplier, so ask Ping which plan carries it, how it is packaged, and who owns support and escalation. Those answers come from Ping and should be in writing before a business case depends on them.
Both vendors describe themselves as privacy-preserving. How do we tell them apart?
Ask each vendor for the list of what persists after enrollment. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Compare that with the other vendor’s own description.
Where does SenseCrypt match the face?
On the user's enrolled phone for both mobile-app methods, the QR flow and the passkey flow. The exception is the enterprise webcam method, available to enterprise customers on a trusted network, where captures are processed inside the customer's isolated deployment rather than the phone.
Does SenseCrypt need the user's phone every time?
Yes for the two mobile-app methods. The companion app on an enrolled phone is required and there is no deviceless mode. The device being signed in to, whether a browser, kiosk or desktop, needs no enrollment at all.
What does SenseCrypt cost?
One dollar per user per month with a twenty-seat minimum, twenty dollars per month for each non-exportable signing key in a managed key service, and ten dollars per month for each tenant or custom domain past the three included. A thirty-day trial runs without a card.