Seventh Sense
Compare

SenseCrypt
Technical library

Biometric vendors

SenseCrypt vs 1Kosmos

1Kosmos publishes a platform that pairs identity verification with passwordless biometric authentication, with identity data held on a distributed ledger. SenseCrypt is an identity provider with a single sign-in ceremony, a face scan completed in a companion app on the enrolled phone. The overlap is narrower than the category suggests.

7 sectionsSeventh Sense / SenseCrypt
On this page

01

Compare product scope and architecture

Both vendors sign a person in with a biometric, so that fact settles nothing. The shapes differ. 1Kosmos runs the length of the identity lifecycle, from establishing who a new person is through to recognizing them on every later visit, and the architecture it publishes describes identity data held on a distributed ledger. SenseCrypt starts at the sign-in and stops there.

That is a scope statement rather than a criticism. A program that has to establish identity from scratch on day one is buying two jobs, and a vendor that covers both can quote for both.

What SenseCrypt offers instead is a single ceremony with nothing softer parked behind it, and the identity provider in the same product rather than beside it.

Face verification runs on the enrolled phone

For both mobile-app methods, capture, liveness and comparison stay on the user's own handset. Nothing is uploaded for a server to check against a gallery, and no gallery exists for it to be checked against.

Identity provider capabilities are included

Applications integrate over OIDC, OAuth 2.0 or SAML 2.0 with the service that runs the ceremony. There is no biometric service and identity provider to keep in step with one another.

Three ways to check the person

A scanned QR code completed in the companion app; a real FIDO2/WebAuthn passkey (ES256) presented by that app as a roaming authenticator; and a webcam variant for enterprise customers on a trusted network, arranged through sales@seventhsense.ai. This licensed on-premises method processes captures inside the customer deployment and does not add an enrolled-phone possession factor.

No shared secret in routine sign-in

Sign-in asks for no password and no shared code. On the passkey path, FIDO2/WebAuthn origin binding is what makes that path phishing-resistant, and we do not extend the claim past it. Phone sign-in also combines a live face check with a key bound to the enrolled device.

02

What the server stores

Every biometric vendor has an answer to this. Ask for the list rather than the reassurance, and compare the lists rather than the adjectives. Ours: IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.

The retained face token is quantum-safe, sealed, biometric-free and disposable. No face images or templates are retained in the documented phone flow. Tokens are tenant-bound and stored alongside the required account records.

ISO/IEC 24745:2022 sets out those properties for protected biometric references; ISO/IEC 30136:2018 sets out how the protection is measured. The result is a system we describe as biometric-blind: there is no gallery to steal, and nothing that resolves to a person's face to disclose or migrate.

Quantum-safe, revocable and renewable face token

The construction uses NIST 140-3 approved symmetric and hash primitives exclusively: AES-256-GCM, HKDF-SHA256, SHA-256. No proprietary or non-approved cryptographic primitives are used anywhere.

Hybrid post-quantum TLS in transit

Traffic runs over hybrid post-quantum TLS (X25519MLKEM768), so a recorded session is not a decryption problem deferred to a later decade.

Patent-pending face tokenization and Face PKI

Face tokenization and Face PKI are patent-pending.

Independent testing you can review

Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021: https://pages.nist.gov/frvt/reportcards/11/seventhsense_000.html. Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2.

03

Which identity problem are you solving?

If your hard problem is onboarding, 1Kosmos is addressing a job SenseCrypt does not do. Proving that a new person is who they claim to be, against documents and data sources, is a separate discipline from authenticating a returning user, and treating them as one purchase usually ends badly.

If your hard problem is that returning users can still be phished, socially engineered or helped through a soft recovery path, that is the job SenseCrypt was built for.

Most organizations have both problems and buy them separately. Deciding which one is urgent is more useful than comparing feature grids.

Identity proofing is outside this scope

SenseCrypt does not perform document-based identity proofing. Enrollment binds a face to an account you already consider legitimate, so whatever established that legitimacy stays your responsibility.

Federation avoids a migration

Registering SenseCrypt as an external IdP over OIDC or SAML 2.0 leaves your existing provider in place, along with the directory it holds, the policy it enforces, and every application already integrated against it.

Tokens carry roles. Your application enforces them.

Roles and permissions ride in the token; what they permit is decided by the application that receives them. Within the product itself, sign-in clears a default-closed group gate and console routes are protected by capability checks.

04

Four questions for both vendors

This page cannot settle the decision and neither can 1Kosmos's. What settles it is putting an identical short list of questions to both companies, refusing category words in reply, and reading the two sets of answers in the same sitting.

Our own answers follow, one under each question, in the form we would give them across a table.

Where does face verification run?

Nothing else moves the cost of a breach as far as this answer does. For both mobile-app methods, the comparison happens on the enrolled handset. The enterprise webcam method is the stated exception: there captures are processed inside the customer's isolated deployment.

What remains after enrollment?

Ask for an itemized inventory. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow.

What an attacker gains from a recorded session

If someone captures the traffic, what can they replay? Origin binding on the passkey path means an assertion relayed through a lookalike domain will not validate against the domain that matters. Phone sign-in also combines a live face check with a key bound to the enrolled device.

What checks protect account recovery?

A hardened front door is only as good as the softest way around it. There is no password to reset here. Pairing a new handset uses a single-use PIN, emailed and also texted where a mobile number sits on the record, and it plays no part in a routine sign-in. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.

05

Protocol coverage, limits and pricing

A seat is a dollar a month and twenty is the smallest order we take, which is where an estimate starts rather than where it lands. Non-exportable signing keys in a managed key service add twenty dollars per key per month, and the key cannot be copied out by anyone, including us. Beyond the three tenants or custom domains every account includes, each further one is ten dollars per month, and customer identity deployments meter monthly active users rather than registered accounts.

The trial runs thirty days and asks for no card. Two limits belong in the same paragraph as the price, because both surface during a proof of concept. End-user authentication keeps no operator-side single sign-on session, so each application sign-in is its own ceremony; the only browser session in the product belongs to the admin console. And the hash-chained tamper-evident log covers administrative actions in that console, while end-user sign-ins are recorded in a separate read-only activity stream that is not hash-chained.

  • OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126)
  • SAML 2.0 identity provider, and SCIM 2.0 (RFC 7644) provisioning for users and groups
  • FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone.
  • Liveness detection tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2
  • Face recognition evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021
  • Multi-tenant isolation, roles and permissions in the token, a default-closed group gate at sign-in

06

Compare the details

SenseCrypt and 1Kosmos, dimension by dimension
DimensionSenseCrypt1Kosmos
Product shapeIdentity provider with one sign-in flowPlatform spanning identity verification and passwordless authentication
Identity proofingNot in scopeIncluded in the published platform; see vendor documentation.
Where face verification runsOn the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.See vendor documentation
Stored on the server after enrollmentQuantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.See vendor documentation
Phishing resistanceOn the passkey path, via FIDO2/WebAuthn origin bindingSee vendor documentation
Application protocolsOIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBASee vendor documentation
List priceOne dollar per user per month, twenty-seat minimumVaries by plan

Product shape

SenseCrypt
Identity provider with one sign-in flow
1Kosmos
Platform spanning identity verification and passwordless authentication

Identity proofing

SenseCrypt
Not in scope
1Kosmos
Included in the published platform; see vendor documentation.

Where face verification runs

SenseCrypt
On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.
1Kosmos
See vendor documentation

Stored on the server after enrollment

SenseCrypt
Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.
1Kosmos
See vendor documentation

Phishing resistance

SenseCrypt
On the passkey path, via FIDO2/WebAuthn origin binding
1Kosmos
See vendor documentation

Application protocols

SenseCrypt
OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA
1Kosmos
See vendor documentation

List price

SenseCrypt
One dollar per user per month, twenty-seat minimum
1Kosmos
Varies by plan

07

Frequently asked questions

Does SenseCrypt do identity verification as well as authentication?

No. SenseCrypt authenticates returning users and does not perform document-based identity proofing. Enrollment binds a face to an account you have already decided is legitimate. If proofing a new person is part of the requirement, price it as a separate capability rather than expecting a sign-in product to cover it.

How does SenseCrypt sign a user in?

The user scans an on-screen QR code and completes the face scan in the companion app on their enrolled phone, or signs in with a real FIDO2/WebAuthn passkey held by that same app acting as a roaming authenticator. Liveness and matching run on the phone in both cases. An enterprise webcam method exists for trusted networks and is arranged through sales@seventhsense.ai. This licensed on-premises method processes captures inside the customer deployment and does not add an enrolled-phone possession factor.

What is stored about the user's face?

IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.

Which standards does SenseCrypt support?

OpenID Connect and OAuth 2.0 (RFC 6749) with PKCE (RFC 7636) and pushed authorization requests (RFC 9126), SAML 2.0 as an identity provider, SCIM 2.0 (RFC 7644) for provisioning, and CIBA for backchannel initiation. Role-based access control and multi-tenant isolation sit alongside them, with console and administrative actions written to a hash-chained, tamper-evident log. Financial-grade flows support FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.

What does SenseCrypt cost?

One dollar per user per month with a twenty-seat minimum. Non-exportable signing keys in a managed key service add twenty dollars per key per month, and tenants or custom domains beyond the three included cost ten dollars per month each. A thirty-day trial runs without a card.

Next step

The next level of detail depends on your stack, so the fastest route is a conversation.