Seventh Sense
Compare

SenseCrypt
Technical library

Identity platforms

SenseCrypt vs Ping Identity

Ping Identity is an enterprise identity platform serving workforce and customer identity, with a long-established position on the federation standards. SenseCrypt is an identity provider built around one ceremony, a face scan completed in a companion app on the enrolled phone. This page covers where each fits, and how to run SenseCrypt behind Ping.

7 sectionsSeventh Sense / SenseCrypt
On this page

01

Compare more than the face-login feature

Ping's portfolio now includes biometric authentication, following its acquisition of Keyless. The line that used to run between an enterprise identity platform and a biometric specialist has been crossed from both directions, so a shortlist built on it will never converge.

Three questions still do the work. Where does the match run. What remains on a server once enrollment is finished. And what is a captured artifact worth to an attacker who has it.

SenseCrypt gives the same answer to all three on every deployment, because there is one ceremony and nothing sits behind it as a fallback to answer differently.

Face verification runs on the enrolled phone

For both mobile-app methods, capture, liveness and comparison happen on the user's own handset. Nothing is sent to a server to be matched against a gallery, because there is no gallery.

What an attacker gains from a recorded session

The face token exchanged at sign-in is sealed and tenant-bound, and on the passkey path FIDO2/WebAuthn origin binding means a relayed assertion cannot be replayed against your real domain. Phone sign-in also combines a live face check with a key bound to the enrolled device.

Read a liveness certificate carefully

Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2, which covers artifacts presented at the camera such as a print or a mask. It says nothing about an injected video stream, which is handled separately by app attestation and device authenticity checks.

Independently evaluated recognition

Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021, published at https://pages.nist.gov/frvt/reportcards/11/seventhsense_000.html.

02

What the server holds after enrollment

A procurement team evaluating biometrics for an enterprise deployment usually asks the storage question last, when it should be first. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.

The retained face token is quantum-safe, sealed, biometric-free and disposable. No face images or templates are retained in the documented phone flow. Tokens are tenant-bound and stored alongside the required account records. ISO/IEC 24745:2022 describes and ISO/IEC 30136:2018 measures.

So the biometric risk register for a SenseCrypt deployment is short. There is no gallery to breach, biometric-free face tokens and account records to assess in a data subject request, and sealed, biometric-free, disposable face tokens and account records to assess on exit. That is what biometric-blind means in practice.

Quantum-safe, revocable and renewable face token

The construction uses NIST 140-3 approved symmetric and hash primitives exclusively: AES-256-GCM, HKDF-SHA256, SHA-256. No proprietary or non-approved cryptographic primitives are used anywhere. There is no public-key assumption inside the token for a future machine to break.

Hybrid post-quantum TLS in transit

Traffic runs over hybrid post-quantum TLS (X25519MLKEM768), which is the answer to recorded-now-decrypted-later traffic that US NSM-10 and the NIST FIPS 203/204/205 series set the timetable for.

Patent-pending face tokenization and Face PKI

Face tokenization and Face PKI are patent-pending.

Non-exportable signing keys

Token signing keys can be held as non-exportable keys in a managed key service. The key cannot be copied out by anyone, including us, which is a shorter sentence than most key custody sections need.

03

Broad platform or focused authentication?

Ping is an enterprise platform with a long record in workforce and customer identity, several deployment models, and the procurement history that large identity programs lean on. Where an identity program spans many systems, several protocols and a long approval cycle, that reach is what is being bought.

SenseCrypt is a service, delivered one way. If your requirement is on-premises or a specific hosting model, Ping covers deployment shapes we do not, and that is a straightforward difference rather than a debating point.

If biometric authentication is what brought you to a Ping conversation, ask where that line lands in the plan you are being quoted and on what timeline, because a capability folded into a large platform is seldom sold the way the standalone company sold it.

Compare deployment models

Ping offers more than one deployment model. SenseCrypt is delivered as a multi-tenant service. If a hosting constraint is part of your requirement, decide that before comparing anything else.

One sign-in method or a range of policy options

An enterprise platform expresses many authentication journeys. SenseCrypt expresses one, and its strength is that there is no second journey to be attacked instead.

Use federation to combine both

Ping accepts an external identity provider over OIDC and SAML 2.0. Face login can be added to the estate you already run without choosing between the two products at all.

04

Running SenseCrypt behind Ping

Organizations that run Ping seldom have displacing it on the table, and nothing here requires them to. External identity providers register over OIDC or SAML 2.0, which makes SenseCrypt a connection to configure rather than a product to swap in.

Ping keeps the directory, the policy, the application catalog and the audit history. Applications keep pointing at Ping. At sign-in the user is handed onward, the ceremony completes on the enrolled phone, and a standard token or assertion comes back for Ping to turn into the session it has always issued.

Setup is configuration on both sides: metadata or discovery endpoints, a client registration, claim mapping, and the policy that decides who is routed through the new path.

Start with a focused pilot

One application or one group is enough to learn what enrollment costs your support desk. Everything else stays on the current method until you decide otherwise.

Map the claims between providers

SenseCrypt emits roles and permissions in the token. Ping maps them into its own model, and your applications enforce what they always enforced.

The session stays with Ping

SenseCrypt keeps no operator-side single sign-on session for end users, so the session lifetime your applications rely on is still governed entirely by Ping.

05

Supported protocols and pricing

SenseCrypt is a standards-based identity provider that happens to authenticate with a face, rather than a biometric product with protocol support added afterwards. That distinction shows up in integration work: one service issues the token and runs the ceremony, so there is no second system to keep in step.

Two operating boundaries, stated in advance. End-user authentication keeps no operator-side single sign-on session, so each application sign-in is a fresh ceremony and the only browser session in the product belongs to the admin console. The hash-chained tamper-evident log covers console and administrative actions; end-user sign-ins are recorded in a separate read-only activity stream that is not hash-chained and offers no customer-facing chain verification.

Each seat is a dollar a month, with twenty seats as the smallest order. Non-exportable signing keys in a managed key service add twenty dollars per key per month, and the key cannot be copied out by anyone, including us. Tenants and custom domains past the three included in every account are ten dollars per month each. Customer identity deployments meter monthly active users, and the thirty-day trial takes no card.

  • OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126)
  • SAML 2.0 identity provider, for federation and for direct application integration
  • SCIM 2.0 (RFC 7644) provisioning for users and groups
  • FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone.
  • Roles and permissions in the token, a default-closed group gate at sign-in, capability checks on console routes
  • Tenant isolation, with three tenants or custom domains per account included.

06

Compare the details

SenseCrypt and Ping Identity, dimension by dimension
DimensionSenseCryptPing Identity
Primary sign-inFace scan in the companion app on an enrolled phoneSeveral authentication methods, varies by product and plan
Delivery modelMulti-tenant serviceMultiple deployment models, see vendor documentation
Where face verification runsOn the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.See vendor documentation
Stored on the server after enrollmentQuantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.See vendor documentation
Phishing resistanceOn the passkey path, via FIDO2/WebAuthn origin bindingVaries by method and configuration
Federation protocolsOIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBADocumented as supported
Use as an external IdPYes, SenseCrypt federates into Ping over OIDC or SAML 2.0Accepts external identity providers
List priceOne dollar per user per month, twenty-seat minimumVaries by product and plan

Primary sign-in

SenseCrypt
Face scan in the companion app on an enrolled phone
Ping Identity
Several authentication methods, varies by product and plan

Delivery model

SenseCrypt
Multi-tenant service
Ping Identity
Multiple deployment models, see vendor documentation

Where face verification runs

SenseCrypt
On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.
Ping Identity
See vendor documentation

Stored on the server after enrollment

SenseCrypt
Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.
Ping Identity
See vendor documentation

Phishing resistance

SenseCrypt
On the passkey path, via FIDO2/WebAuthn origin binding
Ping Identity
Varies by method and configuration

Federation protocols

SenseCrypt
OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA
Ping Identity
Documented as supported

Use as an external IdP

SenseCrypt
Yes, SenseCrypt federates into Ping over OIDC or SAML 2.0
Ping Identity
Accepts external identity providers

List price

SenseCrypt
One dollar per user per month, twenty-seat minimum
Ping Identity
Varies by product and plan

07

Frequently asked questions

Ping already offers biometric authentication. Why look at SenseCrypt?

Because the questions that decide this are not about whether a face is on the menu. They are about the machine that performs the comparison, the contents of the server once enrollment is done, and the resale value of a captured artifact. Ask those of both vendors. SenseCrypt matches on the user's enrolled phone for the mobile-app methods, keeps no face image or biometric template, and persists a sealed token alongside account records, device public keys, sessions and logs.

Can SenseCrypt run on-premises?

No. SenseCrypt is delivered as a multi-tenant service. If your requirement is an on-premises or specialized hosting model, that is a genuine reason to prefer a vendor whose product covers those deployment shapes, and it is worth settling before any other comparison.

How does SenseCrypt attach to an existing Ping deployment?

As an external identity provider over OIDC or SAML 2.0. Ping keeps the directory, the policy and the application catalog, and issues the session. SenseCrypt runs the authentication event: the ceremony completes on the enrolled phone and a standard token or assertion returns to Ping.

What exactly is stored about a user's face?

IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.

What does the iBeta certification cover, and what does it not?

Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2, which covers presentation attacks held up at the camera, such as a printed photo, a screen replay or a mask. It does not address an injected video stream that bypasses the camera. That case is handled by a different control: sign-in runs inside the SenseCrypt app on an enrolled phone, with app attestation and device authenticity checks at each ceremony.

What happens to our biometric data if we leave?

The retained-data inventory includes biometric-free, disposable face tokens, which are deleted with the account and processed within the configured authorized boundary. A migration away from SenseCrypt requires users to enroll with the next system; no face images or templates are transferred.

Next step

The next level of detail depends on your stack, so the fastest route is a conversation.