01
One biometric method or several?
Veridium's buyer already owns an identity stack and is adding biometric authentication to it, with more than one biometric available to add. Our buyer is replacing the stack, and the face is the only door into what replaces it. Two different products, shortlisted together because they compete for the same budget line.
The argument for several modalities is an argument about uneven workforces. Consider a plant floor where hands are gloved all shift, a trading desk with tape over every webcam, a role that never once puts a face in front of a lens. Where any of that describes a real group of employees, per-group modality selection outweighs everything else discussed on this page.
That selection is not something SenseCrypt can offer, and it is better read here than discovered halfway through a rollout.
The face is matched on the enrolled phone
For both mobile-app methods, capture, liveness and comparison stay on the user's own handset. The device being signed in to, browser or kiosk or shared desktop, is never enrolled.
Identity protocols run in the same service
Every endpoint an application touches, OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0, CIBA, belongs to the service that also runs the ceremony. Nothing has to be held at a matching version with a separate biometric product. Financial-grade flows support FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA.
No shared secret for a fake page to collect
Nothing is typed at sign-in and nothing is copied from a screen, so a convincing imitation of your login page has no shared password to harvest. Where the phishing-resistance claim holds, on the passkey path, origin binding under FIDO2/WebAuthn is the mechanism delivering it. Phone sign-in also combines a live face check with a key bound to the enrolled device.
Assess the limits of each sign-in method
A single ceremony has one enrollment flow, one capture path and one recovery path to operate. Fewer moving parts is an operational argument as much as a security one.
02
What the server holds after enrollment
Whichever modality you choose, ask the vendor what remains on a server once a user is enrolled, and ask for a list. Ours: IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.
The retained face token is quantum-safe, sealed, biometric-free and disposable. No face images or templates are retained in the documented phone flow. Tokens are tenant-bound and stored alongside the required account records. ISO/IEC 24745:2022 defines those properties for a protected biometric reference; ISO/IEC 30136:2018 defines how the protection is measured.
This is what the word biometric-blind carries. An auditor asking what biometric data your organization holds gets a short answer, and an attacker taking the datastore gets nothing that resolves to a face.
Quantum-safe, revocable and renewable face token
The construction uses NIST 140-3 approved symmetric and hash primitives exclusively: AES-256-GCM, HKDF-SHA256, SHA-256. No proprietary or non-approved cryptographic primitives are used anywhere. No public-key assumption sits inside it waiting on a future machine.
Hybrid post-quantum TLS in transit
Sessions run over hybrid post-quantum TLS (X25519MLKEM768), so recorded traffic is not a decryption problem deferred to whenever the NIST FIPS 203/204/205 era arrives in earnest.
Published independent testing
Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021: https://pages.nist.gov/frvt/reportcards/11/seventhsense_000.html.
Patent-pending face tokenization and Face PKI
Face tokenization and Face PKI are patent-pending.
03
Compare vendor and product scope
Veridium remains an independent company, which some buyers value: a direct line to the roadmap and a contract with the organization that builds the product. That is a legitimate reason to choose a vendor and it has nothing to do with cryptography.
SenseCrypt is also independent, and considerably younger. What it offers is not more choice but less: one ceremony, hardened, with the identity provider in the same product.
Abstractly, neither shape wins. Their failure modes differ, their running costs differ, and the population being covered usually decides which of the two risks is easier to carry.
Which capture methods do you need?
Supporting many modalities means keeping many enrollment flows, many capture paths and many failure modes in working order simultaneously. Supporting one means keeping one of each, with nothing gentler positioned behind it.
Federate rather than migrate
Registered as an external IdP over OIDC or SAML 2.0, SenseCrypt sits behind whatever provider you run now. Directories, policies and integrated applications are left exactly as they were.
Tokens carry roles. Your application enforces them.
What the token carries is roles and permissions; what they permit is decided by the application reading them. Internally, sign-in passes a default-closed group gate and console routes sit behind capability checks.
04
Ask both vendors these four questions
Two products with almost nothing in common can earn identical ticks in a comparison table, this one included. Four direct questions cut through that faster, and they are the questions we would be asking if the roles were reversed.
Put them to us as well. What follows under each is the answer we give in person, set down here so the two can be checked against each other.
Where does face verification run?
A handset, or a vendor's servers. No other answer moves the blast radius of a breach as far. For both of our mobile-app methods, the comparison happens on the phone in the user's hand.
What does the server retain?
Ask for an itemized inventory. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow.
Which users cannot use this method?
No biometric covers everybody. A face needs a phone, a working camera and a user prepared to enroll it. Make every vendor name the group its method cannot reach, and treat an answer of nobody as a reason to keep asking.
How does account recovery work?
The way back in is usually the weakest part of any hardened front door. Nothing here can be reset, because no password exists, and the PIN that pairs a replacement handset plays no part in a routine sign-in. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.
05
Supported standards and pricing
A dollar per seat per month, twenty seats minimum, is where an estimate opens rather than where it settles. Non-exportable signing keys in a managed key service cost twenty dollars per key per month, and the key cannot be copied out by anyone, including us. Every tenant or custom domain beyond the three an account already includes adds ten dollars a month, and customer identity deployments meter monthly active users rather than registered accounts.
The trial runs thirty days and asks for no card. Two limits stated up front: end-user authentication keeps no operator-side single sign-on session, so each application sign-in is a fresh ceremony and the only browser session in the product belongs to the admin console; and the hash-chained tamper-evident log covers administrative actions there, while end-user sign-ins are recorded in a separate read-only activity stream that is not hash-chained.
- OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126)
- SAML 2.0 identity provider, and SCIM 2.0 (RFC 7644) provisioning for users and groups
- FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone.
- Real FIDO2/WebAuthn passkeys (ES256) through the companion app acting as a FIDO CTAP 2.1 roaming authenticator
- Liveness detection tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2
- Multi-tenant isolation, roles and permissions in the token, a default-closed group gate at sign-in
06
Compare the details
| Dimension | SenseCrypt | Veridium |
|---|---|---|
| Product shape | Identity provider with one sign-in flow | Multi-modal biometric authentication for the enterprise |
| Biometric modalities | Face only | Multiple methods; see vendor documentation. |
| Where face verification runs | On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows. | See vendor documentation |
| Stored on the server after enrollment | Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. | See vendor documentation |
| Phishing resistance | On the passkey path, via FIDO2/WebAuthn origin binding | See vendor documentation |
| Application protocols | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA | See vendor documentation |
| List price | One dollar per user per month, twenty-seat minimum | Varies by plan |
Product shape
- SenseCrypt
- Identity provider with one sign-in flow
- Veridium
- Multi-modal biometric authentication for the enterprise
Biometric modalities
- SenseCrypt
- Face only
- Veridium
- Multiple methods; see vendor documentation.
Where face verification runs
- SenseCrypt
- On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.
- Veridium
- See vendor documentation
Stored on the server after enrollment
- SenseCrypt
- Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.
- Veridium
- See vendor documentation
Phishing resistance
- SenseCrypt
- On the passkey path, via FIDO2/WebAuthn origin binding
- Veridium
- See vendor documentation
Application protocols
- SenseCrypt
- OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA
- Veridium
- See vendor documentation
List price
- SenseCrypt
- One dollar per user per month, twenty-seat minimum
- Veridium
- Varies by plan
07
Frequently asked questions
Does SenseCrypt support fingerprint or other biometrics?
No. Face is the only modality, and there is no password fallback behind it. That is a deliberate design decision rather than a roadmap gap: a single hardened path has no weaker route to attack instead. If your population needs more than one modality, a multi-modal vendor is the correct answer and we would say so on a call.
How is SenseCrypt different from Veridium?
Veridium provides biometric authentication into an identity stack you already run, across more than one modality. SenseCrypt is the identity provider itself, with one face-based ceremony and OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA served by the same product. The comparison is really between a component and a system.
What happens to users who cannot use face login?
They need a route outside the product, because there is no password fallback inside it. In practice that means issuing a suitable device, using the enterprise webcam method on a trusted network, or keeping a different method for that group in the identity platform sitting in front of SenseCrypt. Plan the exceptions before the rollout. This licensed on-premises method processes captures inside the customer deployment and does not add an enrolled-phone possession factor.
Does SenseCrypt store biometric data?
IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.
Can we trial it against a small group first?
Yes, and it is the sensible approach. Register SenseCrypt behind the provider you run now as an external IdP, point one application or one group at it, and leave everyone else on their existing method. The thirty-day trial takes no card.