Government and national eID
eIDAS 2.0 · DPDPAPainIssuer custody of biometric templates is a permanent breach surface.
SolveOffline-verifiable, revocable eID with no stored biometric — verify at a kiosk with a prepared supported verifier.
KYA gives each agent a verifiable credential authorized by a biometrically verified human. Record who authorized the agent, its scope and expiry. Connected applications enforce those permissions.
$ scope: trade.execute - max $10,000 - ttl 1hA biometric verifiable credential via SenseCrypt ZKP establishes the accountable human principal.
The human acts as CA and signs the Agent VC — embedding model hash, scope, and expiry.
A per-action key-pair from KDF(agent_cred, purpose), with a transient private key. This agent-credential flow is distinct from PKI’s live-biometric face sign and face decapsulate operations.
Connected tool calls signed — reducing reliance on API keys, OAuth, and bearer tokens where the integration supports this flow.
A credential is bound to a human and post-quantum signed at issuance. ~1500 bytes, no biometric images or plaintext template, unlinkable by default, revocable, and offline-verifiable with a prepared supported verifier.
SenseCrypt eIDA live face unlocks the credential — passing three integrity gates. Silent failure on any miss; the on-device flow returns no recovered secret on failure.
Liveness · on-deviceSenseCrypt ZKP supports zero-knowledge presentation and selective disclosure. SenseCrypt PKI generates post-quantum key-pairs from a live biometric, stores public keys, and never stores the private keys used during face sign or face decapsulate. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.
Prove · or · signAfter polar-code soft decoding, a CRC confirms the live face was close enough to the enrolled biometric. Wrong face → silent fail.
The authenticated tag verifies the recovery data and ciphertext were not tampered with. Tamper → silent fail.
The on-device Merkle root is verified against the issuer signature (ML-DSA-87). Forged credential → silent fail.
The construction is designed to recover the same seed as appearance changes, within its evaluated operating range.
Explore how the face-derived credential applies to six buyer groups, each with its own integration and deployment requirements.
PainIssuer custody of biometric templates is a permanent breach surface.
SolveOffline-verifiable, revocable eID with no stored biometric — verify at a kiosk with a prepared supported verifier.
PainPhishable SCA, MFA fatigue, and every bank rebuilding and storing KYC.
SolveFace-derived transaction signatures and reusable eKYC — the bank verifies signatures, never the face.
PainPassword-reset cost, shared terminals, and unmanaged BYOD endpoints.
SolvePerson-bound passwordless that survives lost phones, shared and unmanaged devices.
PainShared terminals, clinician switching, and phishable hard tokens for prescribing.
SolveFast auth with no local templates; the prescription itself a face-gated credential.
PainAgents act under borrowed credentials. No accountability, no provenance.
SolveHuman-authorized agent certificates with scope, expiry, and signed intent.
PainSeed-phrase recovery, sybil bots, and banned centralized iris custody.
SolveLive-face unlock of portable credentials; proof-of-personhood subject to the applicable regulatory requirements, zero biometric database.
The SenseCrypt stack spans an available consumer app and core developer SDK, a launched enterprise identity provider, and products offered through early access or design partnerships.
Four security apps in one, unlocked by your face — no master password, ever. MFA authenticator, post-quantum encrypted chat, password manager, and secure notes. Zero-knowledge by construction.
A multi-tenant OIDC issuer and SAML 2.0 IdP with SCIM provisioning. End users sign in with their face — verified on their own phone — instead of a password. Drops in above your existing IAM.
One wallet SDK and one verifier SDK. The verifier ships the STARK circuit and X.509 libraries; the wallet handles enrollment, recovery, and proof generation. Mobile, server, edge, and air-gapped.
Review the named standards, threat model and public research roadmap. Assess the engineering through the evidence and milestones we publish.
Core filing covering eID, SenseCrypt ZKP, SenseCrypt PKI, KYA, and refresh.
The underlying face engine, independently ranked globally in the Q1 2022 NIST FRVT result.
Residual entropy at realistic face error rates — by design.
ML · PQC · zero-knowledge · polar codes — no competitor combines all four.
The research roadmap sets out claims and milestones for external scrutiny.
Cryptography & ML architect. Co-founded tenCube (mobile security), acquired by McAfee / Intel.
10+ years in semiconductors. Co-founder of a publicly-listed venture. MBA, Cornell.