Seventh Sense
SenseCrypt PKI

Post-quantum keys. Generated by your live biometric.

Digital signingAvailable

Your live biometric generates post-quantum PKI key-pairs in memory. Private keys exist only during face sign or face decapsulate and are discarded afterwards. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them. Store public keys and use standard cryptographic libraries supporting the chosen algorithms for signature verification and key encapsulation.

Security scope
  • A live biometric generates post-quantum PKI key-pairs in memory. Store the public keys; the private keys exist only during face sign or face decapsulate operations and are never stored. Certificates, public keys and enrollment records remain; issuer and infrastructure keys have separate custody rules. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.
  • ML-DSA supports face signing and public-key signature verification. ML-KEM supports public-key encapsulation and face decapsulation with a transient private key. Use standard libraries supporting these algorithms. Algorithm support does not imply FIPS module validation or universal certificate compatibility.
Signed by a person
Certificate / X.509Human present.
Signature produced.
ML-DSA / FIPS 204
At the moment of use
  1. 01Live biometric
  2. 02Post-quantum key-pair generated
  3. 03Face sign or face decapsulate
  4. 04Private key discarded; public key stored
private keys never stored
PKI private keys exist in memory only during face sign or face decapsulate. Public keys are stored; certificates and issuer keys have separate lifecycle requirements. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.
The problem with stored private keys

Private keys generated from a live biometric.

Stored private signing keys require protection throughout their lifecycle. SenseCrypt PKI generates private keys from a live biometric only during face sign or face decapsulate. Public keys remain stored for verification and encapsulation. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.

PKI generates the post-quantum private key from the live biometric for face sign or face decapsulate. No stored copy of that private key is retrieved. Public keys remain stored and usable without regenerating the private key. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.

Face sign and face decapsulate

Generate the key-pair. Keep the public key.

A live biometric generates post-quantum PKI key-pairs in memory. Store the public keys; the private keys exist only during face sign or face decapsulate operations and are never stored. Face sign produces a signature that anyone holding the public key can verify with a compatible standard library. Encapsulation also uses the stored public key; face decapsulate regenerates the private key for that operation. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.

FIPS 203 · ML-KEM key establishmentFIPS 204 · ML-DSA signatures
From person to proof

How it works.

PKI: public and private key lifecycles

Explore the four stages.

01 / 04 Explore the stages

Begin with the person.

Your live biometric generates PKI private keys for face sign or face decapsulate. Private keys exist only during that operation.

PKI lifecycle: generate the post-quantum key-pair in memory, use the private key for face sign or face decapsulate, then discard it. Outputs go directly to relying party endpoints, without the IdP seeing them.

Signing tied to human presence.

Face sign uses a post-quantum private key generated in memory from the live biometric. The private key is never stored; the signature and public key remain available for independent verification. Applications must bind the signed data to the intended approval or document.

How split verification works.

Face tokenization and Face PKI: patent-pending

The split-verification design separates roles in establishing the enrolled person’s certificate. The person’s PKI private keys are generated in memory for face sign or face decapsulate and never stored. Public keys and certificates are retained; the CA’s issuer key has its own custody lifecycle. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.

Coexistence

Stored public keys. Standard cryptographic libraries.

Use stored PKI public keys with standard libraries supporting ML-DSA for signature verification and ML-KEM for encapsulation. Private-key face sign and face decapsulate use the biometric operation. IdP federation remains a separate integration.