Support the protocols enterprise customers require
SAML 2.0 with signed assertions, plus OIDC and OAuth 2.0 with PKCE and pushed authorization requests. You fill the section in rather than scheduling the work behind it.
Give enterprise customers the SSO and directory-led account lifecycle they require. SenseCrypt provides both as a service for your SaaS.
Enterprise buyers do not evaluate single sign-on. They require it. The security questionnaire asks whether you support SAML 2.0 and OIDC, whether provisioning is automatic, and whether their identity team keeps lifecycle control, and a no on any of those can end the conversation before pricing starts.
Building it yourself is not a sprint, it is a permanent commitment: SAML edge cases, metadata handling, key rotation, per-tenant key custody, and an audit story you have to defend to somebody else’s auditor. SenseCrypt IdP has launched as the identity layer your product fronts, so the questionnaire stops being an engineering roadmap: a cryptographically isolated tenant per customer, passwordless face sign-in for their people, and none of it priced as an enterprise upsell.
SAML 2.0 with signed assertions, plus OIDC and OAuth 2.0 with PKCE and pushed authorization requests. You fill the section in rather than scheduling the work behind it.
At around a thousand seats, manual user management is unacceptable to any IT organization, which is why SCIM 2.0 sits immediately behind SAML in the same questionnaires.
IdP retains encrypted signing keys per tenant, with generation, rotation and custody managed separately from PKI’s transient private keys. OIDC clients verify ES256 signatures using the tenant’s published public keys.
The industry habit is to lock single sign-on behind the most expensive tier, which the market has come to call the SSO tax: the control buyers need most, priced as a luxury. SenseCrypt’s per-user rate does not move when you turn security on, so offering enterprise sign-in to your customers does not force you to rebuild your own pricing around it.
That is the list rate, with a 20-seat minimum. Customer identities bill as monthly active users, so accounts that do not sign in during the month do not bill.
SAML, SCIM, CIBA, role-based access control and audit logs are in that rate. There is no security edition to upgrade into when a buyer asks for the thing they should always have had.
Thirty days, full feature set, no card. You can answer a live security questionnaire before you commit a budget line.
Each business customer has a separate tenant, issuer and encrypted tenant signing keys. OIDC uses classical ES256; SAML uses separate RSA keys and certificates. Applications enforce tenant isolation by validating the signature, issuer, audience and tenant context.
Branding follows the same boundary. Each tenant serves its sign-in surface from its own verified custom domains, up to 25 of them, so your customer’s employees authenticate on a page that looks and reads like the product they bought rather than like ours.
Enterprise buyers want lifecycle control in their own hands, and your engineers want it out of theirs. Delegated administration per tenant gives the customer’s IT team its own users, groups and roles without raising a ticket with you, which removes the support path that scales worst as you add logos.
Provisioning runs over SCIM 2.0 with per-tenant tokens, so their directory stays the source of truth and your product follows it.
Users, groups, filters and bulk operations, driven from the system their IT team already runs. Your product is not the place a leaver gets forgotten.
Deprovisioning severs device keys and IdP sessions. Your application must also enforce token expiry and end sessions it already holds.
Every console change appends to a tamper-evident audit trail, and person-level activity exports to CSV. That export is what their auditor will actually ask you for.
The people signing in are your customer’s employees, and they get the same ceremony as everyone else on SenseCrypt: enrollment from a photo on file or through self-signup gated to the customer’s email domains, then face sign-in from their own phone onto whatever device is in front of them.
This is the part that changes the security review rather than merely passing it. You are not offering single sign-on with the same phishable secret still sitting behind it. There is no password to stuff and no code to read out, and on the passkey path the FIDO2/WebAuthn signature is bound to your origin, which is what lets that path resist phishing.
Capture and face verification happen on the enrolled phone. IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Face tokenization and Face PKI are patent-pending.
Liveness has iBeta Level 1 and Level 2 presentation-attack testing to ISO/IEC 30107-3, covering the tested component and camera attack conditions. Face recognition entered the NIST evaluation in 2021, then FRVT and later split into FRTE and FATE, and is maintained through our latest submissions. That is evaluation, not certification.
Binding a new phone uses a one-time PIN sent to the mailbox, and by SMS when a mobile number is on file. Sign-in itself never asks for a code. Simple QR is not origin-bound; phishing resistance is specific to the passkey path.
Billing follows the shape of your business rather than a tier sheet, and a 30-day full-feature trial takes no card. Workforce seats bill on the period’s high-water mark, and external users bill as monthly active users in arrears, so a customer’s dormant accounts are not a line item you have to explain to anybody.
Two numbers decide your cost model: how many people actually sign in, and how many branded tenants and domains you run. The first tracks your revenue closely. The second does not, so size it against your expected customer count before you commit to a tenant-per-logo design.
Workforce seats are charged on the period’s peak, so adding staff mid-month does not turn into a reconciliation exercise at renewal.
Customer identities are counted as monthly actives after the fact. The ones that never signed in are not on the invoice.
Nothing in the rate changes when a buyer asks for SCIM, SAML or backchannel approvals, so a security requirement does not become a margin conversation.