Seventh Sense
TechnologySenseCrypt / The underlying primitive

A signing key your face recreates.
Never retained.

A live biometric generates post-quantum PKI key-pairs in memory. Store the public keys; the private keys exist only during face sign or face decapsulate operations and are never stored. Use the stored public keys with standard cryptographic libraries supporting the chosen algorithms to verify signatures or perform encapsulation. Face decapsulation regenerates the private key transiently. IdP retains encrypted tenant signing keys and uses classical ES256 for OIDC federation. SenseCrypt IdP supports FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA for financial-grade flows. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.

Fig. — derived at usePKI
AT RESTMOMENT OF USEAT RESTPRIVATE KEY: GENERATED · USED · DISCARDED
PKI: public keys retained · private keys transient
The platform — SenseCrypt

A person-bound
root of trust.

In the PKI flow, a live biometric generates post-quantum key-pairs in memory. Retain the public keys for verification and encapsulation. The private keys exist only during face sign or face decapsulate and are never stored. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.

≥256BITS
Residual-entropy construction target

The entropy figure is a construction target, not a measurement or NIST certification. In PKI, public keys are stored and private keys exist only during face sign or face decapsulate. Enrollment artifacts, certificates and infrastructure keys have separate lifecycle requirements. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.

Four disciplines — fused into one primitive

ML
Machine learning

A high-dimensional random projection that separates genuine and impostor margins by design.

PQC
Post-quantum

ML-DSA (FIPS 204) supports signatures; ML-KEM (FIPS 203) supports encapsulation and decapsulation. Store the public keys for standard library use. Face sign and face decapsulate generate the private keys transiently. Algorithm support is not module validation.

ZK
Zero-knowledge

STARK-based, transparent setup — no trusted ceremony to compromise. Post-quantum security depends on the full construction and parameters.

POLAR
Soft-decision ECC

Confidence-weighted decoding that tolerates realistic face drift — with a minimum 256-bit residual-entropy construction target.

The moatCompetitors pick one discipline. We fused all four to target the residual-entropy threshold.
Post-quantum, precisely

Post-quantum design. Clear algorithm boundaries.

In PKI, the live biometric generates key-pairs for post-quantum algorithms such as ML-DSA and ML-KEM. Post-quantum protection comes from those algorithms; the never-stored private-key lifecycle is a separate property.

IdP retains encrypted tenant signing keys and uses classical ES256 for OIDC federation. SenseCrypt IdP supports FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA for financial-grade flows. These capabilities do not imply post-quantum IdP federation or FIPS module validation. PKI has a separate post-quantum key-pair lifecycle.

Identity continuity

Person-bound, not device-bound.

SenseCrypt connects identity to the enrolled person. IdP recovery still requires verified email, a new device key and face verification using biometric-free, disposable face tokens. Lume data still needs backups. PKI key generation tolerates biometric change within the evaluated range, and sealed enrollment records require lifecycle management.

Capture assurance

Check for a live person before deriving the key.

The PKI operation first checks the live biometric within the evaluated presentation-attack detection scope, then generates the post-quantum key-pair in memory. Private keys exist only during face sign or face decapsulate; public keys are retained for standard verification and encapsulation.

PRINTED QRSEALED SENSEPRINTLIVE FACEVERIFYOFFLINE123VERIFIEDNO CALL HOMEPRINTED QRSEALEDSENSEPRINTLIVE FACE12VERIFYOFFLINE3VERIFIEDNO CALL HOME
Offline verification: A SensePrint can be carried as a printed QR. A verifier with a camera checks the live person against the sealed credential on the spot, fully offline. No call home, because no server holds a biometric to call.
Evaluation & IP

Review our evaluations and patent portfolio.

FRTE

NIST FRTE since 2021

Our biometric recognition has been evaluated in NIST FRTE under Seventh Sense's own name since 2021 — most recently in the 1:1 track (July 2024) and the 1:N track (September 2024). We submit under our own name so results are checkable, not inherited from a licensed algorithm.

Footnote: ranked among the top 10 in NIST FRVT, Q1 2022.

PCT

A patent-pending portfolio

The cryptographic design is protected by four SenseCrypt patent families filed (PCT), and the split-verification CA in PKI is patent-pending.

SDK

Explore the documentation and SDKs.

Explore Python, REST, Android and iOS references at docs.sensecrypt.com. Review post-quantum algorithms and their exceptions in the architecture whitepaper.