NIST FRTE since 2021
Evaluated under Seventh Sense's own name — 1:1 (Jul 2024) and 1:N (Sep 2024).
"Designed to be" and "engineered to be" are deliberate: these are properties of our construction, stated as such.
Revoke and reissue a SensePrint through the registry. Credential revocation does not delete personal data, and offline verifiers need updates to learn about revocation. The architecture whitepaper documents the full lifecycle.
IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Administrator photo provisioning processes the image transiently; the licensed on-premises webcam method processes live captures inside the customer deployment.
A live biometric generates post-quantum PKI key-pairs in memory. Store the public keys; the private keys exist only during face sign or face decapsulate operations and are never stored. IdP retains encrypted tenant signing keys and uses classical ES256 for OIDC federation. Device and infrastructure keys have their own custody rules. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.
SenseCrypt PKI generates post-quantum ML-DSA and ML-KEM key-pairs in memory, retains public keys, and never stores the private keys. IdP retains encrypted tenant signing keys and uses classical ES256 for OIDC federation. SenseCrypt IdP supports FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA for financial-grade flows. Protocol support does not itself establish certification or FIPS module validation. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.
Credentials are designed for default unlinkability across services. Optional consented linkage is a separate configuration, and account or integration metadata can still identify the person.
For the face-derived key ceremony, our own presentation-attack detection runs at capture before that key is recreated. This does not describe the creation of every device or infrastructure key. We publish no PAD performance numbers.
Yes — docs.sensecrypt.com, with Python, REST, and native mobile (Android & iOS) SDKs you can read today.
Yes — Seventh Sense entered NIST FRVT in 2021 and continued in the evaluation program now divided into FRTE and FATE. This is recognition-algorithm evaluation, not certification of the whole platform.
Evaluated under Seventh Sense's own name — 1:1 (Jul 2024) and 1:N (Sep 2024).
SenseCrypt Face PKI supports FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA).
Four SenseCrypt patent families filed (PCT), plus a granted US patent (US10621440B2).
docs.sensecrypt.com — Python, REST, and native mobile (Android & iOS), readable before you talk to sales.
Presentation-attack detection applied at capture before a face-derived key is recreated. Liveness tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2, within the tested component and attack conditions; this does not certify every integration or cover all injection attacks.