FIDO2 / WebAuthn passkeys

Real passkeys prove the device. The live face proves the person

SenseCrypt is built on real FIDO2/WebAuthn passkeys (ES256). The passkey proves the device you hold, and a live-face check proves the person holding it. Two proofs, one sign-in.

How it works

A passkey and a live face, in one ceremony

Possession is the passkey's home turf. SenseCrypt adds the inherence factor, so the sign-in confirms who is present rather than only which device is present.

Passkeys prove the device

A passkey is an ES256 key pair registered to your account. It signs a fresh challenge at every sign-in, which proves you hold it without a reusable secret to type or hand over. SenseCrypt runs on real FIDO2/WebAuthn passkeys, not a password behind the scenes.

The live face proves the person

A passkey alone cannot tell who is holding the device. SenseCrypt adds a live-face check, so a sign-in proves the person, not only possession of the device.

Three ways to sign in

One platform, three front doors

The FIDO2 passkey path is the phishing-resistant one. Simple QR and Simple Webcam trade that origin binding for a different fit; pick the door that matches the deployment.

Simple QR

Mobile app

Scan the QR on screen, then complete a quick face scan in the SenseCrypt mobile app. The face is matched on your own device in the app.

FIDO2 passkeys

Roaming authenticator

Phishing-resistant path

Sign in with a real FIDO2/WebAuthn passkey (ES256) through the SenseCrypt roaming authenticator app on your phone. WebAuthn origin binding ties the sign-in to the real site, so a look-alike domain cannot replay it.

Simple Webcam

Enterprise

A face scan at the webcam of a trusted workstation, with no phone in the loop. Available to enterprise customers on their own SenseCrypt deployment.

Contact sales@seventhsense.ai

Phishing resistance

Phishing-resistant on the passkey path

On the FIDO2/WebAuthn passkey path, the browser and authenticator enforce the origin, so a stolen or replayed credential does not work against a look-alike domain.

WebAuthn origin binding ties each passkey to the real site, so a credential cannot be replayed against a look-alike domain.
There is no shared password, OTP, or push prompt for an attacker to intercept, relay, or fatigue.
Phishing resistance here is a property of the passkey path. The Simple QR flow uses a different ceremony and does not rely on WebAuthn origin binding.

No password to phish

Passwords get phished, replayed, and stuffed. A passkey signs a fresh challenge instead of sending a secret, so there is no reusable secret to hand over, and the live-face check keeps a stolen device from standing in for its owner.

Mapped to NIST guidance, not certified

The passkey path is designed around the ideas in NIST SP 800-63B: an origin-bound authenticator that resists phishing, paired with verification of the live person. That is our own mapping, not a certification, and we do not claim an assurance level.

Your biometrics

Matched on your own device, in the app

In the Simple QR and passkey flows, your face is matched on your own device in the SenseCrypt app. Simple Webcam, for enterprise customers, works differently: a trusted workstation's webcam captures the face and the customer's own SenseCrypt deployment checks it, so that match does not run on your phone (contact sales@seventhsense.ai).

We never store your face image or biometric template, only a sealed, unlinkable, non-reversible token derived from your face that even we cannot reverse, and which contains no PII.

Built on open standards

The specs it is built on

Real FIDO2/WebAuthn passkeys with ES256 signing, issued through a standards-based identity provider that speaks OpenID Connect and OAuth 2.0.

Keep your passkeys. Add the person

Sign in with a real FIDO2 passkey and a live-face check, phishing-resistant on the passkey path.