ONLINE
LA--:--:--
ATL--:--:--
LDN--:--:--
LIVE WIRE
FACEIN.ID SDK — passwordless login for your app — targeting public launch Friday, July 31, 2026HUGGING FACE confirms a breach exposing internal datasets and credentials — another reminder that stored secrets are the targetDEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027FACEIN.ID SDK — passwordless login for your app — targeting public launch Friday, July 31, 2026HUGGING FACE confirms a breach exposing internal datasets and credentials — another reminder that stored secrets are the targetDEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027

We Can't Leak What
We Don't Have

FaceIn.id uses a zero-knowledge architecture where your biometric data never leaves your device. Our servers verify proofs, not biometrics. Even if we were breached, there's nothing to steal.

ZERO-KNOWLEDGE·ON-DEVICE ONLY

Zero-Knowledge
By Design

Your face or fingerprint is processed on your device. Only a mathematical proof — never your biometric data — is sent to our servers. No data to phish or hack.

01DATABiometrics never leave device
02ENCRYPTIONAES-256-GCM · ECDSA P-256
03COMPLIANCEBIPA · GDPR · CCPA
04TRANSPARENCYPublished Security Model
05SOC 2In Progress
01

Your Device

Camera or fingerprint sensor captures biometric → Device's secure biometric hardware generates template → Template stored in Secure Enclave / StrongBox

✓ RAW BIOMETRIC DATA NEVER LEAVES THIS BOUNDARY
↓ ZERO-KNOWLEDGE PROOF (TLS 1.3) ↓
02

FaceIn.id Servers

Receives mathematical proof → Verifies proof validity → Issues authentication token → Never processes biometric data

✓ SERVERS SEE PROOF, NOT FACE — MATHEMATICALLY IMPOSSIBLE TO RECONSTRUCT
↓ AUTH TOKEN (SIGNED JWT) ↓
03

Your Application

Receives auth token → Verifies with FaceIn.id API → User is authenticated → No password involved at any step

Defense in Depth
Layered Security Model

Three independent security layers protect every authentication event. Each layer operates autonomously — compromise of one does not affect the others.

01DEVICESecure Enclave · Biometric
02NETWORKTLS 1.3 · Certificate Pinning
03APPLICATIONZero-Knowledge · ECDSA
Device Layer
  • Face & fingerprint detection + liveness check
  • Biometric template generation
  • Secure Enclave / StrongBox storage
  • On-device matching engine
Communication Layer
  • TLS 1.3 with certificate pinning
  • Zero-knowledge proof generation
  • End-to-end encrypted channels
  • Challenge-response authentication
Server Layer
  • Proof verification only (no biometric data)
  • User identity tokens (opaque IDs)
  • Session management & rate limiting
  • Audit logging & anomaly detection

Stolen Phone?
Your Accounts Stay Locked.

Phone theft is rising in cities worldwide — moped snatching, grab-and-run. FaceIn turns a stolen phone from an identity catastrophe into a hardware inconvenience.

01BIOMETRICSOn-device only · Never transmitted
02KEYSBound to Secure Enclave
03REVOCATIONInstant remote lock
04RECOVERYProprietary identity-restoration via MCR

Without FaceIn

A thief grabs your unlocked phone:

  • Chrome/Safari autofill exposes every saved password
  • Email accounts — open. Password resets for everything else
  • Banking apps — often accessible via saved sessions
  • Amazon, social media, cloud storage — all compromised
  • One stolen phone = full identity breach

With FaceIn

A thief grabs your unlocked phone:

  • They can see what's on screen — and that's it
  • Every account login requires the owner's face or fingerprint
  • No saved passwords to steal — biometrics can't be copied
  • Banking, email, shopping — all locked behind your biology
  • One stolen phone = a hardware inconvenience, not a life crisis

The real-world difference

Urban phone theft targets unlocked phones specifically because a stolen unlocked device is a skeleton key to your entire digital life. FaceIn breaks that assumption. The phone is just glass and silicon without the owner's face.

A Photo Can't
Produce a Valid Signature

FaceIn never sees your face. Your device performs the biometric check and returns a cryptographic attestation; FaceIn verifies that attestation. A spoof — photo, video, mask, or deepfake — that fails your device's check never produces a valid signature, so it never becomes a login.

Every sign-in uses a fresh, single-use challenge, so a captured or replayed signature is worthless. There is no face template or image on our servers to copy, and nothing about the login can be reused.

Encryption
Standards

Industry-standard cryptographic primitives. No proprietary algorithms. No security through obscurity.

01AES-256-GCMEncrypts vault entries, user preferences, and local biometric templates on device.
02ECDSA P-256Signs cryptographic attestations and device verification challenges.
03ECDH (X25519)Establishes encrypted channels between device and server.
04HKDF-SHA256Generates per-session encryption keys from device-server handshake.
AES-256-GCM

Symmetric encryption for data at rest. NIST-approved, used by the US government for classified data.

Used for: Encrypts vault entries, user preferences, and local biometric templates on device.

ECDSA P-256

Elliptic curve digital signatures for authentication proofs. Same algorithm securing TLS certificates worldwide.

Used for: Signs cryptographic attestations and device verification challenges.

ECDH (X25519)

Elliptic curve Diffie-Hellman for secure key exchange. Generates ephemeral session keys.

Used for: Establishes encrypted channels between device and server.

HKDF-SHA256

HMAC-based key derivation function. Derives unique encryption keys from shared secrets.

Used for: Generates per-session encryption keys from device-server handshake.

Built for the Strictest
Regulations

FaceIn is designed for full compliance with global privacy and biometric data regulations from day one.

01BIPAIn Progress · Illinois
02GDPRIn Progress · EU/EEA
03CCPAIn Progress · California
04SOC 2In Progress
BIPAIn Progress

Illinois Biometric Information Privacy Act

FaceIn.id never collects, captures, stores, or transmits biometric identifiers to our servers. All biometric processing occurs exclusively on-device, meeting BIPA's strictest requirements by architectural design.

GDPRIn Progress

General Data Protection Regulation (EU)

Built with data minimization, purpose limitation, and privacy-by-design principles. Users have full control: access, portability, deletion, and the right to be forgotten — all self-service.

CCPAIn Progress

California Consumer Privacy Act

FaceIn.id provides all CCPA-mandated disclosures, opt-out mechanisms, and data deletion capabilities. We do not sell personal information.

SOC 2 Type IIIn Progress

Service Organization Control 2

Currently undergoing SOC 2 Type II certification for Security, Availability, and Confidentiality trust service criteria. Expected completion Q3 2026.

Security Questions?

We're happy to walk through our architecture, share our security whitepaper, or answer any questions your security team has.

CONTACT SECURITY TEAM →