01Industries · Financial services
Branch staff share desktops; customers approve payee changes in the app. SenseCrypt signs both in with a live face and files every approval as audit evidence.
01The ceremony
The source of trust you already hold
Activate once on their own phone; no password ever exists
App, action, payee, amount
OIDC or CIBA, with a person-level log
02The outcomes
Customers approve every sign-in on the phone in their pocket. No passwords, no codes to type, and the same identity however they bank.
The KYC photo you already collected becomes the enrollment. Customers are passwordless from day one, with no sign-up ceremony to abandon.
Before a payee change or a large transfer, the prompt spells out the payee and the amount, and only the enrolled customer's live face can approve it. There is no SMS code to intercept.
Serve the sign-in ceremony from auth.yourbank.com with your branding, so customers never leave your name.
The desk is theirs in seconds: staff scan the on-screen code and glance at their own phone. The workstation needs no enrollment and holds no credentials.
SCIM keeps the directory in sync on its own: joiners are provisioned before they arrive, and leavers are revoked the day they leave.
If an app speaks OIDC or SAML, it already speaks SenseCrypt: one identity across the stack you run today, not the one you'd have to rebuild.
One tenant per corporate client: users, roles, branding, and audit trail all kept separate.
03The failure modes
Every channel runs its own MFA tool: another vendor, another budget line, another queue of tickets.
Codes and redirects slow every transaction and drive abandonment. They still get phished anyway.
Branch and call center staff rotate through shared desktops all day, and the passwords rotate with them.
Password vaults and scattered PII make banks the richest target, and every breach a disclosure event.
A passkey proves a device was unlocked, not who held it; on shared branch machines the person stays unproven.
Reviews and regulators ask who accessed what and when. A shared credential has no name to give.
04The compliance map
There is no password vault and no biometric database behind sign-in. The face is compared on the device; only a signed proof travels. The stored face token keeps the face unknown: it can't be linked across services or reversed into a face. And for SCA-style step-up, a live face adds a true inherence factor.
A payee change or a large transfer prompts with the exact amount and payee named, and the signature it produces is bound to both: the binding Article 5 of the EBA's technical standards calls dynamic linking.
Read the sourceFederal guidance is explicit: manually entered one-time codes are not phishing-resistant. Approval is a live face on the enrolled phone for staff and customers alike, so a phishing page has no code to collect.
Read the sourceFace matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)
Bring your next audit's control list and check it against the architecture.