Skip to main content
Book a call

Stop Deepfakes Without Stopping Customers.

Passive liveness, depth capture and synthetic-media detection, checked against both presentation and injection attacks. Built in-house, running inside the EEA.

A phone recording a face for a liveness check, with face match, liveness and deepfake checks around it and a verified result

Why fraud teams pick this engine

  • Passive first, gesture second

    Most checks run silently on texture and light. A brief zoom gesture is added because fixed-focus cameras cannot prove depth.

    • No blink or head-turn drill
    • Texture and light read silently
    • 3D map from a 2D camera
  • Built for a GDPR review

    Biometric data is a special category under GDPR. The controls are the product: your retention window, your deletion trigger.

    • Deletion the moment a decision returns
    • Retention window you configure
    • A named Data Protection Officer
  • Three ways to embed it

    Native SDKs for iOS and Android, a web widget, or the REST API behind your own screens. The checks are identical either way.

    • iOS, Android and web SDKs
    • Hosted flow needs no build
    • The API route is two endpoints

What the engine checks

Passive liveness, depth capture and synthetic-media detection, checked against both presentation and injection attacks. Built in-house, running inside the EEA.

  1. Facial matching

    The portrait from the document or the chip compared with the live capture, as vectors not pixels.

  2. Passive liveness

    Skin texture, micro-expressions and light absorption read in the background, no drill to perform.

  3. Depth capture

    A brief zoom gesture builds a 3D map, because most selfie cameras cannot autofocus to prove depth.

  4. Synthetic media

    Face swaps, generated faces and frame-boundary artefacts flagged before a decision returns.

  5. Injection attacks

    The capture channel is encrypted end to end, so a video fed to the browser is not a video we accept.

  6. Duplicate faces

    One face against every prior verification, so a name change is not a new identity.

What the capture actually does

  • Open a secure channel

    The capture stream is encrypted before the first frame, which is what closes the injection route.

    • Encrypted before the first frame
    • Injection route closed by design
    • No unencrypted frame exists
  • Read the face passively

    Texture, micro-expression and light-absorption checks run while the user simply holds the phone.

    • No blink or head-turn drill
    • Texture and light read passively
    • Runs while the user just waits
  • Ask for one gesture

    A short zoom in and out tracks facial keypoints against the background to build a depth map.

    • One short zoom gesture
    • Facial keypoints tracked
    • A real depth map, not a guess
  • Write the evidence

    The scores, the telemetry and the liveness video land in the audit trail, written once.

    • Scores written to the trail
    • Telemetry kept with the case
    • Liveness video stored once

Questions before a demo

What are your FAR and FRR?
Both are measured at a configurable decision threshold, and both move as you move it. We publish the figures under NDA rather than on a web page, because a rate quoted without its threshold is not a rate. Ask and you get the full curve.
Active or passive liveness?
Passive, with one exception. Texture, micro-expression and light checks need nothing from the user. Depth does, because most selfie cameras are fixed-focus and cannot prove a face is three-dimensional, so a brief zoom gesture stands in for autofocus.
Do you store raw images or templates?
That is your configuration, not our default. The audit trail can hold the liveness video as evidence, or the session can be wiped the moment a decision returns. Regulated buyers usually want the first; a privacy review usually wants the second.
Does this help with BIPA?
Not directly. The platform is built for European rules, processes inside the EEA, and is certified against EU standards. If you are onboarding in Illinois or California, the consent and retention controls will help, but the compliance frame we know is GDPR.
How fast can engineering ship this?
The hosted flow needs a session call and a webhook. The SDK route needs an app release, which is usually your constraint rather than ours. The REST route is two endpoints. What actually sets the date is your decision on thresholds and who reviews an exception.

Discover the future of identity verification

Book a demo or contact us — we'll show you how IDENTT fits your onboarding.

Book a call