ONLINE
LA--:--:--
ATL--:--:--
LDN--:--:--
LIVE WIRE
BIOAUTH SDK — Bio-Log In and Account Recovery with no humans and no backdoor, goes live September 15thENTERPRISE — Biometric + Persistent Liveness authority for human and agent work sessions, with logs and receipts. Launching Oct 15, 2026DEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027REGULATORS move on authoritative records — SEC proposes first transfer-agent modernization in ~50 years, contemplating authoritative onchain ownership recordsBIOAUTH SDK — Bio-Log In and Account Recovery with no humans and no backdoor, goes live September 15thENTERPRISE — Biometric + Persistent Liveness authority for human and agent work sessions, with logs and receipts. Launching Oct 15, 2026DEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027REGULATORS move on authoritative records — SEC proposes first transfer-agent modernization in ~50 years, contemplating authoritative onchain ownership records

We Can't Leak What
We Don't Have

Your face never leaves your device. Our servers store only a public key and verify a signature — never your biometric, never a password. There's no reusable secret to steal, which removes the entire class of attacks behind most account takeovers.

NO PASSWORD STORED·ON-DEVICE ONLY·PERSISTENT LIVENESS

Security outcomes,
not sensitive internals.

BioAuth separates device authentication from application authorization and returns only the service data needed for the configured workflow.

01BIOMETRICSRaw device biometric data is not sent to BioAuth in standard flows
02AUTHORITYScoped and revocable
03RECORDSSigned receipts for supported authorization events
04RECOVERYVerified and auditable

A Photo Can't
Produce a Valid Signature

BioAuth is designed to reduce remote impersonation risk by combining supported device authentication with configurable liveness controls.

No security control eliminates every attack. Customers should choose assurance settings and layered safeguards appropriate to their use case.

Risk-appropriate assurance

BioAuth reduces authentication and impersonation risk; it does not promise that every attack or misuse is impossible.

Privacy-conscious design,
customer-specific compliance.

BioAuth provides controls intended to support privacy-conscious deployments. Compliance depends on each customer's use case, configuration, notices, consent, retention, and jurisdiction.

01PRIVACYData-minimizing standard flows
02CUSTOMERSControl notices, consent, and retention
03SOC 2In progress
04LEGALDeployment-specific review required

Security Questions?

We're happy to walk through our architecture, share our security whitepaper, or answer any questions your security team has.

CONTACT SECURITY TEAM →