Your face never leaves your device. Our servers store only a public key and verify a signature — never your biometric, never a password. There's no reusable secret to steal, which removes the entire class of attacks behind most account takeovers.
BioAuth separates device authentication from application authorization and returns only the service data needed for the configured workflow.
BioAuth is designed to reduce remote impersonation risk by combining supported device authentication with configurable liveness controls.
No security control eliminates every attack. Customers should choose assurance settings and layered safeguards appropriate to their use case.
Risk-appropriate assurance
BioAuth reduces authentication and impersonation risk; it does not promise that every attack or misuse is impossible.
BioAuth provides controls intended to support privacy-conscious deployments. Compliance depends on each customer's use case, configuration, notices, consent, retention, and jurisdiction.
We're happy to walk through our architecture, share our security whitepaper, or answer any questions your security team has.
CONTACT SECURITY TEAM →