Privacy-First Digital Identity

Biometric
verification,
without biometric
storage.

Help your organisation authenticate users with face, fingerprint and iris verification — without creating biometric databases, increasing privacy risk, or expanding your compliance obligations.

/ No database
No biometric database to protect
/ Privacy
Privacy-first identity verification
/ Ownership
User-controlled identity tokens
Designed for Government
Designed for Healthcare
Designed for Financial Services
Designed for Enterprise
Privacy by Design
GDPR-aligned principles
Data minimisation
No biometric storage
The problem

The hidden cost of
storing biometrics.

Traditional biometric systems give you strong authentication — but only by collecting and retaining data that can never be reset if it leaks. That trade-off creates three problems every security and compliance team eventually has to answer for.

/01

Security risk

Biometric databases become high-value breach targets. A leaked face or fingerprint can never be changed — the exposure is permanent.

/02

Compliance burden

Sensitive biometric records increase governance obligations under GDPR, BIPA, CCPA and similar frameworks — more to classify, secure, disclose and delete.

/03

User trust

People are increasingly uncomfortable with permanent biometric storage — and slower to adopt services that demand it.

Facenition removes all three.

The solution

What makes Facenition
different.

FaceID, Okta, Microsoft, Entrust and traditional biometric platforms all rely on collecting or storing biometric data somewhere. Facenition is the only approach that delivers biometric-grade verification while holding no biometrics at all.

Verifies identity using face, fingerprint and iris

Stores no biometric data — ever

User-controlled identity tokens

Revocable, rotatable and expirable

Portable across organisations and vendors

Dramatically reduced privacy exposure

Biometric-grade assurance, with nothing for an attacker to steal.

How it works

Verify people.
Not biometric
databases.

Facenition fits into your existing identity flow and feels familiar to your users — while removing the liability you'd normally carry. Four steps, no biometric database.

/01

Enrol once

The user creates a privacy-preserving identity token from a face, fingerprint or iris reading. The biometric itself is never stored.

/02

Store token only

Your organisation keeps a revocable identity token instead of biometrics. There's no biometric database to secure, govern or worry about.

/03

Verify instantly

On return, a live reading regenerates the token on the user's device and matches it against the one on file — fast, strong authentication with no stored biometrics.

/04

Revoke anytime

Tokens can be rotated, expired or revoked instantly — something a leaked biometric can never be.

The model

One model carries
a liability. One doesn't.

The difference is simple enough to explain in a single diagram: traditional systems put a biometric database between your users and your organisation. Facenition replaces it with a revocable token.

Traditional model
/Person
User
/High-value target
Biometric database
/Holds the risk
Organisation
A permanent, irreversible breach liability
Facenition model
/Person
User
/Revocable
Identity token
/Stores token only
Organisation
No biometric storage — nothing to breach
Why security teams choose Facenition

Stronger identity.
Less liability.

Removing biometric storage doesn't just improve privacy — it changes your risk, cost and compliance profile in ways the whole business benefits from.

/01

Reduce breach impact

No biometric records to steal. A compromised token is revoked and reissued — not a lifelong exposure for every user.

/02

Lower compliance costs

Far less sensitive data to classify, govern and disclose, reducing the scope and cost of audits and reporting.

/03

Simplify data retention

No biometric lifecycle to manage — no enrolment archives, retention schedules or deletion workflows for biometric data.

/04

Improve user trust

Strong authentication without permanent biometric collection — easier for users to accept, and easier for you to adopt.

Use cases

Stronger identity.
Less liability.

Wherever an organisation needs to confirm who someone is — and would rather not hold their biometrics to do it — Facenition fits cleanly into the flow.

/01

Government

Citizen identity and digital services — verify people with confidence while collecting far less sensitive data to secure and answer for.

/02

Healthcare

Accurate patient verification without ever building a biometric database of the people you care for.

/03

Financial services

Customer onboarding and fraud prevention with strong identity assurance and far less privacy risk on your balance sheet.

/04

Workforce & access

Physical and digital access control without enrolling employees into a biometric record you then have to protect.

Other applications include SaaS platforms, digital identity ecosystems, compliance and audit workflows, and cross-organisation verification.

The comparison

Why not traditional
biometrics?

Passwords are weak and resettable. Traditional biometric systems are strong but store data that can never be reset. Here's how Facenition compares on the criteria buyers use to justify the decision internally.

PasswordsTraditional biometric systemsFacenition
Stores biometric datan/aYes — indefinitelyNever
Breach liabilityResettablePermanent & irreversibleNothing to expose
Right to deletionStraightforwardComplex — biometrics persistNo biometric to delete
Biometric lifecycle managementn/aRequired & ongoingNone needed
Compliance burdenModerateHeavyMinimised
Cross-platform portability
User ownership of identity
Revocation capabilityReset
Vendor independencePartial
Privacy-first design
Principles

Security and privacy,
by design.

  1. /I

    Data minimisation

    Collect and retain only an identity token — never the biometric behind it.

  2. /II

    Privacy by design

    Privacy is built into the architecture, not bolted on as a setting or policy.

  3. /III

    User-controlled identity

    The person decides how their identity is created, shared, separated and revoked.

  4. /IV

    Vendor independence

    Identity works across organisations and providers — never locked inside one vendor.

  5. /V

    Auditability

    Verifiable identity checks with a clean audit trail and far less sensitive data to govern.

Identity under user control

Give people control
over their identity.

Most identity systems put the platform — or the government — in charge of who you are. Facenition flips that. Because identity tokens are generated on demand and never tied to a stored biometric, the person decides how their identity is created, separated, shared and switched off. This is the difference between being verified and being owned.

/01

Multiple tokens

People can generate as many identity tokens as they need — one per service, or one per purpose — all from the same person, none linkable back to a biometric.

/02

Separate identities

Keep identities for different organisations cleanly separated, so a token used with one vendor reveals nothing about activity with another.

/03

Token expiration

Set tokens to expire after a defined period, so access naturally winds down instead of lingering indefinitely.

/04

Token revocation

Revoke a token instantly, anywhere it's been issued — cutting off access without re-enrolment or touching a biometric.

/05

Vendor independence

Identity isn't trapped inside one provider. Tokens work across vendors and systems, so users are never locked in.

/06

User-controlled privacy

The person — not the platform — decides what their identity is used for. Privacy becomes a default, not a setting buried in a policy.

Compliance & governance

Built to support modern privacy goals.

Facenition is designed to support modern privacy and compliance objectives through data minimisation and privacy-by-design principles. By holding far less sensitive information, organisations reduce their exposure and make governance simpler across every framework.

/Principle
Less exposure

When there is no biometric database, there is far less for an attacker — or an auditor — to find. Reduced data means reduced risk.

/Principle
Data minimisation

Organisations collect and retain only an identity token, in line with the data-minimisation expectations at the heart of modern privacy law.

/Principle
Privacy by design

Privacy is built into the architecture rather than bolted on, supporting frameworks such as GDPR, CCPA/CPRA and BIPA.

/Principle
Easier governance

Fewer sensitive records to classify, secure, disclose and delete — making audits, reporting and oversight more straightforward.

Enterprise security

Token-based by default.
Hardened throughout.

Security teams expect more than a privacy claim. Facenition is built on a token-based architecture with protection at every layer — and nothing sensitive at rest to protect in the first place.

Token-based architecture

No biometric storage

Encryption in transit

Encryption at rest

Audit logging

Revocation support

Integrations

Fits your existing
identity infrastructure.

Facenition is designed to slot into the systems you already run, so you can add privacy-first verification without rebuilding your identity stack.

SSO
Layer biometric assurance onto your single sign-on flows.
IAM
Strengthen identity and access management without storing biometrics.
CIAM
Privacy-first customer identity for onboarding and login.
Access control systems
Authenticate for physical and system access with revocable tokens.
Government identity platforms
Add verification to citizen and digital-service workflows.
Healthcare systems
Match returning patients without a biometric database.

Connecting a system we don't list yet? Integrations can be built to fit your environment — talk to our team.

Frequently asked

Plain answers to
honest questions.

Facial recognition systems capture and store biometric templates to identify people, often without their control. Facenition uses a biometric reading only to generate a privacy-preserving token on the user's device — the biometric is never stored, and the token can be revoked. You get the assurance of biometrics without holding the biometric.
Only a revocable identity token. There is no face, fingerprint or iris record on file. Tokens cannot be reversed into a biometric, and the user controls how they are issued, separated and switched off.
There is no biometric data to lose. A breached store contains only identity tokens, which cannot be reversed into a face, fingerprint or iris. Unlike a leaked biometric — which can never be reset — a compromised token is simply revoked and reissued.
Facenition is designed to fit into your existing identity infrastructure — SSO, IAM, CIAM, access control, and government or healthcare identity platforms. Verification layers onto your current flows, so you can add privacy-first authentication without rebuilding your stack. Integrations can be tailored to your environment.
Yes. Tokens can be rotated, set to expire automatically, or revoked instantly anywhere they've been issued — cutting off access without re-enrolment and without ever touching a biometric.
Yes. A person can generate as many tokens as they need and split them across organisations. Each token verifies the same person, but they cannot be linked together or traced back to a stored biometric — so activity in one place stays separate from another.
By holding far less sensitive data. With no biometric stored, you reduce exposure and governance scope under frameworks such as GDPR, CCPA/CPRA and BIPA. Facenition supports privacy objectives through data minimisation and privacy-by-design, making audits, retention and reporting simpler.
Why now

Why organisations are
rethinking biometrics.

The pressure to authenticate strongly is rising at the same time the cost of storing biometrics is climbing. That gap is exactly what Facenition closes.

  1. /01

    Privacy regulation is expanding

    Frameworks like GDPR, CCPA/CPRA and BIPA increasingly treat biometric data as a special category — raising the obligations attached to holding it.

  2. /02

    Biometric breaches are increasing

    As more systems collect biometrics, the databases holding them become higher-value — and permanently damaging — breach targets.

  3. /03

    Users expect stronger privacy controls

    People are more aware of what permanent biometric collection means, and increasingly reluctant to hand it over.

  4. /04

    Authentication has to get stronger — without growing liability

    Organisations need higher assurance than passwords provide, but can't keep absorbing the risk of storing more sensitive data to get it.

Ready to eliminate
biometric storage?

Deploy biometric verification without maintaining a biometric database. See it working, or talk to our team about where Facenition fits in your organisation.