Skip to main content
FaceSign’s security architecture is built on a principle: tokenize first, analyze second. All biometric data passes through HSM tokenization at the point of ingestion, before it reaches the AI analysis layer. Raw video is never stored.

Six parallel AI models

Every verification session runs six AI models simultaneously. Each model analyzes a different dimension of the interaction, and their outputs are combined into a unified risk score. The models run independently and cannot influence each other’s analysis. Each produces its own confidence score. The platform combines these into a final risk assessment that your application receives via webhook.

Data flow

The path from user camera to your webhook follows a strict sequence designed to minimize exposure of raw biometric data:
Raw video and audio are processed in memory during the session and discarded at the tokenization stage. FaceSign never writes raw biometric media to disk or object storage.

Encryption

Data roles

FaceSign operates as a data processor under GDPR and a service provider under CCPA. Your organization is the data controller. This means: A Data Processing Agreement (DPA) is available on request. FaceSign also provides DPIA (Data Protection Impact Assessment) support materials for organizations that require them.

What FaceSign does not store

  • Raw video or audio recordings
  • Unencrypted biometric data
  • Personally identifiable information beyond what you explicitly send in the session payload
  • Session media after the tokenization stage

What FaceSign does store

  • One-way biometric fingerprint (for future RECOGNITION node matching)
  • Session metadata (timestamps, risk scores, node outcomes)
  • AI-generated transcript of the conversation
  • Tokenized biometric features used for analysis
All stored data is encrypted with AES-256 and subject to your configured retention policy. See Biometric Data Handling for retention periods.

Next steps

Biometric Data Handling

Retention periods, deletion rights, and data subject access.

Deepfake Detection

How interactive liveness achieves a 99% or higher catch rate.

Compliance

GDPR, CCPA, SOC 2, and PSD3 regulatory alignment.