Loading demo…
Loading demo…
Catch presentation attacks before they reach your onboarding flow. Passive liveness identifies print, replay, and 3D mask attacks from a single frame — no challenge, no instructions, no added drop-off.
The model is trained and benchmarked, but we are not publishing a public demo for this one — an open liveness endpoint is an open target for people who want to probe it. Early access runs through design partners instead.
We run early access as a design-partner programme — you get API keys and we get feedback from a real integration before general release.
Face comparison asks whether two faces match. Liveness asks something prior to that: is this a real person, right now, in front of the camera? A system that only compares will happily match a photograph of the right person.
No challenge, no instructions, no head-turning. The user takes an ordinary selfie, which is the whole point — every instruction you add costs you completions.
Real skin has micro-texture that print and screen reproduction flatten out. Screens emit light uniformly; skin produces specular highlights that behave differently across the face.
Monocular depth cues separate a genuinely three-dimensional face from a flat surface held up to the camera, without needing a depth sensor or a second frame.
You get a liveness score from 0 to 1, a live/spoof verdict at your chosen operating point, and where the signal is clear enough, a classification of the spoof type.
ISO/IEC 30107-3 groups presentation attacks into families. The fourth row below is not a presentation attack at all — and that distinction matters more than it sounds.
| Attack | How it works | Detection signal |
|---|---|---|
| Print attack | A printed photograph, sometimes cut out around the eyes or bent to fake curvature. | Absent skin micro-texture, paper grain, flat depth response. |
| Replay attack | A photo or video played back on a phone or tablet screen. | Uniform screen emission, moiré patterning, display bezel and refresh artefacts. |
| 3D mask | A silicone, resin, or paper-craft mask worn over the face. | Material reflectance unlike skin, rigid regions where a face would deform. |
| Digital injection | Synthetic video fed in upstream of the camera, bypassing the sensor entirely. | Not visible in-frame — needs device attestation and capture-path integrity checks. |
Digital injection is the honest gap in every frame-analysis liveness model, ours included. If the attacker never presents anything to the camera, there is nothing in the image to catch. That defence lives in device attestation and capture-path integrity — covered in the liveness technical deep dive.
A vendor quoting one liveness number is telling you almost nothing. The two error rates trade against each other, so only a pair is meaningful.
Attack Presentation Classification Error Rate
Spoofs that got through. Lowering it means tightening the threshold, which rejects more real users.
Bona Fide Presentation Classification Error Rate
Genuine users wrongly rejected. Every point here is abandoned onboarding, and it is the cost nobody quotes.
The pair that actually means something
Our 0.8% BPCER is quoted at 5% APCER. Any single-number liveness claim is hiding one half of this.
Confirm the selfie is a real person before comparing it to the ID portrait, so a good spoof cannot produce a confident approval.
Gate high-value transactions and password resets behind a liveness check rather than an SMS code that can be intercepted.
Verify a genuine person is present during an exam or assessment, not a looped recording.
Re-establish identity when a user has lost their device, where a stolen photo is the most obvious attack.
In every one of these, liveness runs before face comparison. Reversing the order produces confident approvals of well-made spoofs.
The fundamentals — what liveness is, why it exists, and where it sits in a KYC flow.
ReadAttack taxonomy, ISO/IEC 30107-3 conformance, and the deepfake injection problem in detail.
ReadAvailable today: face comparison, face detection, and face blur.
Talk to our engineering team about your use case. We'll get you up and running in under a day.
SOC 2 Type II · GDPR Ready · ISO 27001