Skip links

Post-quantum authentication at the edge

Edge Biometrics Authentication

Authenticate users through live biometric presence without storing or transmitting biometric data,
using post-quantum cryptography derived from images.

The problem with today’s
facial biometrics

Facial biometric authentication is widely used, but current models force a structural trade-off between privacy, portability, and security.

Local biometrics, such as Face ID, Touch ID, or passkeys, keep biometric data on the device. This approach is privacy-friendly, but identity becomes tied to a specific device or ecosystem. Changing devices requires re-enrollment, limiting true portability.

Centralized biometrics allow cross-device authentication, but at a high cost. Biometric templates are stored and processed server-side, creating significant security risk, regulatory exposure under GDPR, and long-term liability in the event of a breach.

Edge Biometrics Authentication is designed to eliminate this trade-off.

identity-protected-biometric-scan-woman-s-face

What is Edge Biometrics Authentication?

Edge Biometrics Authentication is an authentication model where biometrics do not store identity data

Biometric signals are used to confirm that the person in the picture is present, while identity is proven separately using post-quantum cryptography.

This model is built on three core principles:

• Cryptography proves identity

• Biometrics verify liveness and image-to-live match

• No biometric data is ever retained

By separating identity from biometric data, authentication becomes portable, privacy-preserving, and resilient by design.

Biometrics verify presence, cryptography proves identity.

How it works

All biometric processing happens locally, in the browser, and ends immediately after authentication

secrests-vault-secure-and-manage-your-passwords

User selects
an image

The user selects an image that includes their face for later biometric presence validation.

secrets-vault-protect-your-sensitive-photos

Live presence verification

The browser activates the camera to confirm liveness and match the person to the image.

secrets-vault-protect-your-wallet-seed-phrases

Post-quantum key derivation

If verification succeeds, a post-quantum cryptographic key is derived from the image.

secrets-vault-preserve-your-familys-prized-secrets

Cryptographic authentication

The derived key is used to perform strong authentication against the server.

Want to try Edge Biometrics?

Experience post-quantum authentication with biometric presence verification and zero biometric data storage.

Try Edge Biometrics

Key advantages

secrest-vault-visual-passcodes

Zero biometric data storage

Biometric data is never stored or transmitted. It exists only transiently in memory and is discarded once authentication is complete.

secrest-vault-visual-safeguard

Post-quantum by design

Authentication keys are derived using cryptographic constructions designed to resist future quantum attacks, without requiring future migration.

secrest-vault-visual-safeguard

Reduced deepfake risk

Facial recognition alone is increasingly vulnerable to AI-generated deepfakes. In this model, a deepfake is insufficient without the image with the user face and a successful live verification.

secrest-vault-visual-safeguard

True device independence

There are no local keys to migrate or synchronize. Users can authenticate from any device by re-deriving the key and completing edge-based verification.

Why enterprises adopt this identity model?

Edge Biometrics Authentication is adopted by enterprises that require strong proof of presence without introducing biometric data risk.

It fits regulated environments, enterprise IAM architectures, and high-assurance access scenarios where privacy, portability, and long-term security matter.

The model can be combined with additional authentication factors or applied selectively, depending on the risk level and access context.

Captura de pantalla 2026-02-02 150110

Powered by Secrets Vault Identity

Edge Biometrics Authentication is one of the image-based, post-quantum authentication capabilities available within Secrets Vault Identity.

Explore PQC authentication

Any more questions?

Get in touch with our team

contact us

Any more questions?

Get in touch with our team

contact us

Edge Biometrics FAQ’s

No. Biometric data is never stored or transmitted. It is used only transiently on the user’s device to confirm live presence and is discarded immediately after authentication.

No. The image does not need to be secret or stored securely. Security comes from the post-quantum cryptographic key derived from the image, not from the image itself.

Face ID and passkeys rely on locally stored keys tied to a specific device or ecosystem. Edge Biometrics Authentication does not store local keys and allows authentication from any device.

Yes. Since no biometric data is stored or processed server-side, the system avoids the main sources of biometric data liability under GDPR.

Yes. Edge Biometrics Authentication can be combined with additional factors or applied selectively, depending on the security context.

A deepfake alone is insufficient. An attacker would need both: the image with the user face used for key derivation and a successful live presence verification.

No. Everything runs in the browser. No application installation or dedicated hardware is required.

Yes. The cryptographic keys are derived using post-quantum constructions by design, without relying on classical cryptography.

Privacy Summary

This website uses cookies so that we can provide you with the best possible user experience. The cookie information is stored in your browser and performs functions such as recognizing you when you return to our site or helping our team understand which sections of the site you find most interesting and useful.