QuantumSafe QR
Post-quantum QR for secure credentials and access.
- Post-quantum cryptographic signature
- Tamper-proof digital credentials
- Offline verifiable physical/digital QR
What the document is asked
A refusal comes back with the reason for it.
Examined at the moment it is relied on, not only at the moment it was issued
Overview
Zero-Trust Identity covers the two halves of the same problem. It issues credentials that can be proved genuine wherever they are presented, and it finds the identities that were invented rather than stolen, which is what makes them so hard to spot.
Two problems sit either side of the same question. The first is whether a credential presented to you is genuine, whether that is a pass at a door, a certificate, or the code printed on a pack of medicine. The second is whether the person behind an identity exists at all.
For the first, Zero-Trust Identity issues credentials that carry their own proof. Anyone with the right to check one can confirm it is genuine and unaltered, and that check works at a gate or in a warehouse where there may be no connection at all. A copied or edited credential does not survive it.
For the second, it looks at how identities relate to one another rather than at each one alone. Identities assembled out of real fragments belonging to different people tend to look convincing individually and strange collectively, and that pattern is what gets surfaced for an investigator to examine.
3
Products across credentials and identity assurance
Works offline
A credential can be checked with no connection available
Built to last
Credentials designed to stay trustworthy for years to come
In this category
A credential has to prove itself wherever it is presented, a product has to prove it is the genuine article, and an identity has to belong to a person who exists. There is a product for each, and each returns an answer someone can act on.
Post-quantum QR for secure credentials and access.
Verifiable QR authentication for pharmaceutical packaging.
Graph analytics to detect synthetic identities.
How it works
One path issues something that can prove itself later. The other examines what already exists. Both end with an answer a person can act on.
One question
An identity is surfaced for an investigator to examine with the reasons attached, never refused automatically on the strength of a pattern.
A credential is created carrying its own proof of where it came from. An identity arrives the ordinary way, as an application or as a record already on your books.
Whoever is entitled to check a credential can confirm it is genuine and unaltered at the point it is shown. That check does not depend on a connection, so it works at a gate, in a warehouse or in the field.
For identities, what matters is the company they keep. Details shared across records that should have nothing to do with each other are the pattern that distinguishes an invented identity from an ordinary one.
A credential check gives a plain answer at the moment it is needed. An identity finding is handed to an investigator with the connections that raised it, so a person makes the decision and the reasoning is on file.
Use cases
Wherever something has to prove it is what it claims. These are the situations teams bring to the category most often.
Find applications built on identities that were assembled rather than stolen, which pass an ordinary check because each detail belongs to somebody real, before an account is opened or credit is advanced.
Give every pack a credential that can be checked along the supply chain and at the point of dispensing, so a counterfeit does not reach a patient and a genuine pack can prove itself.
Issue passes that cannot usefully be copied or edited, and check them at the gate where connectivity is unreliable and queues do not wait.
Issue entitlements, licences and certificates that can be verified by anyone entitled to check them, and detect claims made in the name of people who do not exist.
Identify policies and claims clustered around identities that do not stand up when examined together, rather than assessing each application entirely on its own.
Let a distributor, a retailer or a customer confirm that an item is the genuine article, and give the manufacturer a record of where verification is happening.
FAQ
Answered the way a fraud lead, a supply chain manager or a compliance officer asks them.
Zero-Trust Identity is FaceOff's suite for proving that a credential is genuine and that an identity belongs to a real person. It issues credentials that carry their own proof so they can be checked wherever they are presented, authenticates products such as medicine packs along the supply chain, and finds identities that were invented from fragments of real people's details. It is used by banks, public bodies, manufacturers and venues.
A synthetic identity is one assembled from details belonging to several real people, rather than stolen wholesale from one. It is hard to catch because every individual detail checks out, so an application examined on its own looks ordinary. What gives it away is how it relates to other records, which is why these identities are found by looking at the connections between them rather than at each one in isolation.
Yes. A credential is designed to carry its own proof, so anyone entitled to check it can confirm it is genuine and unaltered without contacting a server. That matters at a gate, in a warehouse, on a delivery round or anywhere else that connectivity is unreliable, because a check that fails when the network does is not a check people can depend on.
A credential carries proof of where it came from, so a copy or an edited version does not pass the check even though it may look identical. This is the practical difference between a code that simply holds information and a credential that can prove it is genuine: the second one cannot usefully be reproduced by someone who was not entitled to issue it.
No. Identity findings are surfaced to an investigator with the connections that raised them, so a person examines the case and makes the decision. This is deliberate. A pattern is a reason to look more closely rather than proof of wrongdoing, and an automatic refusal on the strength of one would be both unfair to legitimate customers and impossible to explain later.
Zero-Trust Identity is used by banks and lenders screening applications for invented identities, pharmaceutical manufacturers and healthcare providers authenticating packs, venues and event organisers issuing passes that are checked at the gate, public bodies issuing entitlements and licences, and insurers examining clusters of related claims. What these organisations share is that something is being presented to them as genuine.
Credentials are built to remain trustworthy well beyond the point at which older methods are expected to weaken, because a pass, a licence or a product code often has to hold up for years after it is issued. The intent is that a credential issued today does not have to be reissued because the protection behind it has aged out during its working life.
The rest of the line
Bring a credential you issue, a pack you need to protect, or an application set you are unsure about. We will walk through what the check returns and how a reviewer would use it.