Free guide: How to use AI in compliance

Liveness Detection

Liveness detection that confirms a person, not a picture of one

A face match is only as good as the proof that a live person was in front of the camera. Zyphe runs active liveness with anti-spoof checks against photographs, screens, videos and masks, matches the live capture to the document portrait at a threshold you set, and detects imagery injected into the capture stream without ever passing a camera. The models run in-house and are updated every month.

Liveness Detection verification

What is liveness detection?

Liveness detection is the check that confirms a real, present person is in front of the camera during identity verification, rather than a photograph, a screen, a replayed video, a mask or a synthetic image fed into the capture stream. It is what makes a selfie-to-document face match worth anything, and it is evaluated against presentation attacks under ISO/IEC 30107-3.

Trusted by those who trust no one.

Bondex
ETHDENVER
EBSI
Filecoin
XEurope
Protocol Labs
Supra
Yescoin
Twotixx

What the check runs on

75

Default face-match threshold between the live capture and the document portrait. Configurable per flow.

4

Anti-spoof checks against photographs, screens, videos and masks during the active liveness step.

1

Detection models updated monthly and run in-house, so there is no third-party biometric sub-processor in your data map.

What liveness detection covers

Each item is a control Zyphe runs today. The certification detail we cannot yet state with a level, laboratory and date is not stated at all.

Active liveness

The user follows on-screen prompts, and the system confirms a live response while checking the capture for the signatures of a photograph, a screen, a replayed video or a mask.

Face match to the document

The live capture is matched to the document portrait at a configurable threshold, 75 percent by default, so the person presenting the document is the person on it.

Injection-attack detection

Synthetic or replayed imagery fed directly into the capture stream through a virtual camera, an emulator or a modified client never reaches a lens. Detection attests the capture channel rather than the picture.

Biometric uniqueness

Optionally, the same face appearing under a different identity within a flow is flagged, which is how synthetic identities and account herders are caught at onboarding.

Monthly model updates

Deepfake generation changes monthly, so the detection models do too. Ask any vendor how recently theirs were updated and against what.

No biometric honeypot

The live capture is processed transiently and stored encrypted in the user's own vault. Zyphe retains the match result, the audit log and the proof, not a database of faces.

Where liveness sits in the flow

One stage of the KYC flow, after the document and before screening.

The identity document is classified, its security features and machine-readable zone checked, and the portrait extracted. Liveness has something to match against.

The user completes the active liveness prompts. The capture is checked for presentation attacks and the channel for injection, then the live face is matched to the document portrait at your threshold.

The outcome and its evidence go to your case file and to screening. The capture itself goes to the user's encrypted vault; Zyphe keeps results, logs and proofs.

Where liveness sits in the flow visual
Biometrics without a central store

Biometrics without a central store

Every liveness vendor that keeps a database of faces has built the target its customers will be blamed for. Zyphe processes the capture transiently, stores it encrypted in the individual's own vault, and retains only the verification result, the audit log and the cryptographic proof. Biometric data is destroyed within the limits set by BIPA and CUBI, as recorded in the data processing agreement.

Where data is stored, what is retained, and the audit status: the security and trust page

Active versus passive liveness

Active liveness asks the user to do something, turn the head, follow a moving dot, so the system can confirm a live response; it is harder to defeat with a static image and adds a few seconds of friction. Passive liveness analyses a single capture for the properties of a real face without instructions; it is smoother and depends entirely on the quality of the model. Zyphe's flow is active, with anti-spoof analysis on the capture, because a prompted response plus capture analysis catches more than either alone.

Active checks have themselves become an attack surface: pre-recorded video that performs the expected movements, delivered by injection. That is why injection-attack detection is a separate control on this page rather than a footnote to liveness.

How to evaluate a liveness vendor

Testing, with the three details
Presentation-attack detection is evaluated under ISO/IEC 30107-3 by independent laboratories such as iBeta. Ask for the level, the laboratory and the date. A claim without all three is marketing. Zyphe's testing documentation is available on request; until the level and date are on this page, we do not describe it as a certification.
Injection, not just presentation
Ask how the vendor detects imagery that never passes a camera. If the answer is about the picture rather than the channel, deepfakes will get through.
Model currency
Ask when the models were last updated and against which attack families. Monthly is the cadence the attack side moves at.
What happens to the face
Ask where the biometric template lives after the check, for how long, and under whose keys. A vendor that keeps a face database has a breach in its future.
Where we are weaker
Zyphe's flow is active rather than passive, which adds a few seconds for the user, and the presentation-attack testing level is not yet published on this page. If your onboarding is optimised to the last second of friction, test both flows on your own users before you decide.

Bring the attacks that got through

The only meaningful test of liveness detection is the attempts that beat your current vendor. Bring them to the demo and we will run them through the flow.

Book a demo →

Better compliance in 190+ Countries

Banking Secrecy Act

Enforces strict record-keeping and reporting requirements for financial institutions to prevent money laundering and financial crimes in the United States.

Anti-money Laundering Act

Establishes measures and responsibilities for financial intermediaries in Switzerland to prevent money laundering and terrorist financing.

Proceeds of Crime

Canadian regulation requiring financial institutions to detect, prevent, and report suspicious transactions related to criminal proceeds.

Terrorist Financing Act

Legislation enforcing measures in Canada to detect, prevent, and report financial activities linked to terrorist financing.

Anti-money Laundering

Australian regulation mandating financial entities implement robust compliance measures to detect, prevent, and report money laundering activities.

Counter-Terrorism Financing Act

Australian law ensuring financial institutions identify, monitor, and report activities related to financing of terrorism to maintain national and global security.

Integrate in as little as 15 minutes

curl -X POST https://verify.zyphe.com/v1/login_sessions \
-H 'Authorization: Bearer <API_KEY>' \
-H 'Content-Type: application/json' \
-d '{"auth_type": "email"}'

Frequent Questions

Liveness detection confirms that a real, present person is in front of the camera during identity verification, rather than a photograph, a screen, a replayed video, a mask or a synthetic image injected into the capture stream. Without it a face match can be passed with a picture of the document holder. Liveness detection in the glossary

Zyphe's presentation-attack detection has been tested, and the documentation is available on request, but the level, laboratory and date are not yet published on this page, so we do not describe it as a certification here. When they are confirmed they will be stated with all three details.

Liveness addresses presentation attacks, where something is shown to the camera. Deepfakes are most often delivered by injection, bypassing the camera, which is why Zyphe runs injection-attack detection as a separate control and updates both model sets monthly. How fraudsters are beating KYC with 20 dollar deepfakes

Active, with anti-spoof analysis on the capture: the user follows prompts and the capture is checked for the signatures of photographs, screens, videos and masks. The face is then matched to the document portrait at a configurable threshold, 75 percent by default.

It is processed transiently and stored encrypted in the user's own vault. Zyphe retains the match result, the audit log and the cryptographic proof, not a database of faces, and biometric data is destroyed within BIPA and CUBI limits as set out in the data processing agreement. Security and data handling

Yes, with biometric uniqueness enabled: the same face appearing under different identities within a flow is flagged. It is one of the signals that catch synthetic identities and mule networks, which pass a document check because the documents are genuine. Fraud detection software