Liveness Detection
Liveness detection that confirms a person, not a picture of one
A face match is only as good as the proof that a live person was in front of the camera. Zyphe runs active liveness with anti-spoof checks against photographs, screens, videos and masks, matches the live capture to the document portrait at a threshold you set, and detects imagery injected into the capture stream without ever passing a camera. The models run in-house and are updated every month.
What is liveness detection?
Liveness detection is the check that confirms a real, present person is in front of the camera during identity verification, rather than a photograph, a screen, a replayed video, a mask or a synthetic image fed into the capture stream. It is what makes a selfie-to-document face match worth anything, and it is evaluated against presentation attacks under ISO/IEC 30107-3.
Trusted by those who trust no one.
What the check runs on
Default face-match threshold between the live capture and the document portrait. Configurable per flow.
Anti-spoof checks against photographs, screens, videos and masks during the active liveness step.
Detection models updated monthly and run in-house, so there is no third-party biometric sub-processor in your data map.
What liveness detection covers
Each item is a control Zyphe runs today. The certification detail we cannot yet state with a level, laboratory and date is not stated at all.
Active liveness
The user follows on-screen prompts, and the system confirms a live response while checking the capture for the signatures of a photograph, a screen, a replayed video or a mask.
Face match to the document
The live capture is matched to the document portrait at a configurable threshold, 75 percent by default, so the person presenting the document is the person on it.
Injection-attack detection
Synthetic or replayed imagery fed directly into the capture stream through a virtual camera, an emulator or a modified client never reaches a lens. Detection attests the capture channel rather than the picture.
Biometric uniqueness
Optionally, the same face appearing under a different identity within a flow is flagged, which is how synthetic identities and account herders are caught at onboarding.
Monthly model updates
Deepfake generation changes monthly, so the detection models do too. Ask any vendor how recently theirs were updated and against what.
No biometric honeypot
The live capture is processed transiently and stored encrypted in the user's own vault. Zyphe retains the match result, the audit log and the proof, not a database of faces.
Where liveness sits in the flow
One stage of the KYC flow, after the document and before screening.
The identity document is classified, its security features and machine-readable zone checked, and the portrait extracted. Liveness has something to match against.
The user completes the active liveness prompts. The capture is checked for presentation attacks and the channel for injection, then the live face is matched to the document portrait at your threshold.
The outcome and its evidence go to your case file and to screening. The capture itself goes to the user's encrypted vault; Zyphe keeps results, logs and proofs.
Biometrics without a central store
Every liveness vendor that keeps a database of faces has built the target its customers will be blamed for. Zyphe processes the capture transiently, stores it encrypted in the individual's own vault, and retains only the verification result, the audit log and the cryptographic proof. Biometric data is destroyed within the limits set by BIPA and CUBI, as recorded in the data processing agreement.
Where data is stored, what is retained, and the audit status: the security and trust pageActive versus passive liveness
Active liveness asks the user to do something, turn the head, follow a moving dot, so the system can confirm a live response; it is harder to defeat with a static image and adds a few seconds of friction. Passive liveness analyses a single capture for the properties of a real face without instructions; it is smoother and depends entirely on the quality of the model. Zyphe's flow is active, with anti-spoof analysis on the capture, because a prompted response plus capture analysis catches more than either alone.
Active checks have themselves become an attack surface: pre-recorded video that performs the expected movements, delivered by injection. That is why injection-attack detection is a separate control on this page rather than a footnote to liveness.
How to evaluate a liveness vendor
- Testing, with the three details
- Presentation-attack detection is evaluated under ISO/IEC 30107-3 by independent laboratories such as iBeta. Ask for the level, the laboratory and the date. A claim without all three is marketing. Zyphe's testing documentation is available on request; until the level and date are on this page, we do not describe it as a certification.
- Injection, not just presentation
- Ask how the vendor detects imagery that never passes a camera. If the answer is about the picture rather than the channel, deepfakes will get through.
- Model currency
- Ask when the models were last updated and against which attack families. Monthly is the cadence the attack side moves at.
- What happens to the face
- Ask where the biometric template lives after the check, for how long, and under whose keys. A vendor that keeps a face database has a breach in its future.
- Where we are weaker
- Zyphe's flow is active rather than passive, which adds a few seconds for the user, and the presentation-attack testing level is not yet published on this page. If your onboarding is optimised to the last second of friction, test both flows on your own users before you decide.
Bring the attacks that got through
The only meaningful test of liveness detection is the attempts that beat your current vendor. Bring them to the demo and we will run them through the flow.
Book a demo →Better compliance in 190+ Countries
Banking Secrecy Act
Enforces strict record-keeping and reporting requirements for financial institutions to prevent money laundering and financial crimes in the United States.
Anti-money Laundering Act
Establishes measures and responsibilities for financial intermediaries in Switzerland to prevent money laundering and terrorist financing.
Proceeds of Crime
Canadian regulation requiring financial institutions to detect, prevent, and report suspicious transactions related to criminal proceeds.
Terrorist Financing Act
Legislation enforcing measures in Canada to detect, prevent, and report financial activities linked to terrorist financing.
Anti-money Laundering
Australian regulation mandating financial entities implement robust compliance measures to detect, prevent, and report money laundering activities.
Counter-Terrorism Financing Act
Australian law ensuring financial institutions identify, monitor, and report activities related to financing of terrorism to maintain national and global security.
Integrate in as little as 15 minutes
curl -X POST https://verify.zyphe.com/v1/login_sessions \
-H 'Authorization: Bearer <API_KEY>' \
-H 'Content-Type: application/json' \
-d '{"auth_type": "email"}'
Frequent Questions
Liveness detection confirms that a real, present person is in front of the camera during identity verification, rather than a photograph, a screen, a replayed video, a mask or a synthetic image injected into the capture stream. Without it a face match can be passed with a picture of the document holder. Liveness detection in the glossary
Zyphe's presentation-attack detection has been tested, and the documentation is available on request, but the level, laboratory and date are not yet published on this page, so we do not describe it as a certification here. When they are confirmed they will be stated with all three details.
Liveness addresses presentation attacks, where something is shown to the camera. Deepfakes are most often delivered by injection, bypassing the camera, which is why Zyphe runs injection-attack detection as a separate control and updates both model sets monthly. How fraudsters are beating KYC with 20 dollar deepfakes
Active, with anti-spoof analysis on the capture: the user follows prompts and the capture is checked for the signatures of photographs, screens, videos and masks. The face is then matched to the document portrait at a configurable threshold, 75 percent by default.
It is processed transiently and stored encrypted in the user's own vault. Zyphe retains the match result, the audit log and the cryptographic proof, not a database of faces, and biometric data is destroyed within BIPA and CUBI limits as set out in the data processing agreement. Security and data handling
Yes, with biometric uniqueness enabled: the same face appearing under different identities within a flow is flagged. It is one of the signals that catch synthetic identities and mule networks, which pass a document check because the documents are genuine. Fraud detection software
Explore more Zyphe products
Know Your Customer
Verify people without keeping their documents
Document and liveness verification against 4,000+ identity document versions from 213 countries and territories, with injection detection and sanctions, PEP and adverse media screening.
Learn more →Fraud detection software
that stops fraud at onboarding, not in the chargeback report
Fraud detection software that catches forged documents, synthetic identities and injection attacks at onboarding, before the account is ever opened, and keeps watching after it.
Learn more →Age verification
that proves the age without keeping the ID
Age verification software that proves a user is over the age limit from a verified document or a reusable credential, without storing the ID: configurable minimum age, geolocation checks, and an over-18 proof that reveals no birth date.
Learn more →