Liveness Detection
Liveness Detection That Stops Fraud, Not Your Customers
More users, less fraud. Analyze facial captures and prevent identity spoofing without adding friction to the user experience. Detect photos, videos, masks, and presentation attacks while the user simply looks at the camera.
Photo and screen spoofing, video injection attacks, and deepfakes are stopped before an identity ever enters your system.
Trusted by more than 190 financial institutions across 30+ countries
How It Works
Liveness Detection Integrated into the Capture Flow
Step 1
The user looks at the camera
No gestures or additional actions are required. The facial capture collected during onboarding or authentication is enough.
Step 2
Capture and channel analysis
Both image-based signals, including depth, texture, and involuntary movements, and video source signals are analyzed to detect virtual cameras and injected content.
Step 3
Decision within the verification flow
The result is delivered to the verification process before the identity is accepted. Photos, videos, masks, deepfakes, and injection attacks are stopped at this stage.
Step 4
Auditable evidence
Every verification generates a traceable record associated with the verified identity, available for audit and compliance purposes.
Key Benefits
All Liveness Capabilities in a Single SDK
Security operates in the background. Legitimate users enjoy a seamless experience, while impersonation attempts are blocked before an identity is approved.
-
Facial biometrics: verification and authentication with iBeta-certified liveness detection at Levels 1 and 2.
-
Voice biometrics: authentication using either text-dependent or text-independent verification, with no additional hardware required.
-
Fingerprint biometrics: biometric capture directly through the device screen.
-
Reverification: verified identities can be reused across future logins and transactions.
-
Obstruction detection: glasses, masks, hands, caps, or any element covering the face are detected during capture, and users receive real-time guidance.
-
Closed-eye detection: captures with closed eyes are rejected and repeated to ensure valid and comparable biometric evidence.
All capabilities are delivered through the same integration for web and mobile applications as part of our multibiometric authentication platform.
Two Modes. One SDK
Active or Passive Liveness Detection
We provide both options, configurable according to each workflow. Both validate the same signal: a real, live person is physically present in front of the camera. The difference lies in what is required from the user and when it is most appropriate to request it.
-
Passive Liveness: users simply look at the camera. Analysis runs silently in the background without adding steps to onboarding or authentication.
-
Active Liveness: the SDK requests actions such as blinking, turning the head, or moving closer to the camera. This provides explicit evidence of user interaction, making it suitable for high-risk transactions or regulatory environments requiring visible challenges.
-
Combined Approach: passive liveness can be used during onboarding and recurring access, while active liveness serves as an additional security layer when device changes, anomalies, or risk alerts are detected.
What We Detect
Spoofing, Injection Attacks, and Deepfakes
Printed photos, cut-outs, screens displayed in front of the camera, masks, and 3D artifacts. Covered by iBeta Level 1 and Level 2 certification.
Synthetic or face-swapped identities generated in real time during capture. Advanced analysis detects synthetic artifacts that are imperceptible to the human eye.
Pre-recorded or manipulated video streams introduced behind the sensor using virtual cameras, emulators, or compromised channels. Protection is reinforced through Injection Attack Defence.
Face obstructions, closed eyes, or poor lighting conditions. Instead of rejecting the process without explanation, the workflow identifies the issue and guides the user to complete a valid capture.
Compliance
Compliance and Certifications
| Standard | Level | Scope |
|---|---|---|
| iBeta ISO/IEC 30107-3 | Level 1 | Basic presentation attacks, including printed photos and screen replay attacks |
| iBeta ISO/IEC 30107-3 | Level 2 | Sophisticated attacks, including masks and 3D artifacts |
| NIST FATE PAD | Top-ranked position | Independent evaluation of presentation attack detection performance |
| SARLAFT · Colombia | Local AML framework | Aligned with SARLAFT compliance requirements |
| CNBV · México | Local AML framework | Aligned with CNBV compliance requirements |
| Trazabilidad | Identity profile + audit record | Every verification is linked to a verified identity and remains available for audit purposes |
Key Benefits
Why Facephi
Certified performance
Passive liveness certified by iBeta at Levels 1 and 2, and ranked first in the NIST FATE PAD benchmark.
Three biometric modalities, one SDK
Face, voice, and fingerprint authentication delivered through a single integration for web and mobile environments.
Deployment on your terms
Available on-premises, in a private cloud, or as SaaS, with no secondary deployment required as capacity grows.
Verification evidence
Every identity verification generates an auditable record detailing what was verified, how it was verified, and the resulting outcome.
Identity continuity
Verified identities are not lost after onboarding. They can be securely reused in future sessions, transactions, and fraud investigations.
Industries
Industry Use Cases
Analyst Recognition
Recognition by Independent Analysts
Before any technical evaluation, fraud and compliance teams turn to trusted industry analysts. Facephi is featured in leading reports covering fraud prevention, digital identity, and identity monitoring.
Let’s Talk
Complete the form and our team will get in touch with you as soon as possible to better understand your needs and provide the solution that best fits your business.
Frequently Asked Questions
Liveness detection verifies that the person in front of the camera is a real, physically present individual, not a photo, video, mask, or synthetic representation. It is applied during onboarding and authentication before an identity is accepted.
Passive liveness analyzes signals contained within the facial image or video itself, such as depth, texture, and involuntary movement, without requiring gestures or additional user actions. The user simply looks at the camera while the analysis runs in the background.
No. Facial biometrics answers the question, “Who is this person?” Liveness detection answers, “Is this person genuinely present right now?” Both technologies work together: first, liveness validates the presence of a real person; then biometric matching verifies the identity.
Both approaches verify the presence of a real person. Active liveness requests actions such as blinking or turning the head, generating explicit evidence of user interaction. Passive liveness requires no action, eliminating friction and ensuring accessibility. Facephi offers both through the same SDK, configurable according to each use case.
It protects against presentation attacks, including printed photos, screen replay attacks, masks, and 3D artifacts. It also detects deepfakes and synthetic identities generated during capture. Injection attacks using manipulated video streams, virtual cameras, or emulators can be further mitigated through Injection Attack Defence.
The industry benchmark is iBeta certification under ISO/IEC 30107-3. Level 1 covers basic presentation attacks, while Level 2 addresses sophisticated attacks such as 3D masks. Facephi’s passive liveness solution is certified at both levels and holds the leading position in the NIST FATE PAD ranking.
Yes. Facephi supports on-premises deployments on Kubernetes, private cloud environments, and SaaS models, allowing data residency requirements to remain within the boundaries defined by your regulatory framework.
A single SDK supports both web and mobile applications while maintaining a consistent data model across all processes. Verification operates independently from core banking systems, minimizing integration complexity.
Yes. Integration is based on a unified SDK and webhooks that never exchange raw biometric data, only verification outcomes. Existing fraud management platforms continue operating while receiving an additional risk signal.
Implementation timelines depend on the deployment model and the number of workflows involved. A detailed estimate is provided during the technical discovery phase.
Pricing separates licensing and integration services and varies according to verification volume and deployment model. Detailed estimates are provided during the demo based on your specific requirements.
The workflow guides users throughout the capture process to obtain a valid image instead of rejecting the session without explanation. Specific scenarios and behaviors can be reviewed during the product demonstration.
Each verification produces an auditable record detailing what was verified, how the verification was performed, and the resulting outcome. This record remains linked to the verified identity throughout digital onboarding and every subsequent authentication event.


