Skip to content
FaceOff Technologies

BehaviorBioAuth (Onboarding)

BehaviorBioAuth confirms that a real, living person is completing an identity check — not a photo, a screen replay or a deepfake. It watches how someone naturally moves, blinks, looks and speaks during a short guided session, then returns a clear pass-or-fail decision you can trust for regulated onboarding

Product Walkthrough
0:000:00

What it is

A short guided session, then a pass-or-fail decision

Each session draws its challenges in a random order — hold still, turn head left or right, follow a gaze target, blink on cue, and speak a number shown on screen while looking at the camera. Because the sequence is never the same twice, a pre-recorded clip cannot be prepared in advance to pass it.

Beyond those explicit challenges, the engine runs continuous liveness checks in the background throughout the session, so authenticity is confirmed from start to finish rather than at a single moment. Onboarding also captures the customer's government ID — Aadhaar or PAN — and confirms the document against the live, verified face, tying a real identity to the person actually present.

The recorded session is examined by a specialised model that looks for the signatures of synthetic or generated video. The fraud verdict is decided on the server, so it cannot be tampered with on the user's device.

Containerised and self-hosted, so customer data stays within your environment

On-premise

Containerised and self-hosted, so customer data stays within your environment

The fraud verdict is decided on the server, so it cannot be tampered with on the device

Server-side

The fraud verdict is decided on the server, so it cannot be tampered with on the device

Agent-led live Video KYC over secure video, alongside the automated 24/7 journey

RBI V-CIP

Agent-led live Video KYC over secure video, alongside the automated 24/7 journey

PII and biometric templates encrypted at rest, in a format built for hybrid ML-KEM

AES-256-GCM

PII and biometric templates encrypted at rest, in a format built for hybrid ML-KEM

High-level architecture

How BehaviorBioAuth works, end to end

From a short guided session to a server-authoritative decision.

  1. 01

    Capture

    Short guided session on the mobile app

  2. 02

    Liveness challenges

    Randomized actions plus passive, continuous checks

  3. 03

    Verification engine

    Server-authoritative scoring on your infrastructure

  4. 04

    Deepfake analysis

    FaceOff model returns a synthetic-media verdict

  5. 05

    Decision

    Pass or fail, recorded in the admin console

Product exclusiveness

What sets BehaviorBioAuth apart

  1. Behavioral liveness, not a single face match

    A simple biometric only asks whether a face resembles the one on file. BehaviorBioAuth observes how a person actually behaves over a short session — the small, involuntary patterns of movement, blinking, gaze and speech that a printed photo, a screen replay or a deepfake cannot reproduce.

    Flagship capability

  2. Randomized live challenge library

    Each session draws challenges in a random order — hold still, turn head left/right, follow a gaze target, blink on cue, and speak a spoken number while looking at the camera. Because the sequence is never the same twice, a pre-recorded clip can't be prepared in advance to pass it.

    Anti-replay · a different order every session

  3. Server-side deepfake analysis

    The recorded session is examined by a specialised model that looks for the signatures of synthetic or generated video. The fraud verdict is decided on the server, so it cannot be tampered with on the user's device.

    The verdict is decided off the device

  4. Two onboarding journeys, one verified outcome

    Run fully automated self-onboarding that is available 24/7, or an agent-led live Video KYC call over secure video (RBI V-CIP) for assisted and higher-assurance cases — both reach the same trusted verdict, so you choose the right level of friction per customer.

    Agentless 24/7 · agent-led RBI V-CIP

  5. Passive & continuous liveness

    Beyond the explicit challenges, the engine runs continuous liveness checks in the background throughout the session, so authenticity is confirmed from start to finish rather than at a single moment.

    Confirmed start to finish, not at one moment

  6. Government-ID capture & face matching

    Onboarding captures the customer's government ID (Aadhaar / PAN) and confirms the document against the live, verified face — tying a real identity to the person actually present.

    Aadhaar / PAN matched to the live face

  7. Optional vitals & depth modules

    When a deployment calls for extra assurance, add optional checks such as heart rate and blood-oxygen (SpO₂) estimation, and a “move closer” depth check that confirms a three-dimensional face in front of the camera.

    Switch-on modules

Market comparison

How it compares to conventional onboarding

  • Proves a live human is present

    Static face-match KYC
    PartlySingle liveness selfie
    OTP / document-only onboarding
    NoNot addressed
    BehaviorBioAuth
    YesBehavioral + passive liveness
  • Resists printed photo & screen replay

    Static face-match KYC
    PartlyLimited
    OTP / document-only onboarding
    NoNo
    BehaviorBioAuth
    YesYes
  • Resists deepfakes & synthetic video

    Static face-match KYC
    NoNo
    OTP / document-only onboarding
    NoNo
    BehaviorBioAuth
    YesServer-side deepfake model
  • Randomized, unpredictable checks

    Static face-match KYC
    NoFixed or none
    OTP / document-only onboarding
    NoNone
    BehaviorBioAuth
    YesRandom order each session
  • Self-service, available 24/7

    Static face-match KYC
    YesYes
    OTP / document-only onboarding
    YesYes
    BehaviorBioAuth
    YesAgentless journey
  • Assisted live Video KYC option

    Static face-match KYC
    NoNo
    OTP / document-only onboarding
    NoNo
    BehaviorBioAuth
    YesAgentic (RBI V-CIP)
  • Runs on your own infrastructure

    Static face-match KYC
    PartlyUsually vendor cloud
    OTP / document-only onboarding
    PartlyUsually vendor cloud
    BehaviorBioAuth
    YesOn-premise / containerised
  • Encryption at rest + PQC-ready

    Static face-match KYC
    PartlyVaries by vendor
    OTP / document-only onboarding
    PartlyVaries by vendor
    BehaviorBioAuth
    YesAES-256-GCM, ML-KEM ready
  • Optional vitals & depth checks

    Static face-match KYC
    NoNo
    OTP / document-only onboarding
    NoNo
    BehaviorBioAuth
    YesAvailable as modules

The architecture

Hosted by you — one model excepted

One boundary, and only the recorded session crosses it

  • Personal data
  • ID images
  • Biometric templates
  • Video recordings

On your premises

Verification engine

Server-authoritative scoring, in containers you host

Trust boundary

Only the recorded session crosses, protected in transit with authenticated AES-256 encryption. Nothing else leaves your premises.

Off your premises

FaceOff deepfake model

The only component not on your premises

AES-256
Pass or fail, in the console

Use cases by sector

Use cases across sectors

Banking & finance

Open accounts remotely with liveness-backed KYC that resists photos, replays and deepfakes.

How the sector deploys it

Fintech & lending

Onboard borrowers in minutes with a verdict you can defend to auditors.

Telecom

Verify identity for SIM issuance and number portability without a branch visit.

How the sector deploys it

Insurance

Confirm policyholders at onboarding and at high-value claim steps.

How the sector deploys it

Crypto & exchanges

Meet KYC obligations while keeping fraudulent sign-ups out.

Deployment strategy

Runs on your infrastructure. Protects data end to end

  1. Deploy on your infrastructure

    Mobile capture, the verification engine, the admin console and the database ship as containers you host on-premise or in your private cloud.

  2. Choose journeys & policy

    Enable agentless self-onboarding, agent-led Video KYC, or both, and configure the challenge library and pass thresholds to match your risk appetite.

  3. Connect ID capture & console

    Wire up government-ID capture (Aadhaar / PAN) and run day-to-day operations, compliance and fraud review from a single web console.

  4. Deepfake analysis service

    Recorded sessions are sent to FaceOff's deepfake model — the only component not on your premises — over authenticated AES-256 encryption, and the verdict returns to your system.

  5. Go live

    Decisions are server-authoritative, and sessions, biometric templates and recordings remain encrypted inside your environment.

Data protection

Four things a regulated deployment has to pin down

Where the platform runs, how data is held at rest, what it is future-proofed against, and the one component that is not on your premises.

Hosting model
On-premise or private-cloud, fully containerised and self-hosted. Personal data, ID images, biometric templates and video recordings stay inside your environment.
Data at rest
PII and biometric templates are encrypted with AES-256-GCM; ID images and Video KYC recordings are encrypted on disk. Searchable fields use a keyed one-way index so values can be matched without being stored in the clear. Encryption keys are mandatory in production.
Post-quantum ready
The encryption layer is built for a hybrid ML-KEM (Kyber) + X25519 scheme inside a versioned format, so data is safeguarded against future quantum attacks as the layer is enabled — with no change to how data is stored or migrated.
Deepfake service
A single specialised model hosted by FaceOff issues the synthetic-media verdict. Media sent for analysis is protected in transit with authenticated AES-256 encryption; nothing else leaves your premises.

Frequently Asked Questions

It verifies behavioral liveness, not just a single face image. It observes involuntary patterns of movement, blinking, gaze and speech that photos, replays and deepfakes cannot reproduce, and runs passive, continuous liveness checks throughout the session. A specialised model also examines the session on the server for synthetic-media signatures.

Book a technical walkthrough

45 minutes with a solutions engineer. No slide deck unless you ask for one.

We use this to schedule the call. It does not enter a marketing sequence.

The rest of the line

More in BehaviorID

Where it runs

Industries deploying BehaviorBioAuth

Each sector page covers the threat model, the controls, and the regulators that apply.

Verify a living person, not a resembling face

Book a walkthrough and we will show the guided session, the randomized challenge library, the server-side verdict and the console it is recorded in.