Skip to content
FaceOff Technologies

BehaviorID

Facepay

A password proves someone knew a secret. FacePay proves a live, enrolled person is at the handset and is willingly approving this payment — five behavioural signals fused on-device in two to three seconds, before the transaction clears.

What it checks before authorising

  • A live person, not a photo or a replay
  • The enrolled identity, not a lookalike
  • Behavioural congruence across the signals
  • Genuine consent, not coercion

OutputA Trust Factor: proceed, block, or escalate

On-device analysis, from the moment of approval to the authorisation decision

2–3s

On-device analysis, from the moment of approval to the authorisation decision

Behavioural signals fused: face, micro-expression, gaze, posture and voice

5

Behavioural signals fused: face, micro-expression, gaze, posture and voice

Passwords, PINs or OTPs required at the moment of payment

0

Passwords, PINs or OTPs required at the moment of payment

One-time enrolment — every payment after it is validated by behaviour

1

One-time enrolment — every payment after it is validated by behaviour

The moment of approval

One payment, end to end

Static biometrics answer whose face this is. The harder question is whether that person meant to approve this particular transaction, or was made to — which is a question about the seconds around the approval, not about the face.

  1. 01

    Capture

    Front camera and mic sample the moment of approval, on-device

  2. 02

    Fuse

    Five behavioural signals scored together rather than in sequence

  3. 03

    Score

    A Trust Factor for this transaction, not for this device

  4. 04

    Decide

    Proceed, block, or escalate to secondary verification

  5. 05

    Challenge

    High-value or anomalous: a head nod or spoken confirmation

All five stages execute inside the secure enclave. No frames, no audio and no behavioural profile leave the handset — the payment app receives a decision, never a face.

How it ships

Embedded, enrolled once, then invisible

FacePay is not a separate app a customer has to be talked into. It is an SDK the payment app already embeds, and after a single enrolment the customer never thinks about it again.

FaceOff Lite SDK

Lightweight, embedded by the payment app itself

  • Enables FacePay as either an optional or the default authentication method.
  • No change to the underlying UPI, NEFT, RTGS or wallet rails.

Secure enclave execution

On-device, with hardware acceleration

  • The whole analysis completes in two to three seconds.
  • Frames, audio and the behavioural profile never leave the handset.
  • There is no central biometric store, and so nothing central to breach.

One-time enrolment

A single secure capture of face and behaviour

  • Builds the profile once, on the customer's own device.
  • Every payment after that is validated against it — no password, no OTP.

Step-up challenge

Triggered on high-value or anomalous transactions

  • A head nod or a spoken confirmation, layered on top of the passive check.
  • Raises the bar exactly where the exposure sits, rather than on every payment.

Enrolment is the only moment a customer is asked to do anything unusual. Everything after it happens inside a payment they were making anyway.

The behavioural layer

Four signals that a static biometric cannot see

Facial recognition confirms the enrolled identity. These four confirm that the person behind it is live, present and acting freely — and each has its own page on the platform.

Ocular dynamics

Eye Tracking Analysis

Blink pattern and gaze direction — liveness, and whether attention is on the transaction.

Body position

Posture & Behaviour

Body language carrying duress, or anomalous against how this customer normally pays.

Voice

Speech Sentiment

Emotional state and intent in the spoken confirmation, where one is asked for.

Why traditional authentication fails

Credentials prove knowledge, not intent

PINs, passwords and static biometrics all answer a question that fraudsters stopped needing to defeat. The gap they leave is the one sophisticated fraud now operates in.

A password proves a secret was known
It can be phished, socially engineered, or lifted by malware. None of that establishes that a person is at the handset at all.
A face match proves identity, not consent
It confirms whose face it is. It cannot tell you whether they meant to approve this payment, or were standing next to someone who made them.
Coercion has a signature
Micro-expression, gaze and posture read duress. That protects the customers most often targeted — elderly and less confident users — better than any credential can.
Fewer chargebacks, not only fewer frauds
Intent verified at the moment of approval removes the dispute as well as the loss, which is the half of the cost most fraud tooling leaves behind.
Nothing central to steal
The behavioural profile stays inside the secure enclave. There is no template database to breach, which is the failure mode of every centralised biometric scheme.
Adaptive, not a fixed rule
The engine keeps learning new fraud patterns as they appear. A PIN policy does not.

Where it runs

Industries deploying Facepay

Each sector page covers the threat model, the controls, and the regulators that apply.

A new standard for online payment security.

Behavioural intelligence in place of a password, running inside a payment your customers were already making. See it authorise, block and escalate against your own flow.