SpoofSense Logo

SpoofSense Face

Face liveness detection that never interrupts the user.

SpoofSense verifies that a live, physically present human is behind every selfie — passively, from a single image. No blinking, no head turns, no challenges. Just one REST API call that stops print, mask, replay, deepfake and injection attacks.

The basics

What is face liveness detection?

Face liveness detection (also called liveness verification or anti-spoofing) is the technology that confirms the face in front of a camera belongs to a real, live person — not a photo, a screen, a mask, or an AI-generated imitation. It is the layer of an identity stack that decides whether a selfie can be trusted before face matching or KYC decisions run.

Without liveness detection, an attacker with a victim's photo — scraped from social media or a leaked database — can open accounts, take over logins and pass remote onboarding. With it, spoofed faces are rejected at the first step, before they ever become an approved identity.

Liveness checks are standardized under ISO/IEC 30107-3, the international presentation attack detection (PAD) standard, and independently tested by labs such as iBeta. SpoofSense is iBeta Level 1 and Level 2 compliant per ISO/IEC 30107-3.

Passive vs. active

Passive liveness wins on friction — without giving up security.

Active liveness asks users to perform challenges. Passive liveness decides from a single frame. Here is how they compare in production identity flows.

Passive liveness (SpoofSense)Active liveness
User action requiredNone — a single selfieBlink, smile, turn head, follow a dot
Verification timeInstant, from one frame5–30 seconds of challenges
Drop-off riskMinimal added frictionHigher — each challenge loses users
Attack resistanceCertified PAD plus deepfake and injection screeningChallenges can be replayed or deepfaked
AccessibilityWorks for all usersHarder for users with motor or visual impairments

Threat coverage

Every spoof vector, one API call.

Print & mask attacks

Certified presentation attack detection (PAD) catches printed photos, paper cutouts, and 2D or 3D masks presented to the camera.

Screen replay attacks

Detects pre-recorded or live-replayed faces shown on phones, tablets and monitors using screen texture and moiré artifacts.

Deepfakes & AI faces

Screens for GenAI faces, face swaps and reenactment deepfakes with pixel-level artifact analysis.

Deepfake detection

Digital injection

Flags virtual cameras, emulators and injected video streams that try to bypass the camera entirely.

Injection attack detection

Verifying documents too? SpoofSense DocLive applies the same passive approach to ID documents, catching print, replay and portrait-tamper attacks during document capture.

How it works

One image in. One decision out.

01

Capture

Your app captures a single selfie through our Web or Mobile SDK, or any camera pipeline you already run.

02

Analyze

The image is screened for presentation artifacts, screen replay signatures, GenAI fingerprints and injection signals in a single pass.

03

Decide

The REST API returns a liveness decision you can act on instantly — approve, reject, or step up.

Certification

iBeta Level 1 and Level 2 compliant, per ISO/IEC 30107-3.

ISO/IEC 30107-3 defines how presentation attack detection is tested; iBeta is the independent lab that runs those tests. Level 1 covers print and screen replay attacks, Level 2 adds sophisticated 3D masks. SpoofSense passes both — the compliance bar regulated identity programs look for.

FAQ

Face liveness detection, answered.

What is face liveness detection?

Face liveness detection verifies that the face presented during identity verification belongs to a live, physically present human — not a printed photo, a mask, a replayed video, or an AI-generated deepfake. It is the control that stops spoofed faces from passing selfie checks in onboarding, KYC and authentication flows.

What is the difference between passive and active liveness detection?

Active liveness asks the user to perform challenges — blink, turn their head, follow a dot — which adds friction and drop-off. Passive liveness analyzes a single image or frame with no user action required. SpoofSense uses passive liveness, so genuine users complete verification without interruption while attacks are still caught.

Is SpoofSense liveness detection certified?

Yes. SpoofSense is iBeta Level 1 and Level 2 compliant, tested per the ISO/IEC 30107-3 presentation attack detection standard.

What attacks does face liveness detection stop?

SpoofSense detects presentation attacks (printed photos, cutouts, 2D and 3D masks), replay attacks shown on phone, tablet or monitor screens, AI-generated deepfakes and face swaps, and digital injection attacks that use virtual cameras or emulators to bypass the camera.

How do I integrate face liveness detection?

SpoofSense is a REST API with Web and Mobile SDKs. You send a single face image and receive a liveness decision in the response. Most teams integrate in under a day, and new accounts get 100 free credits to test with.

Does passive liveness hurt conversion?

No — that is its main advantage. Because there are no challenge steps, genuine users pass without doing anything extra, which reduces abandonment compared to active liveness flows while keeping spoof detection strength.

Add passive liveness to your flow today.

Start free — 100 credits →