faceping.aidocs

Security

How FacePing protects face data on the device and the server: a memory-safe native engine written in Rust, encrypted storage, signed licences and verified models.

Face templates are sensitive data. This page sets out how FacePing protects them, on the phone and on our servers.

One native engine, written in Rust#

Face detection, liveness, matching, encrypted storage and licence checks all run in the FacePing core, a native library written in Rust. The same core runs inside the SDK on iOS and Android and in the FacePing API when it enrols a face, so a face gets the same checks wherever it's processed.

  • Memory safe. Rust rules out whole classes of bugs, such as buffer overflows and use-after-free, which are a common way into code that parses images from the outside world.
  • Compiled to machine code. The SDK ships the engine as native code, not as readable .NET or JavaScript. The platform SDKs (MAUI now; Swift, Kotlin, Flutter and React Native next) are thin layers over the same core.
  • Standard decoders. JPEG and PNG photos are decoded by well-tested open-source Rust libraries, with EXIF orientation applied before a face is looked for.

On the device#

  • Templates, not photos. A photo is turned into a face template (a list of numbers) and then discarded. A template can't be turned back into a picture of the person.
  • Encrypted at rest. Templates are stored with AES-256-GCM. The key is held in the platform's secure storage (Keychain on iOS, Keystore on Android), never in the app's files.
  • Verification is offline. Checking a face never sends it anywhere: the camera frames stay on the phone.
  • Deleted on time. Sandbox faces are deleted after 24 hours. Production faces are deleted at your retention date, or when the device is revoked or the event deleted. A device that can't reach FacePing stops verifying after 24 hours until it syncs again.
  • Signed sandbox licences. A sandbox key is exchanged once for a licence signed by FacePing (ECDSA P-256). The core checks the signature and limits on the device, so they can't be edited.

Between the device and FacePing#

  • TLS only. The SDK talks to the FacePing API over HTTPS.
  • Encrypted face packs. A production device downloads only the faces it needs, as an AES-256-GCM encrypted pack, and each device has its own token that you can revoke. A revoked device wipes its copy at its next sync.
  • Your region. Face templates stay in the EU (UK and US regions on request).

How we build it#

  • Verified models. The face models are checked against known SHA-256 hashes on every build.
  • No test code in releases. The core has test-only switches for our own test suites. Release builds refuse to compile with them, and every package is scanned for them before it's published.
  • Open-source parts are listed. Every third-party component and its licence is in THIRD-PARTY-NOTICES.txt inside the SDK package.

Reporting a security issue#

Email [email protected] with "Security" in the subject. Please give us a chance to fix the issue before telling anyone else. We'll reply within two working days.