Digital credentials still need to prove who is holding them
PKI and device checks confirm a credential is valid. Face binding confirms the person presenting it is the holder.
By FaceLock Team January 14, 2026
SecurityIdentity VerificationBiometrics
# Digital credentials still need to prove who is holding them
Most digital credential systems answer one question well: is this certificate or device valid? They answer another poorly: is the person standing in front of you the holder?
Traditional PKI can confirm a signature. An mDL can confirm device authenticity. Neither alone proves the legitimate holder is the one presenting it.
## The analog gap
A credential can be cryptographically sound and still fail if someone else gets access to it. That break between digital validity and human presence is what we call the analog gap.
FaceLock closes it by binding the credential to a face at issuance, so later checks require the credential and the holder together.
## Why it matters
Stolen or shared credentials undermine trust even when the crypto looks fine. Face-bound verification gives relying parties a way to check the person, not only the document.