Security & Compliance

FaceTec 3D liveness, on-device biometric processing, and SOC 2 Type II controls — built for the highest-stakes identity verification and government workloads

Envoc · SOC 2 Type II

Envoc

SOC 2 Type II — Built for Government & Identity Workloads

FaceLock is created and operated by Envoc, a SOC 2 Type II compliant technology company. When you handle government data and identity, SOC 2 Type II is table stakes.

Achieved: Envoc attained SOC 2 Type II certification in July 2026. FaceLock inherits these controls across all identity products.

For any government agency serious about protecting privacy and managing high-stakes identity transactions, SOC 2 Type II is table stakes.

SOC 2 Type II is an independent audit of controls over security, availability, processing integrity, confidentiality, and privacy — evaluated over a period of time (Type II), not a point-in-time snapshot.

Envoc applies these controls across FaceLock and its other identity products: continuous monitoring and annual re-audits, with results reported to clients.

Why SOC 2 Type II matters for government identity systems

  • Privacy by design: independently audited controls over how FaceLock collects, processes, stores, and deletes biometric and identity data.
  • High-stakes suitability: Digital driver's licenses, benefit credentials, and identity verification involve real-world consequences (access to benefits, voting, travel, age-restricted services).
  • Risk reduction: Reduces attack surface for deepfakes, data exfiltration, and insider threats through audited policies, monitoring, encryption, access controls, and incident response.
  • Procurement readiness: Most state and federal RFPs now require SOC 2 or equivalent attestations.

Sensitive data FaceLock deployments may protect

  • Driver's license and government ID data
  • Personal information (PII)
  • Health insurance information
  • Health and medical information
  • Student education records (diplomas, transcripts, and related records)
  • Other regulated or legally protected personally identifiable information
Aspect SOC 2 Type II Provider (Envoc) Typical Startup / Non-Compliant Provider
Security Controls Rigorously audited trust services criteria Often minimal or ad-hoc controls
Data Handling Maturity Documented policies, procedures, and audits Frequently lacks formal processes
PII Protection Strong controls for security, availability, and confidentiality Higher risk of breaches or poor practices
Government & Enterprise Fit Suitable for regulated and government workloads Often rejected during security reviews
Audit & Accountability Annual independent SOC 2 Type II attestation (achieved July 2026) Rarely have third-party security attestations

Learn more about Envoc →

FaceLock is built and operated by Envoc, a SOC 2 Type II compliant technology company. View Envoc’s SOC 2 Type II attestation →

Certifications & Standards

FaceLock uses FaceTec's 3D liveness SDK — iBeta Level 1 & 2 certified for presentation attack detection — plus SOC 2 Type II controls from Envoc

icon

iBeta Level 1 Certified

Certified for biometric accuracy and anti-spoofing capabilities

icon

iBeta Level 2 Certified

Highest standard for 3D liveness detection and presentation attack detection

icon

NIST IAL2/IAL3 Compliance

Supports Identity Assurance Level 2 and 3 requirements without additional infrastructure

icon

GDPR Compliant

Privacy-by-design architecture supports compliance with GDPR and other privacy regulations

iBeta

Level 1 & 2

NIST

IAL2/IAL3

GDPR

Compliant

FaceTec Biometric Security Architecture

On-device 3D liveness capture with FaceTec, secure facemap processing, and privacy-first design — raw images never leave the user's device

How FaceTec Biometrics Protect Identity

On-Device FaceTec 3D Liveness

Face geometry and liveness data are captured and processed entirely on the user's device using the FaceTec Device SDK. Raw captures and images never leave the device — only a secure facemap (derived biometric template) is created.

Secure Facemap Matching

The facemap is transmitted solely for matching against the enrolled template using FaceTec's server-side verification technology. FaceTec receives only limited anonymized usage data for licensing; no raw images or facemaps are shared with FaceTec or third parties.

Biometric Binding + PKI Signing

At issuance, the live biometric is cryptographically bound to PKI-signed credentials. Only the enrolled individual can present and prove control of the credential.

Zero Data Collection on Verification

FaceLock Reader verification happens entirely locally on the verifier's device with no network call, no data collection, and no central records created — true offline anonymity for everyday checks.

Reduce PII scope: host FaceLock in your environment

Deploy the FaceLock ecosystem in your tenant — not ours — and keep biometric and identity data under your policies and residency requirements.

SaaS-only identity stacks often expand PII and biometric processing into the vendor's cloud, complicating GDPR reviews, data residency, and security exams. FaceLock supports a deployment model where the ecosystem — including FaceTec-powered liveness capture and facemap matching — runs in your Azure, AWS, GCP, or on-premises environment.

Enrollment, 3D liveness checks, IDV workflows, credential issuance, and append-only audit records can remain in your infrastructure. FaceLock SaaS never needs to hold raw biometric payloads or PII to operate the platform.

The only connection FaceLock services require is billing telemetry. On-device FaceTec processing and facemap exchange for matching stay inside your boundary.

Stays in your environment

  • FaceTec 3D liveness capture and facemap generation (on-device)
  • Enrollment, biometric binding, and MFA matching
  • Credential issuance and append-only temporal audit records
  • Integration with your Entra ID, CMS, SIS, or line-of-business systems

Reaches FaceLock (cloud)

  • Billing and usage telemetry only — not biometric payloads or credential content

Note: FaceLock Reader verification is fully local on the verifier device (zero data transmission or collection). Issuance and Authenticator MFA use on-device FaceTec liveness + facemap exchange that can also stay inside your hosted environment.

Compliance & Standards

NIST IAL2/IAL3 Compliance

FaceLock supports NIST Identity Assurance Level 2 and 3 through FaceTec 3D liveness and biometric binding at issuance. By confirming a live person at the moment of enrollment or MFA challenge, FaceLock closes a real gap in PKI- and document-based systems: a valid credential doesn't guarantee the right person is holding it.

GDPR & Privacy Compliance

FaceLock follows strict purpose limitation: biometric data (Face Data) is captured on-device via FaceTec, converted to a facemap, and used solely for the consented authentication or credential issuance purpose. Raw images never leave the device. No biometric data is used for advertising, marketing, profiling, or secondary purposes. This architecture supports GDPR, BIPA, and other biometric privacy requirements.

SOC 2 Type II (Envoc)

FaceLock is built and operated by Envoc, a SOC 2 Type II compliant technology company. FaceTec-powered 3D liveness and on-device biometric processing run under those independently audited controls, the standard government identity data requires. See the full SOC 2 and Envoc details →

Customer-controlled deployment

FaceLock can run in your cloud or on-premises — including FaceTec liveness and facemap processing — so biometric data stays in infrastructure you control. Learn more about customer-controlled hosting →

Standards Participation

FaceLock participates in standards bodies including NIST, W3C, and FIDO Alliance to help shape secure, accessible identity verification standards.

Schedule a Security Review

Our security team can provide detailed security architecture review and compliance guidance