Logo SealfieSealfie
Security

Your biometrics never leave your phone.

Sealfie stores no biometric data, because it receives none. Here is what actually happens when you approve a request.

The principle

Identity is proven by a key, not by a face

When you create your account, Sealfie generates a P-256 cryptographic key pair inside your phone's secure element — the Secure Enclave on iPhone, StrongBox / TEE on Android. The private key is born there and stays there: never copied into memory, never transmitted, never backed up anywhere else.

Your fingerprint or face only authorises the use of that key, with the operating system, on the device. Neither the app nor our servers ever see any biometric data. What we receive is a signature — mathematical proof that someone holding your phone, and authenticated by it, approved this specific request.

What follows

Three concrete consequences

Nothing to steal from us

A database of biometric templates is a target. We do not have one. Compromising our servers gives access to no fingerprint, no face, no private key.

Nothing to extract from the device

The private key never leaves the secure silicon. Malware on the phone — even a compromised operating system — cannot exfiltrate it.

No degraded mode

A device without a secure element is refused, not accepted with weaker security. We would rather not run than run badly.

The photo

The selfie is a record, not an identifier

The photo taken at the moment of a verification is kept as a timestamped visual record attached to the file. We extract no template from it and run no facial recognition: identity is already established by your key's signature.

The photo answers a different question — what did the scene look like at the moment of approval — which helps an auditor reconstruct a case, but it is not what identifies you.

The log

Sealed, timestamped, third-party verifiable

Every verification is recorded in a sealed, timestamped log. The seal lets an auditor, an insurer or counsel establish that an entry has not been altered after the fact, without having to take our word for it.

Sealfie does not promise you will win a lawsuit — no tool can. What it produces is irrefutable traces that someone other than us can examine.

A technical question?

Implementation details matter to your CISO more than this page can hold. Write to us — the team answers.

Contact us →

See also: privacy policy · how a verification works