FaceScan — Source library
Public documentation snapshot: 2026-09-08
Face technology that shows you what it got wrong.
ASL's face research program: guided capture, ID-document checking, 3D likeness, and every failed result kept.
Face technology that shows you what it got wrong.
Built for: A security or compliance lead who has to decide whether a vendor's face-matching claim is real · A product owner choosing an identity-check vendor and tired of accuracy numbers nobody can reproduce · A privacy officer who needs a written answer to "whose faces trained this, and did they agree?" · A risk or fraud manager who needs a system that says "I don't know" instead of guessing "approved"
FaceScan exists because of this.
You get a deck from a face-technology vendor. It says 99.9 percent accurate. It says liveness. It says anti-spoof. You ask which faces that number was measured on, and the answer is a public benchmark you have never seen, shot on cameras you do not own, of people who do not look like your customers. You ask what happened in the runs that failed, and there is no answer, because failures do not go in decks. So you are being asked to accept a number you cannot check, about a system you cannot inspect, for a decision that will eventually be challenged. Then the harder question arrives, usually from legal. Whose faces trained this? Did those people agree to it? Can you produce that agreement if someone asks in writing? Most vendors cannot, because the training images were scraped, or licensed from someone who scraped, or bought under terms nobody read closely. By then the model is already deciding who gets in, so the question stops being academic. It becomes a liability you have already signed for. And the thing you actually needed was narrow. You wanted to know whether the person at the camera is the person on the ID card, and whether that card is genuine. Instead you were offered a system that also searches galleries, guesses age and ethnicity, and sends a face to somebody else's servers to do it. The overreach is what makes the whole category feel radioactive. The missing evidence is what makes it impossible to defend when a regulator, a customer, or your own board finally asks a specific question.
FaceScan exists because of this.
Failures are published with their numbers, in the same document as the successes, including seven lookalike-aware training candidates that were all measured, all rejected, and written down rather than quietly dropped
FaceScan exists because of this.
No real person's photograph has been used to train the face-matching engine; the training identities are generated, on purpose, so nobody has to be asked for permission after the fact
FaceScan exists because of this.
Real photographs appear only on the measuring side, and every image used to score a model is permanently blocked from ever becoming training data
FaceScan exists because of this.
"Review" is a real outcome rather than a soft failure, and any check whose component is unavailable is recorded as unavailable and can never be counted as a pass
FaceScan exists because of this.
A known attack that got through is kept in the test record as a known limitation even after a later check caught that specific case
FaceScan exists because of this.
Capture guidance is advisory by construction: it can help you frame your face and it structurally cannot make an identity or liveness decision
FaceScan exists because of this.
Consent is versioned, signed, and stored apart from the images it authorises, so the scan and the signer's identity are never filed together
Everything in the current release.
Each of these is built and working today. Nothing on this list is a roadmap item.
A capture guide that tells you why it is waiting
Most face capture just says "hold still" and then fails silently. This one names the direction it wants, shows the angle it is currently reading as an approximate value, and marks where you are against the acceptable band. When pose, framing, light, sharpness, and steadiness are all good together, a one-second countdown and progress ring appear over your face. Drift out and the countdown resets with the reason visible, so nobody is left standing there guessing.
Seven views, and you can redo just one
A scan is face-forward plus turns of roughly 15, 30 and 45 degrees each way. At every angle the guide watches a short run of steady frames and keeps the best one, weighing image quality against how close you got to the requested turn. If view five went badly you tap its thumbnail and retake from there, and the earlier views stay. Nobody has to sit through the whole sequence again because of one bad frame.
Consent recorded before the camera opens
The camera panel stays hidden until the participant has read a versioned agreement, ticked each acknowledgement separately, stated whether they are the adult participant or a parent or legal guardian, and typed a signature. Declining is offered as a real choice, with a generic face and voice available instead. The signature evidence is stored apart from the scan; the scan carries only a random receipt reference and the agreement version, so the images and the signer's identity are not filed together.
A path built for children who will not hold a pose
Asking a toddler to hold seven positions does not work. Instead a parent picks up to a dozen short clips they already have. The analysis happens on their own device: it scores each moment for angle, sharpness, mouth position, and neutral expression, prefers one clean sweep from a single five-second window rather than stitching unrelated moments together, and reports precisely which angles are still missing. The video files, their names, and their audio never leave the device, only the seven reviewed stills can be saved, and every automated selection still has to pass a human review of those stills.
The full video is never stored
Continuous camera video is never written to disk and never uploaded. What survives a session is seven reviewed still images, their measurements, quality readings, and a fingerprint of each. Frames the guide considered and rejected are not submitted or retained. This is enforced in the capture path itself, not a preference somebody could forget to switch on.
A person decides, against ten named checks
A finished build stops and waits. It shows two comparable head candidates side by side across four matched angles and offers both files for download. Nothing is selected until a named reviewer confirms ten specific things: front likeness, both three-quarter views, profile silhouette, face boundary, full-cranium proportion, head-to-neck proportion, neck transition, texture alignment, and no visible artifacts. The resulting decision is written once, bound to those exact files, and cannot be quietly replaced later. The newest volumetric head sits outside that form entirely and has no selection control at all.
ID checking that answers "review" when it should
The document check has three outcomes and "review" is a first-class one. A missing issuer confirmation, an unreadable barcode, an ordinary bad photo, or an unsupported card design all produce review rather than a guess in either direction. Any check whose component is unavailable is recorded as unavailable and can never be counted as a pass. Evidence of replay, tampering, an expired card, an issuer mismatch, or printed data that disagrees with the barcode produces a fail.
The card has to move, and the same card has to stay
A single photo of a licence is easy to fake, so the check asks for a randomized, session-bound live sequence: the front, a sweep each way with exactly four time-spaced frames per sweep, and the barcode side. It then requires that both tilt views track the same physical front, that the two sweeps move in genuinely opposite directions, and that a reflective feature travels through the expected zone while the rest of the card stays unchanged. Showing the front again in place of the back is rejected outright.
Printed text and barcode must agree, without either being exposed
Six fields are read from the printed side and compared with the independently decoded barcode: document number, family name, given names, birth date, expiry, and issuing state. If any pair disagrees, or the same field appears twice with different values, the check stops. The values themselves never travel back to the browser and never enter the audit record; only the field names and the result do. The printed-text reader is optional and off by default, and it starts only when five matching runtime checks are all supplied together, so a partial or wrong reader cannot be silently accepted.
State coverage stated honestly, card design by card design
The barcode's issuer number is bound to its state before any visual work begins, and a disagreement between the two fails immediately. Automated layout coverage today is the current adult Colorado and Arizona designs, each with its own field positions and its own security-feature zone, and the Arizona profile is further bounded to cards issued from March 2023 onward. Legacy and under-21 variants of those two, and every other state, are recognised and routed to a human rather than approximated.
Attack testing that keeps its own failures
A deterministic corpus of thirteen fictional attacks and controls covers screen moire, display pixels, motion blur, glare, extreme angles, edited printed data, re-encoded replay, card substitution, and front-shown-as-back. Twelve behaved inside their declared boundary. One deliberately targeted digital injection got past both image checks, and rather than being quietly fixed and forgotten it is frozen in the record as a known limitation. A later four-case moving-reflection suite now catches that specific injection in the tested case, but the record keeps the original result because it proves image analysis alone cannot establish that a physical card was present.
A face model trained on faces nobody owns
The matching engine was written from scratch rather than starting from a downloaded face model, and no private photo, relative's photo, driver-licence image, or live camera frame has been used to train it. Its training faces are generated identities rendered under controlled poses and lighting. That choice costs accuracy today and the record says so plainly, but it means there is no person anywhere who can ask why their face ended up inside the model.
An image used to score a model can never train one
Real photographs have a place in this work, but only on the measuring side. Every image ever consumed by an evaluation is fingerprinted and added to a permanent denylist that the training loader checks before it will accept anything: 526 hashes are blocked today. The intake gate refuses a package outright if any of its images appear on that list, which is what stops the oldest quiet failure in face research, scoring a model on pictures it was already shown.
A gate that rejects volume without rights
Before any real face data could be trained on, it has to clear a mechanical gate: a hash-pinned executed agreement, explicit commercial rights covering both the images and the resulting model, adults-only status with documented consent, at least ten varied views per person including left, front, and right under more than one lighting condition, and every person assigned to exactly one of training, tuning, or final evaluation. Overlap with previously evaluated images is refused outright. To date the gate has admitted nothing, which is the point of having one.
Every artifact is fingerprinted and re-checked before it is shown
Images, models, review renders, receipts, and decisions all carry fingerprints, and those are recomputed each time something is served or consumed rather than trusted from a stored label. Build state survives a restart, failed attempts are preserved instead of overwritten, and a retry archives the previous attempt before rebuilding the same scan. Nothing shown in the browser reveals where the originals live on the machine holding them.
Numbers we can stand behind.
Every figure below comes from the product's own release record or test suite, not from a marketing estimate.
Numbers we can stand behind.
Nothing is promoted on generated evidence alone; a candidate must beat the current behaviour on people and data it has never seen before it moves anywhere
Numbers we can stand behind.
State-by-state ID coverage is enumerated card design by card design instead of implied, with everything uncovered sent to a human
Surfaces and status.
Status as of 2026-09-02. FaceScan 0.14.0 runs as an access-controlled capture station for a single operator. Its address answered on 2026-09-02 with an HTTP 401 owner-access challenge, a valid certificate for that exact hostname, and camera permission restricted to the same origin., updated 2026-09-01, records the release and states that the current reconstruction package is review-only, with selection and production admission both explicitly not authorised. RESULTS.md, dated 2026-08-24, records the current matching artifact as commercial use: no, runtime activation: no. The document-checking package (0.1.0-dev.7) records that every decision it produces carries an explicit not-authorised-to-authenticate marker and that it is not deployed. The repository's own headline treats the recognizer as unproven research rather than a shipped engine, and no result in it has been promoted to a live product.
Worth more together.
Products on this platform share one sign-in, one support queue, and one engineering standard. These pair naturally with FaceScan.
ASL Verifier
The narrow, deployed face product FaceScan feeds. Verifier does one-to-one comparison on the box and fails closed; FaceScan is where the capture guidance, document checks, and matching candidates that might one day improve it are built and measured.
ASL Timestamp Anchor
FaceScan's consent records and review decisions are written once and fingerprinted. Timestamp Anchor adds independent proof of when each of those records existed, verifiable offline and without ASL involved.
ASL Scan
The same posture applied to security assessments: measure only what you are authorised to measure, seal the result, and never claim certification. Useful for anyone who has to show that the machine handling face capture is itself hardened.
ASL Vault
Face capture produces material that has to be stored under strict access rules. Vault is the credential and secret store built to stay sealed while still accepting writes.
Recent progress.
This product ships often. The most recent verified changes, newest first.
Recent progress.
2026-09-01 Release 0.14.0 shipped a materially better scan-derived 3D head: all seven captured views now feed the fit, the face volume is welded into a closed head instead of a flat photo sitting on a second skull, and the topology gate measured zero boundary edges and zero non-manifold edges. It is published for review only, has no selection control, and cannot authorise anything.
Recent progress.
2026-08-31 Phone capture now carries the measured head angle from the device through to the server, so the same angle that approved the on-screen countdown is the one validated on save; 63 of 63 and 11 of 11 automated checks passed, including 330 reproductions of the pose defect that was fixed.
Recent progress.
2026-08-30 The guided station became reachable from a phone over an access-controlled address so mobile browsers can request camera permission, with a live pose coach, a hold countdown, and visible startup stages added after a real handset failed silently. The natural-video path for young children landed the same day.
Recent progress.
2026-08-29 The physical driver-licence check gained a randomized live-card sequence, a four-frame moving-reflection challenge, printed-versus-barcode field agreement, and an issuer integration boundary that currently reports itself unconfigured; the first real seven-view scan completed its build and stopped, correctly, at human review.
Recent progress.
2026-08-28 A family-aware training round of seven candidates was completed and rejected outright with every failing number recorded, and an earlier claim that one blend was a zero-regression replacement was corrected and withdrawn.
Recent progress.
Pricing for FaceScan is quoted after a short conversation about your situation, because the right scope differs from one team to the next. There is no charge for that conversation.
Can I use this to verify identities today?
Not on its own, and we would rather say that than sell you something that prints "approved" when it does not know. The document check returns "review" for a real licence today because the state issuer confirmation it requires is not connected, and every decision it produces carries an explicit marker saying it is not authorised to authenticate anyone. If you need one-to-one face comparison running in production right now, that is ASL Verifier, which is deliberately narrow and publishes its own limits. FaceScan is the research program that has to clear its gates before any of it reaches a live sign-in.
We already use a face-verification vendor. Why would we look at this?
Because of the question your current vendor probably cannot answer: which faces trained the model, and can you produce their agreement? FaceScan's engine has never been trained on a real person's photograph, and the gate that would let real faces in refuses any package lacking documented consent, commercial rights, ten varied views per person, and clean separation between training and evaluation people. It has admitted nothing so far. If that question ever arrives in writing, the difference is the entire answer.
What actually happens to my face after a scan?
The camera video is never written to disk and never uploaded. What is kept is seven reviewed still images, their measurements, and a fingerprint of each. Frames the guide looked at and rejected are not submitted at all. Your signed agreement is stored in a separate record, and the scan carries only a random receipt reference and the agreement version, so the images and the identity of the person who signed are not filed together. If you decline the agreement, a generic face and voice are available instead.
What does it cost?
There is no published price and nothing to buy self-service. FaceScan is a research program rather than a packaged product, and pretending otherwise would be the first dishonest thing on this page. If you have a specific problem, such as ID checking for a state we do not yet cover, consented likeness capture, or an evaluation you have to defend to a regulator, the right next step is a conversation about scope rather than a plan selection.
What happens if we start with you and then stop, or you shut this down?
The artifacts are ordinary files with fingerprints, held where you can reach them, not rows in a service only we can read. A completed scan produces standard game-ready 3D files you download directly from the review page. Consent records, review decisions, and build receipts are plain, self-describing documents. Nothing here needs ASL running to stay readable, and nothing is held back as a retention mechanism.
How is this different from ASL Verifier? They both do faces.
Verifier is the deployed product: it compares an ID portrait to a live selfie, one to one, on the machine, and fails closed. It is narrow on purpose and publishes what it cannot do. FaceScan is the workshop behind it, where camera guidance, physical document checking, matching candidates, and 3D likeness get developed and, more often than not, rejected. Work crosses from FaceScan to Verifier only after it beats the current behaviour on data it has never seen, and most of it has not.
Can it detect a fake ID?
It catches a lot and refuses to claim more than that. It requires a live randomized sequence rather than a photo, checks that both tilt views track the same physical card and move in genuinely opposite directions, requires a reflective feature to travel through the expected zone while the rest of the card stays put, and requires the six printed fields to agree exactly with the barcode. Screen moire, display pixels, replay, and showing the front in place of the back are rejected. But one targeted digital injection got past both image checks in our own attack corpus and we kept it in the record, because it proves image analysis alone cannot establish that a physical card was really there. Real confidence needs the issuer's own record check, which is not connected yet, and none of this has been confirmed against a genuine card.
Is it safe for a child to be scanned?
The path exists and it was designed carefully: a parent or legal guardian picks short clips they already have, the analysis happens on their own device, the videos and audio never leave it, only seven reviewed stills can be saved, a human still has to review every automated selection, and the guardian's authority is a separately recorded acknowledgement. But we will not tell you it is cleared. Participation by minors needs jurisdiction-specific legal review before any public launch, that review has not happened, and the product itself says so on screen.
What should I know before I rely on it?
We would rather you hear this from us than discover it later. As of 2026-09-02:
What should I know before I rely on it?
Nothing in FaceScan is authorised to approve a login or admit a face into a live product. Every document decision carries an explicit not-authorised-to-authenticate marker, and the separate identity gateway remains the only thing that grants access.
What should I know before I rely on it?
The face-matching engine has never been trained on real faces. Every accuracy figure recorded so far comes from generated identities and does not predict performance on real people, real cameras, or real lighting. It is not a replacement for the deployed comparison engine and is not offered as one.
What should I know before I rely on it?
Real photographs have been used on the evaluation side, never for training. The scored diagnostic that used them was tiny - 14 genuine and 5 impostor comparisons, four of them close relatives - and is far too small to support any population false-accept claim.
What should I know before I rely on it?
Automated ID card layouts cover the current adult Colorado and Arizona designs only, and the Arizona profile is bounded to cards issued from March 2023 onward. Legacy and under-21 variants of those two, and every other state, are routed to a human.
What should I know before I rely on it?
No approved connection to a state issuer record check is configured. Without one, a real card returns "review", never "pass". Changing that requires an executed agreement with an issuer gateway that does not exist yet.
What should I know before I rely on it?
The printed-text reader is optional and switched off by default. It starts only when five matching runtime checks are supplied together, and the component in use today is local test evidence that has not been packaged or licence-cleared for a target machine.
What should I know before I rely on it?
One deliberately targeted digital injection passed both image checks in the recorded attack corpus and is retained as a known limitation. A later moving-reflection check catches that specific case, but still-image analysis alone cannot prove a physical card was in front of the camera.
What should I know before I rely on it?
Physical-device spoof and injection testing is incomplete. The 14-case device matrix is written and locally validated, but the last attempt found no attached handset and the run is recorded as incomplete rather than passed.
What should I know before I rely on it?
Real-card confirmation has not happened. Five consented sample licences were reviewed and none was usable, and a scan of 166 images found no readable barcode at all. Colorado is recorded as unresolved and no consented current Arizona sample has even been identified.
What should I know before I rely on it?
The reconstructed head is head-only. The back of the skull is inferred from the scan boundary, the ears are generated rather than scanned, and there is no hair, body, or animation. No candidate has been approved as a likeness of anyone, and the newest one cannot be selected at all.
Face technology that shows you what it got wrong.
Prefer email? contact@autosecurelogin.com