Auto Secure LoginPlatform
ResearchWebApiAndroidResearch programs

Face technology that shows you what it got wrong.

ASL's face research program: guided capture, ID-document checking, 3D likeness, and every failed result kept.

Built for: A security or compliance lead who has to decide whether a vendor's face-matching claim is real · A product owner choosing an identity-check vendor and tired of accuracy numbers nobody can reproduce · A privacy officer who needs a written answer to "whose faces trained this, and did they agree?" · A risk or fraud manager who needs a system that says "I don't know" instead of guessing "approved"

0real people's photographs used to train the face-matching engine
850 identities / 20,400 imagesfrozen generated corpus, split 800 training and 50 development identities with no identity on both sides
12,256deterministic malformed-input cases run against the document parser, media, and receipt boundaries with no escape from their error and privacy contracts
13 attack scenarios, 1 retained as a known limitationdocument attack corpus, with the single injection that got through kept in the record rather than removed

The problem

FaceScan exists because of this.

You get a deck from a face-technology vendor. It says 99.9 percent accurate. It says liveness. It says anti-spoof. You ask which faces that number was measured on, and the answer is a public benchmark you have never seen, shot on cameras you do not own, of people who do not look like your customers. You ask what happened in the runs that failed, and there is no answer, because failures do not go in decks. So you are being asked to accept a number you cannot check, about a system you cannot inspect, for a decision that will eventually be challenged. Then the harder question arrives, usually from legal. Whose faces trained this? Did those people agree to it? Can you produce that agreement if someone asks in writing? Most vendors cannot, because the training images were scraped, or licensed from someone who scraped, or bought under terms nobody read closely. By then the model is already deciding who gets in, so the question stops being academic. It becomes a liability you have already signed for. And the thing you actually needed was narrow. You wanted to know whether the person at the camera is the person on the ID card, and whether that card is genuine. Instead you were offered a system that also searches galleries, guesses age and ethnicity, and sends a face to somebody else's servers to do it. The overreach is what makes the whole category feel radioactive. The missing evidence is what makes it impossible to defend when a regulator, a customer, or your own board finally asks a specific question.

What changes

  • Failures are published with their numbers, in the same document as the successes, including seven lookalike-aware training candidates that were all measured, all rejected, and written down rather than quietly dropped
  • No real person's photograph has been used to train the face-matching engine; the training identities are generated, on purpose, so nobody has to be asked for permission after the fact
  • Real photographs appear only on the measuring side, and every image used to score a model is permanently blocked from ever becoming training data
  • "Review" is a real outcome rather than a soft failure, and any check whose component is unavailable is recorded as unavailable and can never be counted as a pass
  • A known attack that got through is kept in the test record as a known limitation even after a later check caught that specific case
  • Capture guidance is advisory by construction: it can help you frame your face and it structurally cannot make an identity or liveness decision
  • Consent is versioned, signed, and stored apart from the images it authorises, so the scan and the signer's identity are never filed together

What it does

How FaceScan works, start to finish.

FaceScan is the research program behind ASL's face products. It is where face capture, face matching, physical ID-document checking, and 3D likeness reconstruction get built, measured, and often rejected. Its main output is not a shrink-wrapped app. It is evidence: a written, dated, fingerprinted record of what was tried, what the numbers were, what failed, and the explicit decision about whether a capability is allowed anywhere near a live sign-in. As of the current release that decision is still "not yet" for every recognition claim, and the record says so in the same place it says everything else. The capture side is the part a person actually touches. A guided station walks someone through seven views: face forward, then turns of roughly 15, 30 and 45 degrees to each side. A live pose coach names the direction it wants, shows the current angle as an approximate reading rather than a calibrated protractor, and marks where you are against the acceptable band. Only when pose, framing, light, sharpness, and steadiness are all acceptable at once does a one-second hold countdown appear over your face. Move out of position and the countdown resets with the reason visible, so waiting never feels arbitrary. A person can retake any single view by tapping its thumbnail instead of starting the whole sequence again. There is a separate path for young children that uses short natural clips a parent already has, finds the usable angles inside them, and reports exactly which angles are still missing; every automated selection there still requires a human to review the stills. Before the camera opens at all, the participant reads a versioned agreement, ticks each acknowledgement separately, states whether they are the adult participant or the parent or legal guardian, and types a signature. Declining is a supported choice, not a dead end. What survives a session is deliberately small. Continuous camera video is never stored and never uploaded. Seven reviewed still images are kept, with their measurements and a fingerprint of each; frames the guide considered and discarded are not submitted. The signature evidence is stored in a record separate from the scan, so the images and the identity of the person who signed are not filed together. On the children's path the clips are analysed on the parent's own device and the files, their names, and their audio never leave it. The document side is a physical driver-licence check designed to refuse rather than guess. It asks for a randomized, session-bound sequence: the front, tilt sweeps in both directions with four time-spaced frames each, and the barcode side. It then checks that the barcode is structurally valid, that the dates are current, that the six required printed fields agree exactly with the barcode, that the card layout matches a known design for that issuing state, and that a reflective security feature genuinely travels across the card as it tilts while the rest of the card stays put. Three outcomes exist: pass, review, and fail. A full pass additionally requires a match from an approved issuer record check and a pass from the live face comparison; any check whose component is unavailable is recorded as unavailable and can never be counted as a quiet pass. Because no approved issuer connection is configured, the honest current answer for a real card is "review", and the code returns exactly that. The printed-text reader is a separate optional component that stays switched off unless five matching runtime checks are supplied together, and it has not been packaged for a target machine yet. Automated layout coverage today is the current adult Colorado and Arizona designs; legacy and under-21 variants of those two, and every other state, are routed to a human. The matching side was written from scratch rather than starting from someone else's downloaded face model, and no real person's photograph has been used to train it. The training faces are generated identities rendered under controlled poses and lighting, precisely so that nobody's likeness is taken and then apologised for later. Real photographs have appeared only on the evaluation side, and every image ever used to score a model is permanently blocked from ever becoming training data. Candidates are scored against identities the model has never seen, at thresholds fixed before the run, and a candidate that fails is written down and kept. A whole family of seven lookalike-aware candidates was built, measured, and rejected in one such round, and the numbers that killed them sit in the record beside the numbers that looked promising. A separate intake gate would refuse any future package of real faces that lacked documented consent, commercial rights, ten varied views per person, and clean separation between training, tuning and evaluation people. So far it has admitted nothing. The likeness side turns a completed scan into a game-ready 3D head, and it is deliberately slow to commit. Every build re-checks all seven images against their fingerprints, requires the turns to actually increase in both directions, and refuses to start the expensive reconstruction if the views disagree with each other. It then produces two comparable candidates, renders four matched angles of each, and stops. A person compares them and must confirm ten specific checks by name before either can be chosen, and that choice is written once and cannot be overwritten. A third and newer candidate reconstructs real facial volume from all seven views; in the current release it is published for viewing and download only and carries no selection control at all, because the three-way review contract has not been designed yet. The record is candid that the first real scan was rejected on presentation grounds and rebuilt. The heads are head-only: the back of the skull is inferred, the ears are generated, and there is no hair, body, or animation.

Features

Everything in the current release.

Each of these is built and working today. Nothing on this list is a roadmap item.

01

A capture guide that tells you why it is waiting

Most face capture just says "hold still" and then fails silently. This one names the direction it wants, shows the angle it is currently reading as an approximate value, and marks where you are against the acceptable band. When pose, framing, light, sharpness, and steadiness are all good together, a one-second countdown and progress ring appear over your face. Drift out and the countdown resets with the reason visible, so nobody is left standing there guessing.

02

Seven views, and you can redo just one

A scan is face-forward plus turns of roughly 15, 30 and 45 degrees each way. At every angle the guide watches a short run of steady frames and keeps the best one, weighing image quality against how close you got to the requested turn. If view five went badly you tap its thumbnail and retake from there, and the earlier views stay. Nobody has to sit through the whole sequence again because of one bad frame.

03

Consent recorded before the camera opens

The camera panel stays hidden until the participant has read a versioned agreement, ticked each acknowledgement separately, stated whether they are the adult participant or a parent or legal guardian, and typed a signature. Declining is offered as a real choice, with a generic face and voice available instead. The signature evidence is stored apart from the scan; the scan carries only a random receipt reference and the agreement version, so the images and the signer's identity are not filed together.

04

A path built for children who will not hold a pose

Asking a toddler to hold seven positions does not work. Instead a parent picks up to a dozen short clips they already have. The analysis happens on their own device: it scores each moment for angle, sharpness, mouth position, and neutral expression, prefers one clean sweep from a single five-second window rather than stitching unrelated moments together, and reports precisely which angles are still missing. The video files, their names, and their audio never leave the device, only the seven reviewed stills can be saved, and every automated selection still has to pass a human review of those stills.

05

The full video is never stored

Continuous camera video is never written to disk and never uploaded. What survives a session is seven reviewed still images, their measurements, quality readings, and a fingerprint of each. Frames the guide considered and rejected are not submitted or retained. This is enforced in the capture path itself, not a preference somebody could forget to switch on.

06

A person decides, against ten named checks

A finished build stops and waits. It shows two comparable head candidates side by side across four matched angles and offers both files for download. Nothing is selected until a named reviewer confirms ten specific things: front likeness, both three-quarter views, profile silhouette, face boundary, full-cranium proportion, head-to-neck proportion, neck transition, texture alignment, and no visible artifacts. The resulting decision is written once, bound to those exact files, and cannot be quietly replaced later. The newest volumetric head sits outside that form entirely and has no selection control at all.

07

ID checking that answers "review" when it should

The document check has three outcomes and "review" is a first-class one. A missing issuer confirmation, an unreadable barcode, an ordinary bad photo, or an unsupported card design all produce review rather than a guess in either direction. Any check whose component is unavailable is recorded as unavailable and can never be counted as a pass. Evidence of replay, tampering, an expired card, an issuer mismatch, or printed data that disagrees with the barcode produces a fail.

08

The card has to move, and the same card has to stay

A single photo of a licence is easy to fake, so the check asks for a randomized, session-bound live sequence: the front, a sweep each way with exactly four time-spaced frames per sweep, and the barcode side. It then requires that both tilt views track the same physical front, that the two sweeps move in genuinely opposite directions, and that a reflective feature travels through the expected zone while the rest of the card stays unchanged. Showing the front again in place of the back is rejected outright.

09

Printed text and barcode must agree, without either being exposed

Six fields are read from the printed side and compared with the independently decoded barcode: document number, family name, given names, birth date, expiry, and issuing state. If any pair disagrees, or the same field appears twice with different values, the check stops. The values themselves never travel back to the browser and never enter the audit record; only the field names and the result do. The printed-text reader is optional and off by default, and it starts only when five matching runtime checks are all supplied together, so a partial or wrong reader cannot be silently accepted.

10

State coverage stated honestly, card design by card design

The barcode's issuer number is bound to its state before any visual work begins, and a disagreement between the two fails immediately. Automated layout coverage today is the current adult Colorado and Arizona designs, each with its own field positions and its own security-feature zone, and the Arizona profile is further bounded to cards issued from March 2023 onward. Legacy and under-21 variants of those two, and every other state, are recognised and routed to a human rather than approximated.

11

Attack testing that keeps its own failures

A deterministic corpus of thirteen fictional attacks and controls covers screen moire, display pixels, motion blur, glare, extreme angles, edited printed data, re-encoded replay, card substitution, and front-shown-as-back. Twelve behaved inside their declared boundary. One deliberately targeted digital injection got past both image checks, and rather than being quietly fixed and forgotten it is frozen in the record as a known limitation. A later four-case moving-reflection suite now catches that specific injection in the tested case, but the record keeps the original result because it proves image analysis alone cannot establish that a physical card was present.

12

A face model trained on faces nobody owns

The matching engine was written from scratch rather than starting from a downloaded face model, and no private photo, relative's photo, driver-licence image, or live camera frame has been used to train it. Its training faces are generated identities rendered under controlled poses and lighting. That choice costs accuracy today and the record says so plainly, but it means there is no person anywhere who can ask why their face ended up inside the model.

13

An image used to score a model can never train one

Real photographs have a place in this work, but only on the measuring side. Every image ever consumed by an evaluation is fingerprinted and added to a permanent denylist that the training loader checks before it will accept anything: 526 hashes are blocked today. The intake gate refuses a package outright if any of its images appear on that list, which is what stops the oldest quiet failure in face research, scoring a model on pictures it was already shown.

14

A gate that rejects volume without rights

Before any real face data could be trained on, it has to clear a mechanical gate: a hash-pinned executed agreement, explicit commercial rights covering both the images and the resulting model, adults-only status with documented consent, at least ten varied views per person including left, front, and right under more than one lighting condition, and every person assigned to exactly one of training, tuning, or final evaluation. Overlap with previously evaluated images is refused outright. To date the gate has admitted nothing, which is the point of having one.

15

Every artifact is fingerprinted and re-checked before it is shown

Images, models, review renders, receipts, and decisions all carry fingerprints, and those are recomputed each time something is served or consumed rather than trusted from a stored label. Build state survives a restart, failed attempts are preserved instead of overwritten, and a retry archives the previous attempt before rebuilding the same scan. Nothing shown in the browser reveals where the originals live on the machine holding them.

Proof

Numbers we can stand behind.

Every figure below comes from the product's own release record or test suite, not from a marketing estimate.

0real people's photographs used to train the face-matching engine
850 identities / 20,400 imagesfrozen generated corpus, split 800 training and 50 development identities with no identity on both sides
12,256deterministic malformed-input cases run against the document parser, media, and receipt boundaries with no escape from their error and privacy contracts
13 attack scenarios, 1 retained as a known limitationdocument attack corpus, with the single injection that got through kept in the record rather than removed
7 of 7lookalike-aware training candidates measured and rejected in one round, every failing number recorded
72 / 72automated document-checking tests passing
53 / 53automated checks passing on the existing deployed face-comparison engine, unchanged by this research
63 / 63 and 11 / 11automated checks passing on the most recent phone-capture release, including 330 reproductions of a pose-validation defect that was fixed
  • Nothing is promoted on generated evidence alone; a candidate must beat the current behaviour on people and data it has never seen before it moves anywhere
  • State-by-state ID coverage is enumerated card design by card design instead of implied, with everything uncovered sent to a human

Where it runs

Surfaces and status.

WEB
Web · 0.14.0Live, access-controlled - credentials required, single operator, not a public demo
WEB
Web · 0.14.0Live, access-controlled - natural-video capture route for young children, on the same single-operator station
API
Api · 0.1.0-dev.7In development - physical ID-document validation, not deployed and not authorised to approve anything
WEB
Web · 0.5.0-dev.19In development - camera guidance for the live face-verification product, staged and tested against that product's candidate build but not deployed
AND
Android · not releasedDeferred by decision - camera work not started; the separate physical-device document spoof matrix is written but recorded as incomplete because no handset was attached

Status as of 2026-09-02. FaceScan 0.14.0 runs as an access-controlled capture station for a single operator. Its address answered on 2026-09-02 with an HTTP 401 owner-access challenge, a valid certificate for that exact hostname, and camera permission restricted to the same origin., updated 2026-09-01, records the release and states that the current reconstruction package is review-only, with selection and production admission both explicitly not authorised. RESULTS.md, dated 2026-08-24, records the current matching artifact as commercial use: no, runtime activation: no. The document-checking package (0.1.0-dev.7) records that every decision it produces carries an explicit not-authorised-to-authenticate marker and that it is not deployed. The repository's own headline treats the recognizer as unproven research rather than a shipped engine, and no result in it has been promoted to a live product.

What is new

Recent progress.

This product ships often. The most recent verified changes, newest first.

  • Release 0.14.0 shipped a materially better scan-derived 3D head: all seven captured views now feed the fit, the face volume is welded into a closed head instead of a flat photo sitting on a second skull, and the topology gate measured zero boundary edges and zero non-manifold edges. It is published for review only, has no selection control, and cannot authorise anything.

  • Phone capture now carries the measured head angle from the device through to the server, so the same angle that approved the on-screen countdown is the one validated on save; 63 of 63 and 11 of 11 automated checks passed, including 330 reproductions of the pose defect that was fixed.

  • The guided station became reachable from a phone over an access-controlled address so mobile browsers can request camera permission, with a live pose coach, a hold countdown, and visible startup stages added after a real handset failed silently. The natural-video path for young children landed the same day.

  • The physical driver-licence check gained a randomized live-card sequence, a four-frame moving-reflection challenge, printed-versus-barcode field agreement, and an issuer integration boundary that currently reports itself unconfigured; the first real seven-view scan completed its build and stopped, correctly, at human review.

  • A family-aware training round of seven candidates was completed and rejected outright with every failing number recorded, and an earlier claim that one blend was a zero-regression replacement was corrected and withdrawn.

Pricing

Pricing for FaceScan is quoted after a short conversation about your situation, because the right scope differs from one team to the next. There is no charge for that conversation.

Ask about pricing
Honest by default. We publish the standard each product meets and the limits of each safeguard next to the feature, not in a footnote. If you cannot find an answer on this page, the assistant in the corner reads only these pages and will say so rather than guess.

Questions buyers ask

Straight answers.

Can I use this to verify identities today?

Not on its own, and we would rather say that than sell you something that prints "approved" when it does not know. The document check returns "review" for a real licence today because the state issuer confirmation it requires is not connected, and every decision it produces carries an explicit marker saying it is not authorised to authenticate anyone. If you need one-to-one face comparison running in production right now, that is ASL Verifier, which is deliberately narrow and publishes its own limits. FaceScan is the research program that has to clear its gates before any of it reaches a live sign-in.

We already use a face-verification vendor. Why would we look at this?

Because of the question your current vendor probably cannot answer: which faces trained the model, and can you produce their agreement? FaceScan's engine has never been trained on a real person's photograph, and the gate that would let real faces in refuses any package lacking documented consent, commercial rights, ten varied views per person, and clean separation between training and evaluation people. It has admitted nothing so far. If that question ever arrives in writing, the difference is the entire answer.

What actually happens to my face after a scan?

The camera video is never written to disk and never uploaded. What is kept is seven reviewed still images, their measurements, and a fingerprint of each. Frames the guide looked at and rejected are not submitted at all. Your signed agreement is stored in a separate record, and the scan carries only a random receipt reference and the agreement version, so the images and the identity of the person who signed are not filed together. If you decline the agreement, a generic face and voice are available instead.

What does it cost?

There is no published price and nothing to buy self-service. FaceScan is a research program rather than a packaged product, and pretending otherwise would be the first dishonest thing on this page. If you have a specific problem, such as ID checking for a state we do not yet cover, consented likeness capture, or an evaluation you have to defend to a regulator, the right next step is a conversation about scope rather than a plan selection.

What happens if we start with you and then stop, or you shut this down?

The artifacts are ordinary files with fingerprints, held where you can reach them, not rows in a service only we can read. A completed scan produces standard game-ready 3D files you download directly from the review page. Consent records, review decisions, and build receipts are plain, self-describing documents. Nothing here needs ASL running to stay readable, and nothing is held back as a retention mechanism.

How is this different from ASL Verifier? They both do faces.

Verifier is the deployed product: it compares an ID portrait to a live selfie, one to one, on the machine, and fails closed. It is narrow on purpose and publishes what it cannot do. FaceScan is the workshop behind it, where camera guidance, physical document checking, matching candidates, and 3D likeness get developed and, more often than not, rejected. Work crosses from FaceScan to Verifier only after it beats the current behaviour on data it has never seen, and most of it has not.

Can it detect a fake ID?

It catches a lot and refuses to claim more than that. It requires a live randomized sequence rather than a photo, checks that both tilt views track the same physical card and move in genuinely opposite directions, requires a reflective feature to travel through the expected zone while the rest of the card stays put, and requires the six printed fields to agree exactly with the barcode. Screen moire, display pixels, replay, and showing the front in place of the back are rejected. But one targeted digital injection got past both image checks in our own attack corpus and we kept it in the record, because it proves image analysis alone cannot establish that a physical card was really there. Real confidence needs the issuer's own record check, which is not connected yet, and none of this has been confirmed against a genuine card.

Is it safe for a child to be scanned?

The path exists and it was designed carefully: a parent or legal guardian picks short clips they already have, the analysis happens on their own device, the videos and audio never leave it, only seven reviewed stills can be saved, a human still has to review every automated selection, and the guardian's authority is a separately recorded acknowledgement. But we will not tell you it is cleared. Participation by minors needs jurisdiction-specific legal review before any public launch, that review has not happened, and the product itself says so on screen.

What should I know before I rely on it?

We would rather you hear this from us than discover it later. As of 2026-09-02:

  • Nothing in FaceScan is authorised to approve a login or admit a face into a live product. Every document decision carries an explicit not-authorised-to-authenticate marker, and the separate identity gateway remains the only thing that grants access.
  • The face-matching engine has never been trained on real faces. Every accuracy figure recorded so far comes from generated identities and does not predict performance on real people, real cameras, or real lighting. It is not a replacement for the deployed comparison engine and is not offered as one.
  • Real photographs have been used on the evaluation side, never for training. The scored diagnostic that used them was tiny - 14 genuine and 5 impostor comparisons, four of them close relatives - and is far too small to support any population false-accept claim.
  • Automated ID card layouts cover the current adult Colorado and Arizona designs only, and the Arizona profile is bounded to cards issued from March 2023 onward. Legacy and under-21 variants of those two, and every other state, are routed to a human.
  • No approved connection to a state issuer record check is configured. Without one, a real card returns "review", never "pass". Changing that requires an executed agreement with an issuer gateway that does not exist yet.
  • The printed-text reader is optional and switched off by default. It starts only when five matching runtime checks are supplied together, and the component in use today is local test evidence that has not been packaged or licence-cleared for a target machine.
  • One deliberately targeted digital injection passed both image checks in the recorded attack corpus and is retained as a known limitation. A later moving-reflection check catches that specific case, but still-image analysis alone cannot prove a physical card was in front of the camera.
  • Physical-device spoof and injection testing is incomplete. The 14-case device matrix is written and locally validated, but the last attempt found no attached handset and the run is recorded as incomplete rather than passed.
  • Real-card confirmation has not happened. Five consented sample licences were reviewed and none was usable, and a scan of 166 images found no readable barcode at all. Colorado is recorded as unresolved and no consented current Arizona sample has even been identified.
  • The reconstructed head is head-only. The back of the skull is inferred from the scan boundary, the ears are generated rather than scanned, and there is no hair, body, or animation. No candidate has been approved as a likeness of anyone, and the newest one cannot be selected at all.

Face technology that shows you what it got wrong.

ASL's face research program: guided capture, ID-document checking, 3D likeness, and every failed result kept.

Prefer email? contact@autosecurelogin.com