Verify faces.
Even offline.
Face verification that runs on the phone, works with no signal and has liveness built in. Add it to your app in about 10 minutes.
Running events or ticketing?
Pick your platform to see the code
Ten lines to your first face match.
Same idea on every platform: enrol a face once, verify it whenever you like, with or without a connection.
// MauiProgram.cs
builder.UseFacePing(o => o.SandboxKey = "fp_test_…");
// Add the face once, on the device
await faceping.EnrollAsync("me", await Camera.CaptureAsync());
// Verify any time, with no network (live, with a head turn)
var result = await faceping.VerifyLiveAsync("me", Camera);
// result.Outcome → Match
// result.LivenessScore → 0.98
// result.Elapsed → 1.7 s
Enrol once. Check anywhere.
Your app holds an encrypted copy of the faces it needs, so every check runs on the device.
One photo, with consent
The person agrees and takes a selfie. In the sandbox it happens on the device; in production, through our widget, your server or your front desk.
An encrypted pack per device
Devices download only the faces they need, locked with their own key. A device that loses access wipes itself.
Offline, against the right person
Scan a ticket, card or ID, then look at the camera. FacePing confirms it's that person, and that they're really there.
One face engine, built in Rust.
Detection, liveness, matching and encrypted storage all run in the FacePing core: memory safe, compiled, and the same on every phone and our servers.
Memory safe
Rust rules out whole classes of bugs, such as buffer overflows, in the code that reads images.
Compiled native code
The SDK ships the engine as machine code, not readable .NET or JavaScript.
One engine everywhere
The same core on the phone and on our servers. .NET MAUI, Android, iOS, Flutter and React Native, all thin layers over the same core.
Encrypted at rest
Face templates are sealed with AES-256-GCM, with the key in the Keychain or Keystore.
Finding a face is free. Knowing whose face it is isn't.
ML Kit and Apple Vision find faces but can't tell you who they are. Cloud APIs can, but need a connection for every check.
| Feature | FacePing | Cloud face APIs | ML Kit / Apple Vision |
|---|---|---|---|
| Tells you whose face it is | Yes | Yes | No, detection only |
| Works with no network | Yes | No | Yes |
| Liveness and anti-spoofing | Built in | Varies, often extra | No |
| Cost per check | £0 | About $0.001 each | Free |
| Consent and deletion tooling | Built in | Build it yourself | Build it yourself |
Anywhere you need to know it's the right person.
Events and ticketing
Faster entry and no ticket touting. Verify against the scanned ticket, then delete everything after the event.
Gyms and memberships
No shared cards. Members walk in with their face, even when the Wi-Fi is down.
Staff clock-in
No buddy punching. Clock in on a shared tablet on site, with or without a connection.
Kiosks and check-in
Self-service check-in without a card. Searching all faces (1:N) is available once we approve your use case.
Verification, not surveillance.
FacePing checks that a person is who they say they are, with their consent. It isn't built to identify strangers, and we won't let it be used that way.
Read how we handle data- Consent built inA clear question, with an equally easy “no thanks”.
- No photos keptThe photo becomes a face template, then it's gone.
- Deleted on scheduleOn our servers and every device, with a log to prove it.
- Your regionHosted in the EU. UK and US regions on request.
- Paperwork includedDPA, DPIA template, privacy notice and consent wording.
- Checked before go-liveThe sandbox is instant. Production needs one quick review.
The price is right here.
You pay for each person stored with FacePing in a month. Checks and devices are unlimited.
- 25 faces per device
- Each deleted after 24 hours
- No card, no approval
- No monthly fee
- Only the people you store
- Invoiced monthly
A person counts once in a month if their face is stored at the end of it, or was enrolled and deleted within it. Prices exclude VAT. Prices in pounds, euros or US dollars: pick yours above. Larger volumes or custom terms: talk to us.
Good to know
Is it really offline?
Yes. Once a device has synced, every check runs on the phone or tablet: no network, no cloud call. Devices sync again to get new enrolments and stay authorised; offline devices keep working for 24 hours by default.
Why do I have to apply before going live?
Face templates are biometric data under GDPR and several US state laws. We check your use case once, usually within two working days. The sandbox needs no approval, so you can build while we review.
How does billing work?
You pay for each person stored with FacePing in a month. A person counts if their face is still stored at the end of the month, or if they were enrolled and deleted within it, and nobody counts twice in a month. So a one-day event (enrolled 28 October, deleted 7 November) counts once, and a gym member counts every month they're enrolled. Checks, devices and failed attempts never count. Prices exclude VAT; we also bill in € and $.
Can it search a crowd for someone?
No. FacePing isn't built for surveillance. Searching all enrolled faces (1:N) is available for opt-in kiosks once we've approved the use case.
Which platforms are supported?
.NET MAUI, iOS (Swift), Android (Kotlin), Flutter and React Native, all available now as previews. Each has a step-by-step guide and a finished starter app on GitHub.
How secure is it?
The face engine is written in Rust, a memory-safe language, and ships as compiled native code. Face templates are encrypted on the device, checks never leave the phone, and any device can be revoked, wiping its copy at its next sync. The detail is on our security page.
Where is face data stored?
On the device, encrypted with AES-256-GCM, and on our servers in the EU (UK and US regions on request). It's deleted on the schedule you set, and every deletion is logged.
From empty project to a face match in about 10 minutes.
Pick your platform, get a free sandbox key, follow the steps.