Authentication for the AI Era
One unclonable hardware token.
Already in every customer's hand.
Every smartphone camera sensor carries a factory-random, non-copyable silicon fingerprint. ToothPic turns it into a hardware security key: nothing to ship, nothing to store, issued in a single app update.
The problem: AI now fakes identity at scale
Anything known can be phished
Any person can be synthesised
Anything shown can be faked
Any camera feed can be injected
OTPs, passwords, face and voice checks are all software signals and GenAI manufactures software. Only physical possession still settles who is really there.
How it works: the token is the camera sensor
Read
Sensor noise pattern (PRNU) via the standard camera permission.
Rebuild
A standard elliptic-curve key is regenerated in ~30 ms to sign the challenge.
Vanish
Key destroyed after signing. Nothing on the phone, nothing in a database.
Hardware-token security with software-token economics
| Unclonable & HW-Bound |
Survives Reset |
Vendor Independent |
User Friction |
Cost | |
|---|---|---|---|---|---|
|
SMS OTP / SIM binding
Transferable by design
|
Read & type | €€ | |||
|
Passkeys
Synced by design
|
Prompt | € | |||
|
Secure enclave
Erased on reset
|
Biometric / PIN | € | |||
|
Hardware token
Dedicated physical key
|
Carry & press | €€€ | |||
|
ToothPic
Bound to camera silicon
|
Invisible | € |
One integration. Three measurable outcomes.
Reset-proof identity ends helpdesk re-enrolment. Frictionless SCA for PSD2/3, PSR Art. 59 and DORA.
A deterministic signal auto-clears false alerts and unmasks emulators, cloned apps and mule farms across factory resets.
A deepfake has no physical phone, so it cannot sign. 1-tap push replaces call-centre security questions.
Runs beside your stack - not instead of it
ToothPic SDK
on-device
Your IdP
Okta, Keycloak...
Validated. Certified. In production.
4 paid EU deployments
Insurance, payments & academia, live in production
4 patent families
US EU-CN JP IL KR, 20-year terms
400M+ users
Proof of concept on a real-time payments platform
Certified.
FIDO2+U2F Certified. Politecnico di Torino spinoff, 2 EIC Seals of Excellence
90 days to proof. One flow. Your own data.
Existing controls stay live. Reversing costs one sprint. Let's talk.
Scope
Pick one journey, freeze the baseline
Pilot
SDK runs silently beside your SCA
Decide
Fraud lift, false rejects, latency, NPS