Hardware-Grade Authentication Made in EU

Authentication for the AI Era

One unclonable hardware token. Already in every customer's hand.

Every smartphone camera sensor carries a factory-random, non-copyable silicon fingerprint. ToothPic turns it into a hardware security key: nothing to ship, nothing to store, issued in a single app update.

7B+
devices already carry the token
99.99%
account-takeover risk removed
€0
marginal cost per authentication
430 ms
invisible to the user*

The problem: AI now fakes identity at scale

Anything known can be phished

Any person can be synthesised

Anything shown can be faked

Any camera feed can be injected

OTPs, passwords, face and voice checks are all software signals and GenAI manufactures software. Only physical possession still settles who is really there.

How it works: the token is the camera sensor

Read

Sensor noise pattern (PRNU) via the standard camera permission.

Rebuild

A standard elliptic-curve key is regenerated in ~30 ms to sign the challenge.

Vanish

Key destroyed after signing. Nothing on the phone, nothing in a database.

0 SECRETS AT REST DEFEATS INJECTION ATTACKS FIDO2 U2F

Hardware-token security with software-token economics

Unclonable &
HW-Bound
Survives
Reset
Vendor
Independent
User
Friction
Cost
SMS OTP / SIM binding
Transferable by design
Read & type €€
Passkeys
Synced by design
Prompt €
Secure enclave
Erased on reset
Biometric / PIN €
Hardware token
Dedicated physical key
Carry & press €€€
ToothPic
Bound to camera silicon
Invisible €

One integration. Three measurable outcomes.

Cost & Compliance
€9-20M
SMS OTP spend saved per 10M users

Reset-proof identity ends helpdesk re-enrolment. Frictionless SCA for PSD2/3, PSR Art. 59 and DORA.

Fraud & Capacity
70%
analyst time reclaimed

A deterministic signal auto-clears false alerts and unmasks emulators, cloned apps and mule farms across factory resets.

Deepfake Defence
30 ms
to disqualify a synthetic caller

A deepfake has no physical phone, so it cannot sign. 1-tap push replaces call-centre security questions.

Runs beside your stack - not instead of it

ToothPic SDK

on-device

Signed challenge FIDO2/EC

Your IdP

Okta, Keycloak...

Zero database changes - only standard public keys
100% on-device - no biometrics or keys leave the phone; GDPR-clean
Weeks, not quarters - a plugin next to your current SCA

Validated. Certified. In production.

4 paid EU deployments

Insurance, payments & academia, live in production

4 patent families

US EU-CN JP IL KR, 20-year terms

400M+ users

Proof of concept on a real-time payments platform

Certified.

FIDO2+U2F Certified. Politecnico di Torino spinoff, 2 EIC Seals of Excellence

90 days to proof. One flow. Your own data.

Existing controls stay live. Reversing costs one sprint. Let's talk.

WEEKS 1-2

Scope

Pick one journey, freeze the baseline

WEEKS 3-10

Pilot

SDK runs silently beside your SCA

WEEKS 11-13

Decide

Fraud lift, false rejects, latency, NPS