Biometric decision governance

A high facial-recognition score cannot make an unlawful scan lawful

FaceTrust demonstrates the Biometric Decision Firewall. It puts calibrated evidence, jurisdiction, consent, and deterministic routing between a raw vendor score and a trained reviewer.

0.91

Raw vendor score

Synthetic SF-0002 example

BLOCK

Deterministic route

Seeded jurisdiction table

100% of 1,498

Unlawful scans blocked

Synthetic 3,000-alert held-out set

These are deterministic results from seeded synthetic scenarios, not customer, production, or open-world outcomes.

A match score is evidence, not authority to act

A facial-recognition alert can look decisive while its legal and evidential basis remains unresolved.

Raw thresholding compresses the decision into one number. It does not establish that collection was permitted, that consent exists, that the probe is usable, or that uncertainty is narrow enough to support action.

The synthetic SF-0002 alert makes the failure concrete. Its raw vendor score is 0.91, yet the seeded jurisdiction table marks facial recognition as prohibited in San Francisco. The route is BLOCK.

FaceTrust keeps that lawfulness check in the workflow. The system never automatically confronts, detains, or accuses a person.

Decision boundary

Lawfulness is evaluated before a security team acts.

  • 01Can this scan be processed in the seeded jurisdiction?
  • 02Is the required consent recorded?
  • 03Does the capture clear the 72-pixel floor?
  • 04What does the calibrated prediction set support?

How the Biometric Decision Firewall works

Agents advise; deterministic controls decide.

01

Normalize the alert

A stubbed vendor adapter maps the raw vendor score, probe quality, gallery-photo age, demographic group, and location into one decision record.

02

Calibrate the evidence

A local group- and capture-quality-conditional calibrator produces a calibrated match probability, an interval, and a 93% conformal prediction set.

03

Apply deterministic policy gates

Jurisdiction, consent, the sub-72-pixel capture floor, and prediction-set outcome determine BLOCK, SUPPRESS, ESCALATE, or CONFIRM. Enrollment age is recorded as a reviewer and audit flag, but it does not independently change the route.

04

Prepare trained review

The Compliance Reviewer drafts a readable memo from structured decision facts. The memo is advisory because deterministic code has already set the route.

05

Seal the receipt

Each decision creates a SHA-256 hash-chained audit record and can export a printable HTML audit exhibit.

Proof in the interface

Every view below comes from the working demo. Where cases or metrics appear, they use seeded synthetic data; no real faces or customer footage appear.

FaceTrust How Live Review Works guide explaining the seeded live-review session
The operating guide labels live review as a seeded, reproducible session. The walkthrough uses synthetic alerts and has no live camera or customer-data feed.
FaceTrust Decision Guide defining BLOCK, SUPPRESS, ESCALATE, and CONFIRM routes
The Decision Guide makes each route explicit: BLOCK for an unlawful location, SUPPRESS for a false match or insufficient capture quality, ESCALATE for human review before action, and CONFIRM for a credible match routed to a reviewer.
FaceTrust assurance view comparing synthetic held-out coverage across six Fitzpatrick groups
On the synthetic 3,000-alert held-out set, the firewall's minimum empirical coverage across six evaluated Fitzpatrick groups is 91.5%. The raw baseline's minimum is 40.6%.
FaceTrust synthetic benchmark run processing recorded decisions with evidence links
The completed benchmark receipt records 364 of 364 synthetic replay decisions processed and keeps evidence links available for inspection. It is a demo benchmark, not a production capacity commitment.

What changes between a raw threshold and a decision firewall

The distinction is where lawfulness, uncertainty, and human accountability enter the route.

Decision input Raw-score baseline Biometric Decision Firewall
Match evidenceVendor score at or above 0.70 in the demo baselineCalibrated probability, interval, and 93% conformal prediction set
LawfulnessNot part of the raw thresholdDeterministic jurisdiction and consent gates
Capture qualityNot part of the raw thresholdSub-72-pixel floor plus capture-conditioned calibration
Human controlA threshold can be treated as the action triggerUncertain and credible cases route to a trained reviewer
Audit evidenceNot evaluated by the raw-score ruleSHA-256 hash-chained record and printable audit exhibit

What this demo does not do

This demo is not a facial-recognition model, legal opinion, compliance certification, or customer deployment. Its camera, VMS, vendor, consent, NIST, and customer-data connections are not live. The footprint, alerts, statute and consent tables, replay, and held-out set are seeded or synthetic. It does not include live CCTV, liveness detection, persistence, authentication, or rate limiting.

Questions compliance and security teams ask

Can FaceTrust replace our facial-recognition vendor?

No. FaceTrust demonstrates the Biometric Decision Firewall, a vendor-agnostic governance layer that sits between a facial-recognition vendor and the decision workflow. The demo uses a stubbed vendor adapter, so it does not connect to a live vendor, VMS, camera, or customer data.

What happens when a score is high but the scan is not lawful?

Lawfulness wins. In the synthetic SF-0002 example, a 0.91 raw vendor score routes to BLOCK because the seeded jurisdiction table marks facial recognition as prohibited there.

How does the firewall decide between BLOCK, SUPPRESS, ESCALATE, and CONFIRM?

Deterministic gates check jurisdiction, consent, a sub-72-pixel capture floor, and the calibrated 93% conformal prediction-set outcome. Enrollment age is recorded as a reviewer and audit flag, but it does not independently change the route.

Does CONFIRM authorize an automatic confrontation?

No. CONFIRM routes a credible match to a trained reviewer to action. The firewall never automatically confronts, detains, or accuses a person.

How would calibration work with our cameras and population?

The demo uses a local group- and capture-quality-conditional calibrator on seeded synthetic data. Production calibration would use the client's adjudicated history and would need validation for its capture conditions and operating context.

What evidence can compliance or privacy teams inspect?

Each decision creates a SHA-256 hash-chained record and can export a printable HTML audit exhibit. The dossier keeps the raw vendor score, calibrated evidence, policy findings, route, and advisory reviewer memo together.

Technical Research

The research behind this demo — the architecture, the verification design, and the enterprise blueprint.

Social

Also Published On

Put the decision boundary before the alert reaches operations

The useful architecture conversation starts with the controls your current workflow can prove.

We can examine where jurisdiction, consent, calibration, trained review, and audit evidence belong around an existing facial-recognition system.

Decision controls to map

  • ✓ Raw vendor outputs
  • ✓ Jurisdiction and consent inputs
  • ✓ Capture-quality floor
  • ✓ Trained-reviewer routes

Evidence questions to resolve

  • ✓ Adjudicated calibration history
  • ✓ Policy-gate ownership
  • ✓ Decision receipts
  • ✓ Audit exhibit workflow