Biometric decision governance
FaceTrust demonstrates the Biometric Decision Firewall. It puts calibrated evidence, jurisdiction, consent, and deterministic routing between a raw vendor score and a trained reviewer.
0.91
Raw vendor score
Synthetic SF-0002 example
BLOCK
Deterministic route
Seeded jurisdiction table
100% of 1,498
Unlawful scans blocked
Synthetic 3,000-alert held-out set
These are deterministic results from seeded synthetic scenarios, not customer, production, or open-world outcomes.
A facial-recognition alert can look decisive while its legal and evidential basis remains unresolved.
Raw thresholding compresses the decision into one number. It does not establish that collection was permitted, that consent exists, that the probe is usable, or that uncertainty is narrow enough to support action.
The synthetic SF-0002 alert makes the failure concrete. Its raw vendor score is 0.91, yet the seeded jurisdiction table marks facial recognition as prohibited in San Francisco. The route is BLOCK.
FaceTrust keeps that lawfulness check in the workflow. The system never automatically confronts, detains, or accuses a person.
Decision boundary
Lawfulness is evaluated before a security team acts.
Agents advise; deterministic controls decide.
A stubbed vendor adapter maps the raw vendor score, probe quality, gallery-photo age, demographic group, and location into one decision record.
A local group- and capture-quality-conditional calibrator produces a calibrated match probability, an interval, and a 93% conformal prediction set.
Jurisdiction, consent, the sub-72-pixel capture floor, and prediction-set outcome determine BLOCK, SUPPRESS, ESCALATE, or CONFIRM. Enrollment age is recorded as a reviewer and audit flag, but it does not independently change the route.
The Compliance Reviewer drafts a readable memo from structured decision facts. The memo is advisory because deterministic code has already set the route.
Each decision creates a SHA-256 hash-chained audit record and can export a printable HTML audit exhibit.
Every view below comes from the working demo. Where cases or metrics appear, they use seeded synthetic data; no real faces or customer footage appear.
The distinction is where lawfulness, uncertainty, and human accountability enter the route.
| Decision input | Raw-score baseline | Biometric Decision Firewall |
|---|---|---|
| Match evidence | Vendor score at or above 0.70 in the demo baseline | Calibrated probability, interval, and 93% conformal prediction set |
| Lawfulness | Not part of the raw threshold | Deterministic jurisdiction and consent gates |
| Capture quality | Not part of the raw threshold | Sub-72-pixel floor plus capture-conditioned calibration |
| Human control | A threshold can be treated as the action trigger | Uncertain and credible cases route to a trained reviewer |
| Audit evidence | Not evaluated by the raw-score rule | SHA-256 hash-chained record and printable audit exhibit |
This demo is not a facial-recognition model, legal opinion, compliance certification, or customer deployment. Its camera, VMS, vendor, consent, NIST, and customer-data connections are not live. The footprint, alerts, statute and consent tables, replay, and held-out set are seeded or synthetic. It does not include live CCTV, liveness detection, persistence, authentication, or rate limiting.
No. FaceTrust demonstrates the Biometric Decision Firewall, a vendor-agnostic governance layer that sits between a facial-recognition vendor and the decision workflow. The demo uses a stubbed vendor adapter, so it does not connect to a live vendor, VMS, camera, or customer data.
Lawfulness wins. In the synthetic SF-0002 example, a 0.91 raw vendor score routes to BLOCK because the seeded jurisdiction table marks facial recognition as prohibited there.
Deterministic gates check jurisdiction, consent, a sub-72-pixel capture floor, and the calibrated 93% conformal prediction-set outcome. Enrollment age is recorded as a reviewer and audit flag, but it does not independently change the route.
No. CONFIRM routes a credible match to a trained reviewer to action. The firewall never automatically confronts, detains, or accuses a person.
The demo uses a local group- and capture-quality-conditional calibrator on seeded synthetic data. Production calibration would use the client's adjudicated history and would need validation for its capture conditions and operating context.
Each decision creates a SHA-256 hash-chained record and can export a printable HTML audit exhibit. The dossier keeps the raw vendor score, calibrated evidence, policy findings, route, and advisory reviewer memo together.
The research behind this demo — the architecture, the verification design, and the enterprise blueprint.
The useful architecture conversation starts with the controls your current workflow can prove.
We can examine where jurisdiction, consent, calibration, trained review, and audit evidence belong around an existing facial-recognition system.