Security and compliance

Six layers between the fraudster and an approval, and a receipt anyone can verify. Self-declared conformance by Catalisa, not lab-tested or certified.

Signed evidence Per-subject lockout Capture integrity Same face throughout Randomized gestures Liveness printed photoreplayed videomaskvirtual camera

The six layers

  1. LivenessReal skin, not paper or a screen.
  2. Randomized gesturesYesterday's video won't work today.
  3. Same face throughoutNo one can swap people halfway through.
  4. Capture integrityA virtual camera goes to review.
  5. Per-subject lockoutRepeated attempts lock the CPF.
  6. Signed evidenceNo one can change the result afterward.

Measured in a virtual-camera injection test: a genuine video from an approved session, injected into a new session, was rejected by the randomized gestures.

Verifiable without Catalisa

Download the public key

Your organization's key, at GET /evidence-keys.

Get the receipt

At GET /sessions/:id/evidence, with the signature.

Verify

openssl pkeyutl -verify — on your own machine, even with Catalisa offline.

Where the data lives

  • Our own engine, in BrazilThe models run on Catalisa infrastructure in Brazil; no face image is sent to third parties.
  • Or in your environmentWith a dedicated installation, the platform runs in your data center or private cloud, and images never leave it. See the options
  • EncryptedFace enrollments and credentials in AES-256-GCM.
  • Isolated pageThe capture runs under a strict security policy with a single-use token.

Run your first verification and read the receipt.