
Security and compliance
Six layers between the fraudster and an approval, and a receipt anyone can verify. Self-declared conformance by Catalisa, not lab-tested or certified.
The six layers
- LivenessReal skin, not paper or a screen.
- Randomized gesturesYesterday's video won't work today.
- Same face throughoutNo one can swap people halfway through.
- Capture integrityA virtual camera goes to review.
- Per-subject lockoutRepeated attempts lock the CPF.
- Signed evidenceNo one can change the result afterward.
Measured in a virtual-camera injection test: a genuine video from an approved session, injected into a new session, was rejected by the randomized gestures.
Verifiable without Catalisa
Download the public key
Your organization's key, at GET /evidence-keys.
Get the receipt
At GET /sessions/:id/evidence, with the signature.
Verify
openssl pkeyutl -verify — on your own machine, even with Catalisa offline.
Where the data lives
- Our own engine, in BrazilThe models run on Catalisa infrastructure in Brazil; no face image is sent to third parties.
- Or in your environmentWith a dedicated installation, the platform runs in your data center or private cloud, and images never leave it. See the options
- EncryptedFace enrollments and credentials in AES-256-GCM.
- Isolated pageThe capture runs under a strict security policy with a single-use token.