New Gartner® research — ToothPic is named a Sample Vendor in the Emerging Tech Impact Radar: Disinformation Security, September 2026.

Read more

Authentication for the AI era · Made in EU

One unclonable hardware token. Already in every customer’s hand.

Every smartphone camera sensor carries a factory-random, non-copyable silicon fingerprint. ToothPic turns it into a hardware security key: nothing to ship, nothing to store, issued in a single app update.

FIDO2 · U2F certified Gartner Representative Vendor ’24 & ’25
7B+
devices already carry the token
99.99%
account-takeover risk removed
€0
marginal cost per authentication
30 ms
invisible to the user

The shift

AI now fakes identity at industrial scale.

OTPs, passwords, face and voice checks are all software signals — and generative AI manufactures software. Only physical possession still settles who is really there.

Authentication, identity proofing and caller trust have become one problem. No software-layer signal can settle it.

Anything known can be phished
Anything shown can be faked
Any person can be synthesised
Any camera feed can be injected

The physics

The token is the camera sensor.

During manufacturing every sensor develops microscopic, unclonable imperfections — Photo-Response Non-Uniformity (PRNU), a physical unclonable function. ToothPic turns it into a standard key, only for the instant it is needed.

1

Read

Factory-random silicon noise (PRNU) is read through the standard camera permission. No photo is taken or stored.

2

Rebuild

A standard elliptic-curve private key is regenerated in ~30 ms to sign the challenge.

3

Vanish

The key is destroyed immediately after signing. Nothing on the phone, nothing in a database.

0 secrets at restDefeats injection attacksISO 30107-3 · CEN/TS 18099

Where it’s used & what it delivers

Six use cases. Measurable impact in each.

For banks, payment providers, insurers and fintechs. One integration — login, payments, fraud operations and deepfakes, secured by one hardware key.

Login & app access

Replaces passwords and SMS OTP with an unclonable hardware key.

99.99%account-takeover risk removed

Payment & transaction signing

Invisible, PSD2/3-compliant SCA for transfers and instant payments.

€9–20MSMS OTP spend saved per 10M users

Device binding & re-enrolment

New phone, reinstall or reset — without SMS, helpdesk or a branch visit.

Up to 50%less device-ID maintenance

Fraud back-office efficiency

A deterministic signal auto-clears false alerts and unmasks emulators and mule farms.

70%analyst time reclaimed

Contact-centre verification

A push to the customer’s own phone verifies the caller and cuts handling time.

1 tapreplaces security questions

Deepfake-proof video & voice

Remote onboarding, KYC and executive approvals: a real phone must sign.

€95Mlost by an Italian bank to an AI voice-clone scam (2026)

The evaluation

Hardware-token security with software-token economics.

Only ToothPic satisfies every critical criterion — privacy-compliant and easy to integrate.

Comparison of authentication methods
MethodUnclonable & HW-boundSurvives resetVendor independentUser frictionCost
SMS OTP / SIM bindingTransferable by design✕✓✕Read & type€€
PasskeysSynced by design✕✓~Prompt€
Secure enclaveErased on reset~✕✕Biometric / PIN€
Hardware tokenDedicated physical key✓✓✓Carry & press€€€
ToothPicBound to camera silicon✓✓✓Invisible€

Integration

Runs beside your stack — not instead of it.

A device-bound FIDO2 credential running in parallel with your current SCA. Not a rip-and-replace.

  • Zero database changes — only standard public keys, stored in the directory you already run.
  • 100% on-device — no biometric template or private key ever leaves the handset. GDPR-clean.
  • Weeks, not quarters — a plugin alongside your current SCA, with up to 50% less device-ID maintenance.
Your appiOS · Android
ToothPic SDKon-device
Signed challengeFIDO2 / EC
Your existing IdPany FIDO2 / OIDC-compliant provider

Works with the identity provider you already run — for example Okta, Keycloak, Duende, Microsoft, F5 or Shibboleth, and any other standards-based IdP. The list is illustrative, not exhaustive. ECDSA · NIST P-256 signatures, FIDO2-compliant.

Proof

Validated. Certified. In production.

Gartner Representative Vendor

Market Guide for User Authentication, 2024 & 2025.

4 patent families

US · EU · IT · CN · JP · IL · KR, 20-year terms.

FIDO2 + U2F certified

Standards-compliant: no proprietary protocol to adopt.

4 paid EU deployments

Insurance, payments and academia — live in production.

400M+ user proof of concept

Validated on a real-time payments platform.

Politecnico di Torino spin-off

Two EU Seals of Excellence. Incubated at I3P.

In production

Some of our customers

A selection of the organisations running ToothPic in insurance, payments, public services and research.

  • Poste Italiane
  • Intesa Sanpaolo Assicurazioni
  • Value+
  • CSI Piemonte
  • Politecnico di Torino

The ask

90 days to proof. One flow. Your baseline.

Existing controls stay live throughout. Reversing costs one sprint.

Weeks 1–2

Scope

One high-value transaction journey. Freeze the fraud, false-alert and SMS OTP baseline.

Weeks 3–10

Pilot

The SDK runs beside your current SCA. Real users, real transactions, silent evaluation.

Weeks 11–13

Decide

Fraud lift · false rejects · latency · NPS. A clear, data-backed gate to production.

See how the pilot is de-risked

Ready to see it on your own data?

90 days to proof. One flow, your baseline, existing controls stay live — and reversing costs one sprint.