Login & app access
Replaces passwords and SMS OTP with an unclonable hardware key.
Authentication for the AI era · Made in EU
Every smartphone camera sensor carries a factory-random, non-copyable silicon fingerprint. ToothPic turns it into a hardware security key: nothing to ship, nothing to store, issued in a single app update.
The shift
OTPs, passwords, face and voice checks are all software signals — and generative AI manufactures software. Only physical possession still settles who is really there.
Authentication, identity proofing and caller trust have become one problem. No software-layer signal can settle it.
The physics
During manufacturing every sensor develops microscopic, unclonable imperfections — Photo-Response Non-Uniformity (PRNU), a physical unclonable function. ToothPic turns it into a standard key, only for the instant it is needed.
Factory-random silicon noise (PRNU) is read through the standard camera permission. No photo is taken or stored.
A standard elliptic-curve private key is regenerated in ~30 ms to sign the challenge.
The key is destroyed immediately after signing. Nothing on the phone, nothing in a database.
Where it’s used & what it delivers
For banks, payment providers, insurers and fintechs. One integration — login, payments, fraud operations and deepfakes, secured by one hardware key.
Replaces passwords and SMS OTP with an unclonable hardware key.
Invisible, PSD2/3-compliant SCA for transfers and instant payments.
New phone, reinstall or reset — without SMS, helpdesk or a branch visit.
A deterministic signal auto-clears false alerts and unmasks emulators and mule farms.
A push to the customer’s own phone verifies the caller and cuts handling time.
Remote onboarding, KYC and executive approvals: a real phone must sign.
The evaluation
Only ToothPic satisfies every critical criterion — privacy-compliant and easy to integrate.
| Method | Unclonable & HW-bound | Survives reset | Vendor independent | User friction | Cost |
|---|---|---|---|---|---|
| SMS OTP / SIM bindingTransferable by design | ✕ | ✓ | ✕ | Read & type | €€ |
| PasskeysSynced by design | ✕ | ✓ | ~ | Prompt | € |
| Secure enclaveErased on reset | ~ | ✕ | ✕ | Biometric / PIN | € |
| Hardware tokenDedicated physical key | ✓ | ✓ | ✓ | Carry & press | €€€ |
| ToothPicBound to camera silicon | ✓ | ✓ | ✓ | Invisible | € |
Integration
A device-bound FIDO2 credential running in parallel with your current SCA. Not a rip-and-replace.
Works with the identity provider you already run — for example Okta, Keycloak, Duende, Microsoft, F5 or Shibboleth, and any other standards-based IdP. The list is illustrative, not exhaustive. ECDSA · NIST P-256 signatures, FIDO2-compliant.
Proof
Market Guide for User Authentication, 2024 & 2025.
US · EU · IT · CN · JP · IL · KR, 20-year terms.
Standards-compliant: no proprietary protocol to adopt.
Insurance, payments and academia — live in production.
Validated on a real-time payments platform.
Two EU Seals of Excellence. Incubated at I3P.
In production
A selection of the organisations running ToothPic in insurance, payments, public services and research.





The ask
Existing controls stay live throughout. Reversing costs one sprint.
One high-value transaction journey. Freeze the fraud, false-alert and SMS OTP baseline.
The SDK runs beside your current SCA. Real users, real transactions, silent evaluation.
Fraud lift · false rejects · latency · NPS. A clear, data-backed gate to production.

Gartner names ToothPic among the Sample Vendors in its Emerging Tech Impact Radar: Disinformation Security (September 2026), under Trust and Authenticity for Physical AI.
Read more
India operates one of the most sophisticated and expansive digital-payment ecosystems in the world. This incredible achievement has historically relied on a s
Read more
Discover why enterprises are adopting passkeys and how ToothPic delivers secure, device-bound, and unclonable authentication for corporate environments. World
Read more90 days to proof. One flow, your baseline, existing controls stay live — and reversing costs one sprint.