Liveness detection & presentation-attack detection
A face match only tells you two images look like the same person. Liveness detection tells you the face at the camera is a real, present human — not a photo, a screen, a mask or a deepfake. Zanyara runs both passive and active liveness, backed by presentation-attack detection, so a genuine document is bound to a genuine, present holder rather than to whoever is holding up a picture.
Passive first, active when it counts
Most vendors pick a lane. Zanyara does both, and uses them where each is strongest. Passive liveness reaches a decision from a single selfie — analysing texture, depth cues, reflection and micro-motion — with nothing asked of the user, so the common case is fast and frictionless. When the passive signal is ambiguous, Zanyara steps up to an active challenge — a head turn or gesture prompt — to force a response an artefact can’t easily give. Genuine users sail through; only the uncertain cases pay the friction.
What it is built to stop
- Printed photos — a still image held to the camera.
- Screen / video replay — a recording or photo played on another device.
- Cut-outs & 2D masks — paper masks with the eyes or mouth removed.
- 3D masks — moulded silicone or resin masks that mimic depth.
- Deepfake / synthetic media — AI-generated faces or face-swaps.
- Camera-injection & bypass — feeding frames straight into the app without a real camera ever seeing them.
Beyond the face: injection defence
The frontier of the arms race is no longer just can we tell a mask from a face. It is did these frames come from a real camera at all. Deepfakes fed through a virtual camera can defeat face-only liveness, so Zanyara layers in device-intelligence signals and a capture-path integrity check — the frames are signed at capture, so a stream that didn’t originate from the genuine on-device camera is flagged. Face analysis and capture integrity together are far harder to beat than either alone.
One signal in one decision
Liveness never travels alone. It runs on the same selfie Zanyara uses for face match, and the result is returned alongside the document, biometric and AML outcomes as a single verification — delivered by webhook and in the operator console, with borderline cases routed to human review.
Frequently asked questions
- What is presentation-attack detection (PAD)?
- PAD is the set of checks that decide whether a face presented to a camera belongs to a real, live person or to an artefact — a printed photo, a video replayed on a screen, a mask, or synthetic (deepfake) media. “Liveness detection” is the everyday name for the same thing. ISO/IEC 30107-3 is the standard that defines how PAD is measured.
- What is the difference between active and passive liveness?
- Passive liveness reaches a decision from a single selfie with no action asked of the user; active liveness asks for a deliberate action — a head turn or gesture. Zanyara runs passive-first for speed, and steps up to an active challenge when the passive signal is uncertain. There is a fuller comparison in our active vs passive guide.
- Does it stop deepfakes and injection attacks?
- Deepfakes and camera-injection (feeding synthetic frames straight into the pipeline rather than showing them to a real camera) are the hardest and fastest-moving class of attack. Zanyara addresses them with more than face analysis: device-integrity signals and a capture-path integrity check on the frames themselves, so a stream that never came from the genuine on-device camera is treated as suspect. No vendor should claim total immunity here; it is an arms race, which is why we defend in depth rather than on a single model.
- Is Zanyara iBeta or ISO 30107-3 certified?
- Zanyara’s liveness is designed to align with the ISO/IEC 30107-3 testing framework, and independent iBeta evaluation is on our roadmap. We do not currently hold an iBeta confirmation letter, and we will say so plainly rather than imply a certification we don’t have. Our explainer covers what such a letter does and doesn’t prove.
- How does it fit into a full verification?
- Liveness is one signal in a single decision. In a typical flow Zanyara captures the document, matches the live selfie to the document (or the chip’s signed photo), runs liveness/PAD on that selfie, and screens against AML watchlists — then returns one outcome by webhook and in the console.