liveness It is a liveness verification technology that verifies whether a facial biometric sample is being captured from a person who is alive and present at that moment. In processes of digital signatureFurthermore, it adds a layer against fraud attempts involving photos, videos, masks, or other false presentations. However, proof of life alone does not necessarily confirm a person's identity: this depends on the other verifications combined with the process.
In practice, the user records or captures their face with the camera, and the system analyzes signals that help distinguish a legitimate presentation from an attempt at forgery. Depending on the technology, this detection can happen through actions requested from the user or passively, in the background.
In addition to explaining how liveness works, this article shows its relationship with facial recognition, LGPD (Brazilian General Data Protection Law), fraud prevention, and the current workflow of Facial Biometrics – Proof of Life at ZapSign.
Summary
- Liveness seeks to prove that biometric capture occurs with a person alive and present.
- The technology is a form of Presentation Attack Detection (PAD), used against attempts involving photos, videos, and other artifacts.
- Liveness is not synonymous with facial recognition, nor does it, on its own, confirm the user's entire identity.
- Biometrics is sensitive personal data, and its processing must comply with the LGPD (Brazilian General Data Protection Law) and implement measures proportionate to the risk.
- At ZapSign, Facial Biometrics – Proof of Life uses video, currently costs 15 credits per use, and records a photo in the signature report.
Quick facts
- Technical definition: o NIST Liveness detection is treated as part of presentation attack detection methods, analyzing characteristics or reactions to determine if a biometric sample comes from a living, present individual.
- Sensitive data: a ANPD It emphasizes that biometric data is sensitive personal data and that its use must consider necessity, security, prevention, and risks to the data subjects.
- Cost on ZapSign: a official plans page It currently charges R$ 1,50 per validation of the Liveness Detection (Facial Biometrics) functionality.
What is liveness and what role does it play in digital signatures?
livenessDigital proof of life, or digital proof of life, is a mechanism designed to assess whether the biometric sample presented to the system is being captured from a real, present person, and not just a photograph, video recording, or other artifact used in an attempt at fraud.
This distinction is important because liveness and facial recognition are not exactly the same thing. Proof of life seeks to answer the question "is there a living person in front of the camera?". Facial verification, on the other hand, can compare the captured face with a reference image to assess whether both belong to the same person.
Therefore, liveness represents a relevant layer in authentication. digital identities, especially when combined with other identification mechanisms. A verification by selfieFor example, it can gain more robustness when the stream also attempts to confirm that the capture was performed live.
This could strengthen the evidence related to validity of signaturesHowever, it does not automatically eliminate the possibility of fraud or dispute. Effectiveness depends on the technology used, the other layers of authentication, the quality of the capture, and the process design.
When Truora acquired ZapSign in 2022, we began a phase where our experience with electronic signatures became even more closely intertwined with facial recognition technologies. For me, this intersection between security and user experience is one of the most interesting applications of biometrics in digital processes.
Another potential benefit lies in experienceDepending on the implementation, proof of life can add evidence without requiring the user to memorize another password or perform an in-person procedure.
What is liveness detection or digital proof of life?
The term liveness detection It is often associated with the automated detection of presentation attacks in biometric systems. NIST uses the term Presentation Attack Detection (PAD) for the automated determination of an attempt to present an artifact or feature to the sensor in order to deceive the system.
Proof of life is one part of this universe: anatomical, behavioral, or other characteristics of the captured image can be analyzed to estimate whether the face belongs to a person who is actually in front of the device.
This is especially useful because biometric attacks can utilize printed photographs, images displayed on screens, videos, masks, morphing, and synthetic content. The goal of liveness is to reduce the ability of these presentations to be accepted as legitimate capture.
Types of liveness detection: active and passive.
There are two well-known approaches to proof of life: active and passive liveness.
No active livenessThe system prompts the user to take an action, such as moving their head, blinking, smiling, or following an on-screen instruction. The response then becomes part of the analysis.
No passive livenessIn this case, the evaluation takes place without an explicit challenge. Algorithms can analyze image or video characteristics, texture patterns, depth, lighting, or other signals to look for evidence of a genuine capture or a fraudulent presentation.
There is no universal rule stating that one method is always more secure than another. Performance varies depending on the algorithm, sensor, environment, types of attacks evaluated, and configuration. Passive methods tend to generate less friction; active methods add interaction but can also increase abandonment or create accessibility barriers.
How does liveness work technically?
The process begins with capturing images or video of the face using a camera. From there, the PAD solution can analyze different signals, depending on the technology used.
- movement and behavior: actions, microexpressions, or changes in facial position;
- texture and lighting: characteristics that help to differentiate a face from a representation on screen, in print, or in artificial material;
- depth: When available, spatial information can help distinguish a three-dimensional face from certain flat artifacts;
- algorithmic analysis: Models can identify patterns associated with known presentation attacks.
Some solutions utilize additional sensors; others work only with conventional cameras. NIST, in fact, maintains specific evaluations of passive PAD algorithms based on 2D images, showing that performance and vulnerability vary between solutions and types of attack.
What is the difference between liveness, facial recognition, and identity validation?
These features can be combined, but they solve different problems. Within ZapSign itself, they appear as distinct functionalities.
| Resource | What are you looking to verify? | As it currently appears on ZapSign | Cost reported |
|---|---|---|---|
| liveness | If there is a person alive and present during the capture. | Facial Biometrics – Proof of Life | R$ 1,50 per validation |
| Facial recognition | If the captured face matches the photograph in the document used as a reference. | Facial recognition | R$ 1,50 per validation |
| Identity validation | It combines different identity verifications. | Document examination + proof of life + CPF validation at the Federal Revenue Service | R$ 5,00 per validation |
Therefore, saying that liveness alone “proves that the person is who they claim to be” oversimplifies the process. Proof of life is primarily about human presence at the time of capture. For a more comprehensive conclusion about identity, other evidence may be necessary.
Liveness, biometrics and LGPD (Brazilian General Data Protection Law)
When a facial image is used to extract or process biometric attributes linked to a natural person, a category of sensitive personal data protected by the LGPD (Brazilian General Data Protection Law) comes into play.
This requires evaluating the purpose, necessity, transparency, security, retention, and the appropriate legal basis for the processing. An important point is that Consent is not the only possible legal basis. for biometric data.
Article 11 of the General Law of Data Protection It provides, among other possibilities, for processing without consent when indispensable for preventing fraud and ensuring the security of the data subject in identification and authentication processes for registration in electronic systems, observing the conditions stipulated by the law itself.
This does not mean that any biometric data collection is automatically justified by the security argument. The ANPD (Brazilian National Data Protection Authority) has been drawing attention to proportionality, necessity, risks, less intrusive alternatives, and adequate protection measures, especially because biometrics cannot simply be replaced like a password after a data breach.
When I wrote about biometrics and facial recognition, I highlighted precisely that the advancement of these technologies brings an equivalent responsibility for companies: protecting biometric data and respecting user privacy. I also consider dialogue between industry, government, and society essential to balance the benefits with individual rights.
What are the main challenges of liveness detection?
Liveness should not be treated as a foolproof technology. PAD systems can make mistakes and exhibit different performance depending on the capture conditions and attacks used in testing.
- false acceptance: A fraudulent presentation can eventually be classified as legitimate;
- false rejection: A legitimate person may not pass the verification;
- Capture quality: Camera, lighting, framing, and connection can all affect the experience;
- accessibility: Challenges that require specific movements may be unsuitable for some users;
- new attacks: Deepfakes, morphing, and other synthetic techniques require continuous evolution of defenses;
- privacy: Biometric data collection increases the responsibility for data protection and governance.
What is the difference between liveness and traditional authentication methods?
Passwords, PINs, and tokens prove something the user knows or possesses. Biometric verification, on the other hand, works with physical or behavioral characteristics related to the individual.
These methods don't need to compete with each other. In higher-risk operations, combining different factors may be more appropriate than completely replacing one authentication method with another.
Passwords can be subject to phishing, reuse, or leakage; biometrics also presents its own risks, including algorithmic errors, presentation attacks, and more serious impacts when sensitive data is exposed.
Therefore, the choice should consider the risk of the operation, experience, cost, privacy, and recovery capacity in case of failure.
How does liveness work to prevent fraud?
The main anti-fraud function of liveness is to hinder presentation attacks against biometric capture. Among the methods employed by different solutions are the following.
Motion analysis
The system can assess spontaneous movements or request actions, such as turning the head or blinking. These responses add information that a still photograph does not provide.
3D depth sensing
In compatible devices and solutions, depth information can help detect certain artifacts and two-dimensional representations. Availability depends on the hardware and implementation used. cellular and other devices.
Texture analysis
Algorithms can look for differences between features of a face captured live and patterns produced by certain types of fingerprints, screens, masks, or other attack devices.
Tests and challenges
In an active approach, the user may receive random instructions. The analysis verifies if the response matches the presented challenge, making some pre-prepared attacks more difficult.
AI and machine learning
Modern solutions can employ artificial intelligence and machine learning to identify patterns associated with fraudulent presentation attempts. These models need to continue to be evaluated because offensive techniques also evolve.
More recently, I followed another front in the fight against fraud at ZapSign: the use of Open Gateway to utilize information from the telephony network's own infrastructure in signatory validation. What I find particularly interesting is being able to add a new layer of security and governance without creating an additional step of friction for the signer.
In other words, liveness can be an important factor, but fraud defense tends to work better when different signals are combined according to the risk.
⚠️ Also check out these related articles 👇
➡️ Learn how to sign with a digital certificate
➡️ Understand what a digital signature verifier is for
➡️ What is a digital contract and how to adopt one for your company
What are the steps to use liveness in ZapSign?
On the platform, the feature currently appears as Facial Biometrics – Proof of LifeThe official process can be summarized in the steps below.
1. Create the document
Open your ZapSign account and create or send the Valid identity document which should receive the signatures.
2. Add the signatory
In the section for signatories, register the person who should sign and review the data associated with the workflow.
3. Enable advanced authentication.
Enable advanced authentication options to choose an additional layer of verification.
4. Select Facial Biometrics – Proof of Life
Choose the option that corresponds to the proof of life. When the signer reaches the authentication stage, ZapSign will request a video capture of their face.
5. Configure signatures and initials.
If necessary, define the locations where the visual representation of the signature or the headings They should appear in the file.
6. Send the link to the signatory.
Finalize the setup and share the document. The signer will access the workflow, make the requested recording, and go through automatic verification.
After capture, a photo extracted from the video can be incorporated into the signature report, adding a visual record related to authentication.
What are the rules and costs for using liveness on ZapSign?
Cost per use
Facial Biometrics – Proof of Life currently costs 15 credits per use, equivalent to R$ 1,50 per validation.This feature is an additional resource, and the applicable terms and conditions should be checked on the Plans and Pricing page or in the help center before large-scale implementation.
The previous version of this article already mentioned the 15 credits and linked the discount to the completion of the course. document signatureSince the current documentation states the cost per use but does not repeat this billing condition in the same way, it is safer to consider the current commercial rule displayed on the platform at the time of use.
Authentication process
Currently, ZapSign's documentation states that the signer records a video of their face. The system automatically performs the analysis and, when the step is completed, extracts a photograph of the capture for inclusion in the signature report.
Report and evidence
Photography and verification records add evidence to the process. Even so, no single element should be considered in isolation as infallible proof of identity: the strength of the evidence comes from the combination of documents, expressions of will, authentications, logs, integrity, and context.
Liveness, therefore, is an important layer for reducing attacks against biometric verifications, but it works best within a strategy that combines risk, expertise, privacy, and other evidence of identity. Click here to learn about this solution offered by us, at ZapSign!
Frequently Asked Questions (FAQ)
Liveness is proof of life used in biometric processes to assess whether the capture is being made of a living and present person. It helps detect presentation attacks using photos, videos, masks, or other artifacts used to deceive biometric systems.
No. Liveness verification checks to see if there is a living person present in the capture. Facial recognition can compare a face to a reference image to verify identity. Both features can be used together in the same workflow.
It can help detect presentation attacks and reduce risks, but it doesn't eliminate all fraud. Deepfakes and other techniques continue to evolve, so proof of life should be combined with other evidence, monitoring, exception rules, and risk-proportional authentication.
Yes, provided that the processing of biometric data has an adequate legal basis and observes purpose, necessity, transparency, security, and the rights of the data subject. The LGPD (Brazilian General Data Protection Law) even provides for provisions related to fraud prevention and security in electronic identification and authentication processes.
Facial Biometrics – Proof of Life currently costs 15 credits per use, equivalent to R$1,50 per validation. As prices and conditions may change, please consult the Plans and Pricing page and the help center before projecting costs at scale.

Getúlio Santos is the CEO of ZapSign, a lawyer, technology enthusiast, and entrepreneur.

![[Banner] Digital transformation in practice Digital transformation in practice](https://blog.zapsign.com.br/wp-content/uploads/2024/10/Banners-para-blog-Guia-transformacao-digital.png)
![[Banner] Sign-up 1 – 10.12.24 Sign up for free at ZapSign](https://blog.zapsign.com.br/wp-content/uploads/2024/12/BANNER-SIGN-UP-1.png)


