You can change a password. You can be issued a new card number, close an account, freeze your credit, or move house. Every piece of information a company holds about you is, in principle, revocable — you can outlive the leak.
Not your face. There is no reissue. Whatever is taken remains accurate for the rest of your life, and it identifies you in every photograph, every doorway camera, and every database that anyone ever assembles afterwards. A leaked biometric is the only kind of stolen credential that never expires and can never be replaced.
This is well understood, and it is usually offered as an argument for holding biometric data more carefully — better encryption, tighter access controls, a stricter retention schedule. We want to make a stronger argument. The problem is not that the industry secures stored faces badly. The problem is that it stores them at all, and that the storing is not an accident or a lapse. It is the business model.
Why Vendors Keep Faces
A verification vendor is asked to answer a narrow question: is this person live, and do they match this document? Answering it requires holding the face for a few seconds. Nothing about the question requires holding it afterwards.
And yet almost everyone does, because a retained face is worth a great deal to the vendor and nothing to the person it belongs to. Templates accumulate into an index, and an index makes the next check cheaper. It lets a vendor tell its customers that the same face was seen last month under a different name at a different company — a genuinely useful fraud signal, and one that can be packaged and sold back as a premium tier. It produces a dataset for training the next model. It creates switching costs, because the customer's history now lives inside the vendor. Every commercial incentive in the category points the same direction, and it is not toward deletion.
The result is that the thing the customer is buying — an answer to a yes-or-no question — comes bundled with something the customer never asked for and cannot inspect: a permanent, growing, centralized collection of human faces, held by a third party, sitting in one place.
Four Ways It Goes Wrong
Stored biometric data does not fail in one way. It fails in four, and only the first one is what people mean when they say "breach."
It leaks. This is the obvious one and the least interesting, because it is simply a matter of time and scale. A database of faces is a target in a way that a database of email addresses is not, precisely because of the irrevocability described above.
It is compelled. A vendor holding face records holds them subject to whatever legal process reaches the jurisdiction it operates in — subpoenas, warrants, national security letters, and in some regimes, processes with no notice to anyone. The company's privacy policy does not bind a court. We have written before about how readily the state reaches for records that already exist, and how the definitions of who can be compelled keep widening. A face index is not a neutral technical artifact; it is a resource that becomes available to anyone who can obtain lawful access to it, under laws that may not have been written yet.
It outlives the promise. The retention policy you agreed to was written by a company that may be acquired, restructured, or wound up. Data is an asset in a bankruptcy. Policies are revised with an email notification. The commitment made to you in 2026 is only as durable as the entity that made it, and entities in this sector are not notably durable.
It expands. Data collected for one purpose has a long history of finding others. The collection built to stop fraud becomes the collection used to recognize returning customers, then to match across clients, then to train a model, then to power a product nobody described at the outset. Each step is small and defensible. The destination is not one anybody chose.
The Law Has Been Trying to Reach This
It is worth noting how unusual the legal treatment of biometrics has become, because it reflects a settled judgment that this data is different in kind.
Illinois passed the Biometric Information Privacy Act in 2008 — notable not for its restrictions but for giving individuals a private right of action, which is rare in American privacy law and is why BIPA has produced consequences where other statutes have produced compliance memos. Meta settled a BIPA class action over facial recognition for $650 million. Clearview AI, which built a face search engine by scraping billions of images from the open web and sold access to it, settled a BIPA suit brought by the ACLU by agreeing to stop selling its database to most private entities in the United States. In 2024, Texas settled its own claim against Meta under the Capture or Use of Biometric Identifier Act for $1.4 billion.
The through-line is that these were not penalties for losing data. They were penalties for collecting and keeping it. Legislatures and courts have been circling the same conclusion for fifteen years: with biometrics, possession is itself the hazard. The industry's response has largely been to improve its consent flows.
The Other Design
There is a straightforward alternative, and its only real cost is commercial rather than technical.
Treat the face as something you borrow for the length of one question. Capture it, run the comparison, emit the answer, and destroy every input — the scan, the document images, and the biometric template itself. Keep the fact that a check occurred, when it occurred, who requested it, and what the result was. Keep nothing that could identify the person it was about.
This is how ByteVerify is built. The face scan, the ID images, and the template are destroyed when the check settles, within 24 hours at the outside, whether the result was verified, failed, or expired. There is no face index. There is no stored video. The verification software runs on servers Byte Federal operates, so the software's maker never receives a face at all. The binding statement is our published Biometric Data Retention and Destruction Policy, which exists so that this paragraph is an obligation rather than a marketing claim.
What this produces is a system with very little to steal. A total compromise of the records yields check identifiers, timestamps, requester names, and three-state results. It does not yield a single face, because there is not a single face in there to yield. The security property comes from the architecture rather than from the diligence of whoever is on call.
Minimizing the Output, Too
Data minimization is usually discussed as a question of what you retain. It applies just as much to what you emit, and this is where a second design decision follows from the first.
ByteVerify returns exactly three possible answers: verified, failed, or expired. There is no confidence score and no reason code, and both omissions are deliberate.
A score looks like more information and is actually a transfer of responsibility. Handed a 0.84, the buyer must decide what 0.84 means, and has been quietly made the party who set the threshold — without the test data, the attack telemetry, or the population statistics needed to set it well. Worse, a score reads as a warranty. It invites the belief that the number is calibrated to the buyer's specific risk, which it cannot be.
A reason code is worse still, because of who reads it. Telling a failed attempt which of the three checks it failed is a tutorial. Attackers iterate, and a system that explains its objections trains the next attempt against itself. The information that helps a legitimate user understand a decline is the same information that helps an adversary defeat the decline.
So the threshold stays with the party that has the lab results and the attack data, the output stays at three states, and the published fine print — rather than a number — is where the meaning of "verified" is pinned down.
What This Costs
An argument like this is only worth reading if it admits what it gives up, and this design gives up real things.
You cannot go back and look. If a transaction is disputed three weeks later, there is no video to review, no image to hand an investigator, and no way to have a human examine the face and form a second opinion. The evidence is gone, deliberately, and if your process depends on that review, this is the wrong tool for that step.
You cannot recognize a returning person. Without a retained template there is no way to know that today's verified face is the same face you verified last month, which forecloses an entire class of useful signals — repeat abusers, one person operating many accounts, a face seen across unrelated customers. That is the single most valuable thing a face index does, and choosing not to keep one means choosing not to have it.
And it means accepting that the check is narrow. It establishes that a live person held a physical government ID bearing their own face. It does not establish that the document is genuine or currently valid, because no issuing authority is queried. It does not establish who the person is, since no name is resolved and no record is consulted. It says nothing about sanctions, watchlists, AML, KYC, credit, or background, and it must not be used for decisions governed by the Fair Credit Reporting Act. It is one signal, to sit inside controls you already run.
Those are genuine costs, and a vendor with a face index can offer things we cannot. The position here is not that the trade is free. It is that the trade is worth making, because the capability being given up is smaller than the liability being avoided — and because the liability is not borne by the vendor. It is borne by every person whose face is in the index, who was never asked, and who has no way to get it back.
The Safest Database
Security in this industry is usually framed as a contest of diligence: better encryption, tighter access, shorter retention, more audits. All of that is worth doing, and none of it changes the underlying shape of the problem, which is that a collection of faces is dangerous in proportion to its existence rather than in proportion to how well it is guarded. Every control is a bet that the guarding will hold — across every employee, every vendor, every jurisdiction, every change of ownership, and every year the data continues to sit there being accurate.
There is one way to win that bet reliably, and it is not to guard better. The data a vendor keeps is the data that leaks, that gets subpoenaed, that survives the company, and that finds a second use nobody consented to. The obvious conclusion has been available the whole time, and the only reason it is unusual is that it is commercially inconvenient.
Ask the question. Take the answer. Destroy the rest. The safest biometric database is the one that does not exist.
Sources and Notes
Illinois Biometric Information Privacy Act (740 ILCS 14, enacted 2008); In re Facebook Biometric Information Privacy Litigation ($650M settlement, approved 2021); ACLU v. Clearview AI (BIPA settlement, 2022); Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code ch. 503) and the State of Texas settlement with Meta ($1.4B, 2024). Byte Federal's retention commitments are set out in our published Biometric Data Retention and Destruction Policy. ByteVerify is a supplemental risk signal and is not an identity, sanctions, AML, KYC, or background-screening service; laboratory figures for the underlying liveness and matching technology are as published by that technology's vendor from NIST/NVLAP-accredited testing under ISO/IEC 30107-3 and ISO/IEC 19795-2, and describe the technology rather than an audit of Byte Federal's deployment.
Frequently asked questions
Why is storing biometric data different from storing other personal data?
Because it cannot be revoked. A password can be changed, a card reissued, an account closed. A face cannot be reissued, so a leaked biometric stays accurate for the rest of a person's life and identifies them in every database anyone assembles afterwards. It is the only stolen credential that never expires.
Why do verification vendors keep face templates at all?
Because a retained index is commercially valuable to the vendor even though it is worthless to the person it belongs to. It makes subsequent checks cheaper, enables cross-customer matching that can be sold as a premium fraud signal, produces training data, and creates switching costs. Answering the actual question — is this person live and do they match this document — requires holding the face for only a few seconds.
What are the ways stored biometric data goes wrong?
Four, and only the first is what people mean by a breach. It leaks. It is compelled through subpoenas, warrants or other legal process that a privacy policy cannot override. It outlives the promise, because companies are acquired, restructured or wound up and data is an asset in a bankruptcy. And it expands, as data collected for one purpose is gradually used for others nobody described at the outset.
Why does ByteVerify return no confidence score or reason code?
Both are deliberate omissions. A score looks like information but transfers responsibility: the buyer is quietly made the party who set the threshold, without the lab data or attack telemetry needed to set it well, and it reads as a warranty. A reason code is worse, because telling a failed attempt which check it failed is a tutorial for the next attempt. The result is verified, failed or expired, and the published fine print pins down what verified means.
What does a delete-everything design cost you?
Real things. You cannot review a disputed check later, because there is no video or image to examine. You cannot recognize a returning person or spot one face across many accounts, which is the most valuable thing a face index does. And the check is narrow by construction. The position is not that the trade is free — it is that the capability given up is smaller than the liability avoided, and the liability falls on people who were never asked.
Topics in this guide
- privacy
- biometrics
- identity-verification
- data-retention
- policy
- byteverify
Use what you learned
Choose the Byte Federal product that fits your next step.