Solutions
About
Security
Resources
Contact us
Request Your Trial
Request Your Trial

FAQ

FAQ
FAQ

General

YEO CFR SDK

YEO for Business

General

Can it be spoofed?

YEO's three-layer stack, Facial Mapping, Anti-Spoofing Liveness Detection, and Depth Verification, is specifically designed to defeat common attack vectors including photographs, video replay, deepfake media, and physical masks. Independent penetration testing has been completed. No system is unconditionally spoof-proof, but the architecture significantly increases the difficulty and cost of attack.

What is liveness detection and why does it matter?

Liveness detection is the capability that distinguishes a live, physically present person from a representation of one, a photograph, a video, or an AI-generated deepfake. Without liveness detection, a facial recognition system can be defeated by holding a photograph up to the camera. YEO's Anti-Spoofing Liveness Detection, combined with Depth Verification, makes this attack class significantly harder. YEO has completed independent penetration testing using presentation imitation attacks, including masks and deepfake technology.

Who founded YEO?

YEO was founded in 2017 by Alan E J Jones (CEO), Sarah Bone (CMO), and Luca Rognoni (CSO). Alan is a serial entrepreneur with four successful exits including a NASDAQ-listed business. Luca brings 25+ years of encryption and security engineering experience and is the architect of YEO's core technology. Sarah leads positioning, go-to-market strategy, and demand generation.

Where is YEO based?

YEO Messaging is headquartered in London, UK.

What makes YEO different from other identity verification companies?

Most identity verification companies solve the onboarding problem: verifying who opens an account. YEO solves the session problem: verifying who is operating the account throughout the session. These are technically and commercially different challenges. YEO is also distinguished by its on-device architecture: no biometric data is transmitted or stored externally, and by its continuous, passive verification model rather than point-in-time checks.

What industries does YEO serve?

YEO's technology is relevant wherever identity assurance matters beyond login. Our current focus is financial services (banking, payments, crypto, wealth management), regulated professional services (legal, compliance, insurance), enterprise communications, and child safety online. The CFR SDK is designed to integrate into any platform where session-layer verification adds value.

What is continuous identity verification?

Continuous identity verification means confirming that the right person is present throughout a digital session, not only at the point of entry. YEO's technology runs passively in the background, verifying presence at regular intervals and at key points (such as authorising a transaction or sending a high-risk communication), without interrupting the user experience for legitimate users.

What is the session gap?

The session gap is the window between a user authenticating at login and everything that happens inside the session afterwards. Almost every digital platform verifies identity at the point of login. Almost none verify that the same person remains present and in control of the session after that moment. Account takeover, authorised push payment fraud, and AI-enabled impersonation all exploit this gap β€” operating inside authenticated sessions rather than trying to defeat the login.

What does YEO stand for?

It stands for Your Eyes Only. It reflects the core principle behind everything we build: communications and verified identity that belong only to the person they are meant for.

What is YEO Messaging?

YEO Messaging is a secure communications and continuous identity verification company. We build technology that verifies not just who opens a digital session, but who remains present throughout it. Our products serve regulated industries, enterprise organisations, and technology platforms that need identity assurance beyond the login moment.

What products does YEO offer?

YEO has three products. The YEO CFR SDK embeds continuous facial recognition directly into third-party applications, payment platforms, digital banking, crypto wallets, and any platform where session-layer identity assurance matters. The YEO Messaging SDK provides identity-verified, end-to-end encrypted messaging infrastructure that developers can embed into their own platforms. YEO for Business is our enterprise secure communications product for regulated organisations.

YEO CRF SDK

Does the on-device architecture help with BIPA compliance?

Yes, materially. The Illinois Biometric Information Privacy Act (BIPA) and similar state-level biometric privacy laws create liability around the collection, storage, and transmission of biometric data. Because YEO's on-device architecture means no biometric data is transmitted or stored externally, it removes the central point of liability that most biometric systems create. Organisations should conduct their own legal analysis, but the starting position is structurally different: there is no biometric database to defend.

What happens if verification fails?

The integrating platform defines its own policy response. Options include prompting a re-verification step, flagging the session for review, restricting high-risk actions, or ending the session. YEO provides the verification signal; the platform controls the action.

Does it affect the user experience?

For legitimate users, the experience is passive; verification happens in the background without prompts, interruptions, or friction in normal use. A verification prompt only surfaces when a significant event triggers it (such as a high-value transaction) or when the system detects that the verified account holder may no longer be present.

What platforms and operating systems does it support?

The SDK supports iOS and Android mobile environments. Please contact us for current platform compatibility and the roadmap.

How does the SDK integrate?

Integration is at SDK level, meaning it does not require changes to a platform's existing authentication infrastructure. It runs alongside existing login systems rather than replacing them. Most integrations go live within days of the technical handshake being completed.

Is the CFR SDK patented?

Yes. YEO holds patents in the US, the UK, the EU, and China, covering the continuous facial recognition technology stack. The patents are valid until 2038.

Is biometric data stored or transmitted?

No. All biometric processing happens on the user's device. No image, template, or biometric data is transmitted to YEO's servers or any external system. There is no central biometric database. This is an architectural fact, not a policy promise β€” there is no transmission pathway to remove data from.

What is the YEO CFR SDK?

The YEO CFR SDK (Continuous Facial Recognition Software Development Kit) is a biometric identity verification layer that integrates directly into existing applications. It verifies that the account holder is present and in control of their session β€” continuously, passively, and entirely on-device β€” rather than only at login.

How does the CFR SDK work?

The SDK runs three verification layers in combination. Advanced Facial Mapping builds a precise biometric model of the enrolled user. Anti-Spoofing Liveness Detection distinguishes a live person from a photograph, video replay, or AI-generated deepfake. Depth Verification confirms physical presence, distinguishing a live face from a screen or mask. All three layers process on the user's device. If the verified account holder is no longer present, the platform receives a real-time policy trigger, which the integrating application can act on according to its own rules.

YEO for Business

How do we get a demo?

Book a demo at yeomessaging.com/contact-us or contact the team directly at hello@yeomessaging.com.

How long does implementation take?

Implementation timelines vary by organisation size and existing infrastructure. Please contact us to discuss your specific requirements: yeomessaging.com

Is YEO for Business available on mobile and desktop?

Yes. YEO for Business is available across mobile (iOS and Android) and desktop. Please contact us for current platform availability and enterprise deployment options.

Is biometric data stored centrally?

No. YEO's on-device biometric architecture applies to YEO for Business as well as the CFR SDK. Biometric verification happens on the user's device. No biometric data is transmitted to or stored on YEO's servers.

Does YEO for Business replace our existing communications infrastructure?

No. YEO for Business is designed to sit alongside existing infrastructure, providing a verified, compliant channel for regulated communications, high-stakes decisions, sensitive instructions, and SMCR-relevant actions without requiring firms to abandon their existing tools for general business communication.

Does data stay under the firm's control?

Yes. YEO for Business is built on a data sovereignty model; communications data is held under the control of the regulated firm, accessible to regulatory standards. This is distinct from consumer messaging platforms where data resides on third-party servers and cannot be produced to regulatory standards by the firm.

Who is YEO for Business designed for?

YEO for Business is designed for regulated firms in financial services, banks, asset managers, brokers, investment firms, and regulated professional services, including legal and insurance. It is particularly relevant for firms subject to SMCR, which imposes personal liability on named senior individuals, and for any organisation that needs to produce evidential-standard communications records to a regulator.

What is the session gap and why does it matter for compliance?

The session gap is the period between a user's login and the end of their session. Most platforms have strong controls at login but no verification mechanism after that point. For regulated firms, this means a named individual's credentials could theoretically be operated by someone else in the session and the firm could not demonstrate otherwise. YEO for Business closes this gap with continuous biometric verification throughout the session.

What is a verified audit trail and why does it matter?

A standard communications record shows what was said and when. A verified audit trail shows who said it, confirmed by biometric identity verification at or around the point of the communication, not reconstructed after the fact. Under SMCR, personal liability requires the FCA to identify a named individual responsible for a specific decision. A session log cannot confirm that the account holder was the person present. A verified audit trail can.

What regulations does YEO for Business help with?

YEO for Business is directly relevant to obligations under SMCR (Senior Managers and Certification Regime), MiFID II, Market Abuse Regulation, FCA Consumer Duty, and insider dealing rules, all of which require regulated firms to evidence not just what was communicated, but who communicated it, and that the named individual was the verified person on record at the point of the communication. It is also relevant to data sovereignty obligations under UK GDPR and sector-specific FCA operational resilience requirements.

How is YEO for Business different from WhatsApp, Signal, or Microsoft Teams?

Consumer and general-purpose messaging platforms, including WhatsApp, iMessage, and Signal, solve the encryption problem. They protect the content of messages in transit. They do not solve three problems that matter to regulated firms: data sovereignty (data on WhatsApp sits on Meta's servers, not the firm's), identity evidence (session logs show an account was active, not that the named account holder was verified at the point of the communication), and audit trail quality (most platforms produce content records, not identity-verified records). YEO for Business addresses all three.

What is YEO for Business?

YEO for Business is an enterprise secure communications platform built for regulated organisations. It combines end-to-end encrypted messaging with continuous biometric identity verification and a verified audit trail, meaning every communication can be evidenced not just for its content, but for the verified identity of the person who sent it.

Solutions
YEO CFR SDKYEO Messaging SDKYEO For Business
Industries
LegalCyberSecurityBankingInsuranceGovernmentPublic AuthoritiesSocial Communities
Resources
InsightsCase StudiesWhitepaper CFR SDKFAQPress
Company
AboutSecurityContact Us
Β© 2026 YEO messaging Ltd is registered in England and Wales 10785061. |
Terms & Conditions | Privacy Policy | Cookie Policy

πŸ‡ΊπŸ‡Έ US Patent No: 10,607,035 (Granted March 31, 2020) πŸ‡¬πŸ‡§ GB patent No: 1713943.7 (Granted February 2022) πŸ‡¨πŸ‡³ Chinese patent 201880071020.4 (Granted April 2nd 2024) πŸ‡ͺπŸ‡Ί EU patent No: PCT/EP2018/073464 (applied Feb 2020)