The standard objection to biometric authentication is not that it fails to work. It is that it works, and then someone stores the result.
A password that leaks can be changed. A fingerprint cannot. That asymmetry is the entire reason biometric systems attract regulatory attention out of proportion to their footprint, and it is the reason most organisations that would benefit from biometric verification quietly decide not to build it.
The constraint we started from
We began Tilde ID from an inverted question. Rather than asking how to secure a biometric database, we asked what an identity system looks like if it is structurally incapable of holding one.
That is a stronger position than it sounds. A guarantee enforced by encryption depends on key management, staff discipline and the continued good behaviour of everyone with production access. A guarantee enforced by the schema — the data was never written — survives all three going wrong.
What that means in practice
Three things follow from the constraint, and they are not optional extras.
Templates, not images. The capture produces a mathematical representation, and the original is discarded before it leaves the device. A template is not reversible into a face or a fingerprint, which means a template store is not the same category of asset as an image store, either technically or legally.
Matching close to the capture. Where the hardware allows it, comparison happens on the device and the server receives an assertion rather than a biometric. The server learns that a match occurred. It does not learn what matched.
Retention as an architectural decision. What a system stores is decided before what it does. Every additional field has to justify itself against the question of what happens when it leaks, because eventually something always does.
The cost
This is more difficult to build than the conventional approach, and it is worth being honest about where the difficulty lands.
On-device matching means dealing with an enormous range of hardware quality — and the devices most of our market actually owns sit at the lower end of it. Template-based comparison narrows the tuning options available for the tradeoff between false accepts and false rejects. And discarding the source image means you cannot re-process historical captures when the algorithm improves, which is a real capability to give up.
We think the trade is correct anyway. The alternative is building an asset whose value to an attacker rises every year while your ability to protect it stays flat.
Why this becomes the default
Regulation is converging on data minimisation from several directions at once, and the organisations that most need identity verification — banks, marketplaces, public services — are precisely the ones least able to absorb a breach of this kind.
At that point, not holding the data stops being a principled position and becomes the commercially obvious one. We are building for that moment rather than waiting for it.