BIPA-Safe by Architecture. FCRA-Defensible by Patent.
The two largest legal risks in any rail biometric program are BIPA exposure and FCRA continuous-monitoring defensibility. Safience answers both architecturally: non-match images deleted instantly, no biometric identifier stored, the carrier remains data controller for X-LST, and eMotive's dual face-and-name match (US Patent US20240193715A1) is the FCRA accuracy defense on the record.
The core BIPA defense. No biometric identifier is stored within the statutory definition for non-match events.
The carrier — not Safience — is the data controller for X-LST. No new data controller relationship is created.
The patented dual face-and-name match methodology behind eMotive. The FCRA accuracy defense on the record.
Privacy brief, BIPA exposure analysis, FCRA workflow, DPA — delivered before procurement opens the file.
Privacy by Architecture, Not Privacy by Policy.
You are not a sales target. You are a mandatory legal gate, and a smart vendor sends you the privacy brief before you ask for it. Two questions drive everything: *what does BIPA (and the state-by-state mosaic emerging behind it) say about the data we are about to collect?* and *if our HR team runs continuous criminal monitoring on safety-sensitive employees and a wrongful adverse action follows, do we have an FCRA accuracy defense on the record?* BIPA applies to the collection, storage, and use of biometric identifiers. RTIS/RVIS captures, compares, and deletes on non-match — there is no stored biometric identifier within the statutory definition for non-match events. For match events, the reference image is one the carrier placed on its own X-LST under the carrier's existing legal basis — Safience is not the data controller. eMotive is a database of consented individuals — not a law enforcement database — and its dual face-and-name matching methodology (patented, US20240193715A1) is the FCRA accuracy defense on the record. The structure does not eliminate your legal review. It changes what the review is about — from "should we store this data" to "have we documented the architecture correctly in our privacy policy, DPA, and consent forms." We bring the documentation to that review.
-
The BIPA Storage-of-Biometric-Identifier Gap
Illinois BIPA settlements have exceeded $100M for unauthorized collection, storage, or use of biometric identifiers. Most vendors store the template; their defense is policy. Safience deletes the non-match identifier instantly — the statutory storage trigger does not fire for the overwhelming majority of entry events.
-
The X-LST Data Controller Gap
Most identity vendors become a new data controller in your privacy framework. X-LST is operator-controlled. Safience never sees list contents during normal operations and only adjudicates at the RAC moment. The carrier remains data controller; Safience is platform processor for the adjudication step only.
-
The FCRA Continuous-Monitoring Accuracy Gap
FCRA exposure on continuous monitoring is essentially an accuracy question: did the alert correspond to the person the carrier actually intended to monitor? eMotive's patented dual face-and-name match (US20240193715A1) is the accuracy defense — defensible against a name-coincidence challenge by design.
-
The State Biometric Privacy Mosaic Gap
Beyond Illinois, the state-by-state biometric privacy landscape (Texas, Washington, NYC, evolving California guidance) is widening every legislative cycle. Architectural defenses scale across statutes; policy defenses don't.
Your Privacy Review of Safience: Step by Step
GC review is a documentation exercise. We deliver the documentation up front.
-
Read the privacy brief
We send a four-page privacy architecture brief: data flow, retention rules, BIPA analysis, state mosaic analysis, FCRA workflow for eMotive, and patent reference for the dual-factor match. Outside counsel can scan it in one read.
-
Review the DPA
We send a DPA template that establishes the carrier as X-LST data controller and Safience as platform-tier processor for adjudication. Most carrier privacy teams redline at most a handful of clauses.
-
Review the eMotive consent framework
We send the eMotive consent form, adverse action notice template, dispute resolution procedure, and the FCRA workflow. The dual-factor match is the accuracy defense.
-
Validate union and CBA implications
For unionized environments, we send a one-page brief written for the labor side: entry-threshold-only RTIS/RVIS, consent-based eMotive, no automated adverse action, no surveillance of work-floor activity.
-
Sign and deploy
With privacy brief, DPA, eMotive consent framework, and union brief on file, the deployment clears legal review on a single pass.
Most Biometric Vendors vs. Safience Privacy Posture
| Capability | Most Biometric Vendors | Safience Privacy Architecture |
|---|---|---|
| BIPA defense | Policy-based ("we stored it, here's why") | Architectural ("we did not store the non-match identifier") |
| Data controller for watchlists | Vendor becomes new controller | Carrier remains X-LST data controller |
| FCRA continuous-monitoring defense | Probabilistic / name match | Patented dual face + name match (US20240193715A1) |
| Non-match data retention | Stored for window of days/weeks | Deleted instantly |
| On-device sensitive data | Stored on edge sensor | Zero on-device sensitive data |
| State biometric mosaic resilience | Re-fight policy per state | Architecture scales across statutes |
| Documentation provided before review | Marketing material | Privacy brief, DPA, eMotive consent pack, union brief |
| Union / labor legal review | Often surfaces during deployment | Pre-drafted brief delivered alongside the privacy pack |
Products for General Counsel
GC review is a documentation exercise. We deliver the documentation up front.
Privacy Architecture Brief
BIPA analysis, state biometric privacy mosaic, FCRA workflow, retention rules, data-flow diagram. Four pages, written for outside counsel review.
DPA Template
Establishes the carrier as X-LST data controller and Safience as platform-tier processor for adjudication. Most carrier privacy teams redline only a handful of clauses.
eMotive FCRA Pack
Consent form, adverse action notice, dispute resolution procedure, patent reference (US20240193715A1). Built for HR-side FCRA compliance.
Union / Labor Brief
One-page document written for SMART-TD, BLET, Boilermakers, and Brotherhood review. Entry-threshold-only, consent-based, no automated adverse action.
RAC Adjudication Record
Human-verification chain of custody for every alert. The documentation layer that supports LE referral, plaintiff-bar defense, and regulator review.
Where Next
The privacy posture pairs with three operational lenses.
Get the Privacy Brief Before Procurement Opens the File.
Schedule a 30-minute privacy review with our legal architecture team. You will leave with the four-page privacy brief, the DPA template, the eMotive FCRA pack including patent documentation (US20240193715A1), and the union-side brief — everything outside counsel and labor counsel will ask for.