How does the identification system work?

The two operating modes of the TOFIND algorithm

Connected / mode

I — Online identification

1
Capture: image + GPS location
2
Pre-validation and upload to server
3
Qualitative assessment: similarity analysis
4
Biometric validation (cosine, 512-d)
5
Audited record (audit chain link)
  1. Real-time transmission — the local device captures the image and the GPS coordinates of the person, instantly sending the data to the central server.
  2. Pre-validation and quality filter — before heavy processing, the local system runs a quick check for quality and obvious inconsistencies, optimizing bandwidth use.
  3. Central qualitative assessment — on the server, the AI engine runs a visual similarity analysis to confirm the face and discard visibly incorrect candidates.
  4. Biometric validation (cosine, 512-d) — the algorithm measures the cosine distance between the 512-dimension vector of the captured photo and the registered vector, producing the final verdict.
  5. Audited record and verdict — after confirmation, the result is sent to the device and an immutable cryptographic hash (SHA-256) is generated and logged in the audit chain.
Offline / mode

II — Offline identification

1
Preload: watchlist sync model
2
Local comparison
3
Protected queue
4
Reconciliation
  1. Preload (Watchlist Sync Model) — the system syncs a restricted sub-database, defined by the agency as a priority: wanted individuals and/or missing persons.
  2. Local comparison — the detected face is processed by the local model, which generates a numeric vector representing the face, without saving the raw image.
  3. Protected queue — the result stays encrypted on the device itself, awaiting a network connection for final reconciliation.
  4. Reconciliation — as soon as the device detects a signal, the system syncs these records with the server, retroactively updating the audit chain.
Facial recognition engine

ArcFace architecture — the same one that already topped the industry's most respected ranking

TOFIND Sentinel is built on ArcFace architecture. An implementation of this architecture achieved 1st place on the VISA track of NIST FRTE (Face Recognition Technology Evaluation, the industry's most respected ongoing benchmark, used by governments, border agencies and police forces worldwide), in October 2021.

99.8%accuracy on a reference academic benchmark (LFW)
98%+accuracy even under difficult conditions — mask, extreme angle, low resolution
512vector dimensions per face analyzed

How TOFIND compares two faces

θ v₁ v₂ θ v₁ v₂ Same person Different people

Each face becomes a vector of 512 numbers. Comparing two faces means measuring the angle between these vectors: the smaller the angle θ, the higher the probability of being the same person. It's this "angular margin" — which gives ArcFace its name — that makes the comparison more robust to lighting and pose variation.

The ecosystem's data frontier

TOFIND MISP — connects to any legacy database

Every state keeps its data differently. MISP is the API that connects to any source database, processes and normalizes the data via AI, and delivers it ready for Sentinel — always pending human review before any activation.

Information Security

Security and rigor are our top priority.

SHA-256chained hash audit trail
2×independent verification layers
100%human confirmation always required

Every event generated by the system is recorded on a trail designed so that any later alteration is detectable, like an airplane's black box. The architecture was built from day one around the principles that Brazilian facial-recognition regulation has been consolidating: mandatory human confirmation before any identification counts as a decision.

Meet the SentinelX hardware