article

Boop chooses the TACEO Network for private palm matching

5 min read

Boop is changing how people move through physical spaces with its palm scanner. A single scan of your hand handles venue entry, coat check, and food and drink budgets, so you can leave your wallet and phone behind.

Read Boop’s site carefully and you’ll find an easy-to-miss line: your palm-code is cryptographically split across independent entities, and no single entity can reconstruct it, including Boop.

Boop is partnering with TACEO specifically to enforce this crucial privacy requirement.

Securely working with physical biometrics

Plenty of biometrics never touch an external system. The fingerprint reader on a front door keeps its data stored locally on the hardware. Nothing leaves the device, eliminating central database risks.

Boop is building for scale across multiple locations. The same palm needs to work at a coffee shop in London, a gym in New York, or an event space down the street. That requires comparing a palm-scan against stored records from anywhere.

The standard solution relies on a central database where someone hosts the data and someone can read it. Encryption simply shifts the vulnerability to whoever holds the key. If that data leaks, the damage is irreversible. A leaked password takes minutes to reset, whereas a compromised palm-code lasts forever.

Safe physical biometrics require running cross-location comparisons without any single party ever holding the usable palm-code. That’s where TACEO comes in.

To eliminate the need for a central database, the core solution relies on Multiparty Computation (MPC), a branch of cryptography that splits sensitive data into secret shares across multiple machines. The machines compute an output together without any single one ever decrypting or seeing the underlying input.

TACEO powers some of the largest production MPC identity deployments in the world, processing high-scale biometric comparisons without exposing raw user data. But scaling this tech in the physical world requires more than pure cryptography.

Cryptography is one part. The network is another.

MPC is well understood. The protocols are public, the papers are decades old, and a competent engineering team can implement a matching protocol. What a team cannot easily produce is the network of independent node operators.

MPC security relies entirely on genuine independence across the network: different organisations, different jurisdictions, no common owner, and no shared incentive to collude. Structuring, vetting, and maintaining an institutional network that guarantees those trust boundaries across borders is a complex legal and architectural challenge long before it is a cryptographic one.

Boop’s alternative was to find those operators themselves, one at a time, around the world, and then keep the network running while also shipping hardware. They chose not to, allowing them to focus fully on making Boop the standard gesture for everyday access and payments.

The TACEO Network is operated by academic and institutional node operators distributed globally, and has been running secure computation for large scale production systems for over a year.

We realized early on that if we wanted to build private biometrics at scale, we had two choices: become a distributed infrastructure company ourselves, or partner with the team that already mastered it. By building on the TACEO Network, we get the highest standard of cryptographic privacy out of the box without taking our eye off shipping the physical device.

— Nathan Jay, CEO and Cofounder of Boop

How private palm matching works

Using MPC, the palm-code exists as secret shares distributed across independent operators on the TACEO Network. These operators run comparisons directly over the secret shares without reconstructing the original data.

In a Boop deployment on the TACEO Network, a comparison runs like this:

Neither Boop, TACEO, nor the venue ever hosts a central biometric database.

Applied privacy for the real world

This architecture removes the liability of storing biometric data, giving venues a way to offer instant physical access without taking on sensitive user data.

Members’ clubs, gyms, offices and festival gates currently run on keycards, fobs and wristbands. A palm replaces all of them, and the venue never holds anything it could lose.

Payments leverage the exact same underlying architecture, extending the system from physical access to everyday transactions.

When you unify access and payments under a single privacy-preserving identity layer, the convenience factor is huge. Users can walk out the door without a phone or wallet, venues remove sensitive data liability, and the entire flow bypasses walled-garden payment rails. Boop is showing what real-world identity utility looks like when privacy is built into the foundation.

— Lukas Helminger, CEO and Cofounder of TACEO

Building the privacy-preserving physical layer

As a single gesture powers more of your daily life, the foundation behind it needs to match that ambition. Using your palm to open a gym door is great convenience, but using it to handle your wallet, keys, and identity turns a physical device into essential everyday utility. Designing that utility to be private by default means users get absolute control, every time they boop.

Together, Boop and TACEO are proving that real-world physical convenience and privacy-first architecture can ship in the same product.

If you are building hardware or identity systems that require private biometric matching, get in touch with our team.

Want to read more about identity at TACEO? Browse all Identity articles