I don't believe this vague blanket claim. How much are you paying somebody who proves you wrong? A million dollars? No? Then I should assume anybody who can spoof this and would like a million dollars might do so unless the total value secured is assured to be less than one million dollars (in which case I expect this project will be gone by summer).
XIX ends up capturing a huge amount of facial recognition data and then storing it somewhere indefinitely in "the cloud" to inevitably get stolen and then no doubt we can expect a PR crafted apology and an insistence you've learned your lesson.
Every single time a person authenticates, video of their face is transmitted over the network. I have no doubt you'll say it's ephemeral and you don't store that video, but of course the users have no way to assure themselves of that, they just know they sent it.
Overall my impression is that this delivers markedly worse real world security than WebAuthn and has terrible privacy issues that can't be fixed.