Strong 2FA and MFA are increasingly required in both employee and consumer contexts because username/password authentication is simultaneously insecure and burdensome. Many recent breaches have involved compromised passwords on user and administrative accounts, pushing organizations to improve assurance while reducing user friction. Regulations are also accelerating adoption; PSD2 in the EU, for example, requires strong customer authentication and behavioral analysis to approve monetary transactions, needs that full-featured MFA can help address. Typical MFA platforms emphasize interoperability with IAM directories, fast provisioning, SSO for on-prem and SaaS apps, multiple authentication methods, risk-adaptive policies using contextual factors (device, network, geolocation, behavioral signals), and integration with governance and security intelligence tools.
inWebo, founded in Paris in 2008 with offices in Silicon Valley, provides a cloud-based 2FA SaaS for on-prem and cloud applications, offering browser and mobile authenticators plus SDKs. The product supports password login, OTP via mobile app and SMS, mobile biometrics (via SDK), step-up authentication, and mobile push approvals that can be frictionless to the user. It also provides a browser-based “Virtual Authenticator” requiring JavaScript, using a proxy approach that intercepts requests and prompts for a PIN, incorporating a browser “fingerprint” as a device identity signal. inWebo can also function as a RADIUS server for VPN/network access and supports SAML federation; OAuth 2.0 and OIDC support were expected in 2018, with limited SSO requiring consistent usernames across apps.
The service exposes authentication logs via REST APIs for external analytics tools but lacks built-in analytics and full consent management, offering instead “transaction sealing” with cryptographic proof of device-originated consent. Its infrastructure uses FIPS 140-2 cryptography and HSM-backed key handling, offers a 99.9% SLA, and reports 100% uptime over six years. Strengths include rapid deployment and high availability; challenges include limited authenticators, missing FIDO, limited risk-adaptive and threat intelligence features, and gaps in analytics and interoperability enhancements.
See All Locations
See All Locations