Rising data breaches, fraud, and evolving cyber-attacks are pushing organizations to upgrade authentication in ways that increase security while improving usability. Many legacy IAM stacks struggle to keep pace with new requirements and technologies, especially in consumer contexts, prompting a modular approach that separates authentication from the broader IAM system and uses discrete MFA and risk-adaptive services. Risk-adaptive authentication evaluates contextual and behavioral signals—such as location, device, time of day, and user behavior baselines—to trigger step-up challenges (e.g., OTPs, push approvals, biometrics, hardware tokens) only when risk warrants it. Behavioral biometrics extend this model by enabling login, in-app authorization, or continuous authentication based on patterns like keystrokes, swipes, and device sensor data, typically collected via client-side agents or SDKs.
Regulatory pressure increases the need for strong authentication and careful handling of personal data. Financial services face MFA/strong authentication requirements under PSD2 and similar rules (e.g., 23 NYCRR 500), while AML/KYC obligations drive identity data collection that must still comply with privacy regulations like GDPR and CCPA/CPRA. Passwordless authentication has emerged as a practical way to improve both security and UX, including biometrics, trusted devices, and risk-based checks that avoid interrupting “happy path” flows. Account recovery remains essential; techniques include OTPs, push notifications, and device linking, while Knowledge-Based Authentication is discouraged due to weak security.
Keyless (founded 2019) provides a passwordless biometric authentication platform for workforce and consumer use cases, delivered via a multi-cloud SaaS “Keyless Network” plus an Authenticator app and SDK. Its core differentiator is privacy-preserving biometric protection: encrypted biometric templates are split using Shamir’s Secret Sharing, distributed across network nodes, and evaluated with Secure Multi-Party Computation so nodes never access unencrypted biometric data. Keyless supports standards-based SSO, remote ID document verification, liveness detection, device health checks, and has achieved FIDO2 and FIDO biometric subcomponent certifications, with stated high availability and fast transaction processing—while still lacking SIEM and external fraud-intel integrations and broader provisioning standards.
See All Locations
See All Locations