Identity threat response

Every identity attack has a window. We close it in-request.

PasskeyBridge ingests carrier and breach signals, scores them against your playbook, and revokes, freezes, or steps up in the same request—backed by post-quantum signatures you can verify yourself.

Grounded inNIST FIPS 204W3C VC 2.0FIDO2 / WebAuthnGSMA Open Gateway
Threat response in action

Three attacks. Three neutralizations.

Real attack patterns mapped to real response timelines—from signal ingestion to automated remediation, every millisecond accounted for.

T+0 msThreat detected
Attacker

Attacker initiates SIM port-out request at carrier store with social-engineered credentials.

PasskeyBridge

Vonage Number Insight webhook fires. PasskeyBridge ingest validates HMAC-SHA256 signature.

T+8 msAnalyzing
Attacker

Carrier begins porting process. Attacker's device receives OTP.

PasskeyBridge

Intelligence worker scores event. Behavioral clustering detects anomaly—device fingerprint mismatch.

T+14 msResponding
Attacker

Attacker attempts account login with intercepted OTP.

PasskeyBridge

Cascade engine triggers. Cross-reference confirms SIM signal does not match bound passkey device.

T+38 msResolved
Attacker

Login attempt rejected. Attacker locked out.

PasskeyBridge

All active sessions revoked. Passkey re-enrollment ceremony initiated on verified device. Audit log written.

Sessions revoked. Passkey re-enrollment triggered.38 ms
Signal sources

We watch what a passkey can't see.

Carrier state, breach exposure, agent behavior, and device binding—ingested continuously, scored on every request.

Carrier

Live carrier state

SIM tenure, port-out, and Silent Number Recycling from carrier intelligence, validated on ingest and scored inside the auth path.

Vonage Number InsightHMAC-SHA256sim_swapport_out
Breach

Breach-sourced credentials

Leaked credentials matched against HIBP with k-anonymity—only a hash prefix ever leaves your tenant, never a password.

HIBP k-anonymitycredential_leakzero PII
Agents

Behavioral trust decay

A live trust score per delegated agent, recalculated on A2A activity; drift past the narrowing threshold revokes scope automatically.

trust scoreA2A coefficientscope narrowing
Device

Bound passkey device

Every decision cross-references the requesting device against the passkey bound to the account—WebAuthn, phishing-resistant, revocable.

FIDO2 / WebAuthndevice fingerprintrevocable
Cryptographic foundations

Security you can verify, not just trust.

Every primitive is a ratified NIST standard or a provably secure construction. No proprietary ciphers, no security through obscurity.

ML-DSA-65 / ML-DSA-87

NIST FIPS 204 lattice-based digital signatures. Hybrid classical + post-quantum scheme with runtime algorithm branching per tenant.

ML-DSA-65 is default (3,309-byte signatures). ML-DSA-87 (Security Level 5, 4,627-byte signatures) available as Enterprise add-on.

  • Dilithium-based lattice construction (mldsa-wasm)
  • Hybrid co-signing: classical ES256 (P-256), or ES384 (P-384) on the ML-DSA-87 / CNSA 2.0 tier
  • Per-tenant pqc_level configuration
  • CNSA 2.0 aligned signature suite
3.3 KB / 4.5 KB signatures · FIPS 204

BLAST Protocol

Bi-Lateral Authenticated Secure Tunnels. X25519 ECDH key exchange with perfect forward secrecy and ephemeral session keys.

Every tunnel negotiation produces a unique shared secret. Keying material is zeroized after session teardown.

  • X25519 ephemeral key pairs
  • HKDF-SHA256 key derivation
  • AES-256-GCM tunnel encryption
  • Automatic session expiry + teardown
AES-256-GCM · PFS

QRNG Entropy

Hardware quantum random number generation from Outshift and QCi sources, with deterministic DRBG expansion and local CSPRNG fallback.

Entropy pool is continuously replenished. Each request draws from the highest-available source in the hierarchy.

  • Outshift QRNG primary source
  • QCi uQRNG secondary source
  • ANU Quantum tertiary source
  • Local CSPRNG guaranteed availability
Hardware entropy · 4-tier fallback

Cached Trust Proofs

Time-bounded, PQC-signed proof tokens that enable offline identity verification without network connectivity.

Proofs carry a trust level, expiry, and optional ML-DSA signature. Revalidated automatically when connectivity resumes.

  • Encrypted proof payload (AES-256-GCM)
  • Time-bounded with automatic expiry
  • Optional ML-DSA post-quantum signature
  • Network-aware trust level assignment
Offline verification · PQC-signed
Compliance posture

Standards alignment you can audit.

Every cryptographic implementation, data-handling policy, and credential lifecycle maps to a ratified standard.

Standard
Status
Coverage
SOC 2 Type II
Aligned
Immutable audit logging, key rotation policies, tenant isolation via PostgreSQL RLS, time-bounded credential lifecycles.
ISO 27001
Aligned
Information security management controls—access control, cryptographic key management, incident response procedures.
NIST FIPS 203
Aligned
ML-KEM key encapsulation tracked on the post-quantum roadmap. Current production hybrid uses X25519 ECDH for key agreement and ML-DSA for signatures (FIPS 204).
NIST FIPS 204
Implemented
ML-DSA lattice-based digital signatures via mldsa-wasm (PQClean reference). ML-DSA-65 default; ML-DSA-87 (Security Level 5) Enterprise add-on.
W3C VC 2.0
Full Parity
JWT-VC issuance, SD-JWT-VC selective disclosure, OID4VCI ceremonies, OpenID4VP presentation exchange, StatusList2021 revocation.
CNSA 2.0
Aligned
ML-DSA signatures (FIPS 204) deployed today; ML-KEM (FIPS 203) on the roadmap. Timeline-compliant with NSA CNSA 2.0 transition guidance.
eIDAS 2.0
Aligned
Cross-border credential interoperability. Verifiable credential format compatibility with EU Digital Identity Wallet architecture.
FIDO2 / WebAuthn
Implemented
Passkey registration, authentication, and device biometric binding. Parametric revocation with cross-pillar recovery.

Put a trust layer under your identity.

Start free in minutes, or talk to us about the enterprise and agentic tiers.

Prefer the full technical overview? Read the docs or request the whitepaper.