Engineering
Security & Cryptography
Security is our core discipline, not a feature we add at the end. Our approach is bottom-up — we build on a pre-designed security framework rather than retrofitting one — which produces systems that are resilient to attack at the ground level.
Two-factor authentication
We provide end-to-end two-factor (2F) authentication for merchant websites and SaaS applications, covering both devices and integration. Two models are offered: an offline pocket generator using a smartcard and PIN for challenge/response strong-authentication, and an interactive USB token that establishes an SSL/TLS client-authenticated, encrypted channel. We supply the smartcards, USB tokens and pocket generators, card and key-management modules, and security libraries that integrate with popular web servers.
PKI & applied cryptography
We implement public-key infrastructure and RSA-based security for closed user-group schemes, including certification-authority operation, certificate management and key diversification. The same cryptographic processes run consistently from card firmware, through device hardware, to the server-side SAM.
Security integration
Cryptography is only as good as its integration. We embed security across every layer — secure elements and SAMs for key storage, signed transactions on-device, secure VPN/IPSEC channels for communications, and comprehensive transaction logging and auditing throughout.