aswad
Security

Security you can audit,
not just trust.

No passwords to steal, no shared secrets to breach. Just live-verified identity and phishing-resistant passkeys — with an audit trail for every use.

0
Passwords stored
100%
Phishing-resistant
<1s
To verify

Nothing to steal

No password database, no shared secret. A breach of a connected app exposes only useless public keys.

Phishing-resistant

Passkeys are bound to the real domain. Paste one on a fake site and it simply won't work — by design.

Bound to a verified passport

Every passkey traces to a KYC-verified, immutable web passport — so high-risk actions prove a real, present human.

Certified & compliant

Built to the standards your auditors expect.

SOC 2 Type II
Audited controls
FIDO2 certified
Phishing-resistant auth
PSD2 SCA
Strong customer auth
GDPR · CCPA
Data minimization

Security FAQ

Where is my private key stored?

On your device, protected by your biometric. It never leaves the device and is never transmitted to Paswad.

What happens if Paswad is breached?

There's no password database and no private keys to take — only public keys and an activity log. The most valuable target simply doesn't exist.

How do you stop account takeover?

Recovery is anchored to live verification against your immutable web passport — not an emailed link. High-risk recoveries add an agent check and a post-recovery cool-down.

Can an app act without me?

No. Reading and signing are separate grants, and every payment needs a fresh passkey tap. You can revoke any app anytime.

Security FAQs

How Paswad's architecture keeps accounts and payments safe.

Where are private keys stored, and does Paswad ever see them?

Your private key is generated on your device and protected by your biometric or device PIN. It never leaves the device and is never transmitted to Paswad. We only ever store the matching public key, which is useless to an attacker.

This is the core of the FIDO2 and WebAuthn model. See how passkeys work.

What data does Paswad actually store?

Paswad stores public keys, the verified claims of your web passport, and an activity log of sign-ins and signed transactions. There is no password database and no private keys, so the most valuable target simply does not exist.

We follow data minimisation, and selective disclosure means apps receive only the claims they need. Learn about the verified passport.

What standards and certifications does Paswad meet?

Paswad is built on the open FIDO2 and WebAuthn standards and is FIDO2 certified for phishing-resistant authentication. We support PSD2 strong customer authentication for payments and align with GDPR and CCPA through data minimisation.

Audited controls are covered under SOC 2 Type II, with compliance support available for regulated customers. See SCA in transaction signing.

What happens to my accounts if Paswad is breached?

Because there is no password database and no private keys on our servers, a breach exposes only public keys and an activity log — none of which can be used to sign in or move money on your behalf.

Reading and signing are separate grants, every payment needs a fresh passkey tap, and you can revoke any connected app at any time. Paswad never holds your funds.

The Passwordless Dispatch

Plain-English passkey & identity writing from Muslih Ali — straight to your inbox. No spam, unsubscribe anytime.