Security you can audit,
not just trust.
No passwords to steal, no shared secrets to breach. Just live-verified identity and phishing-resistant passkeys — with an audit trail for every use.
Nothing to steal
No password database, no shared secret. A breach of a connected app exposes only useless public keys.
Phishing-resistant
Passkeys are bound to the real domain. Paste one on a fake site and it simply won't work — by design.
Bound to a verified passport
Every passkey traces to a KYC-verified, immutable web passport — so high-risk actions prove a real, present human.
Built to the standards your auditors expect.
Security FAQ
On your device, protected by your biometric. It never leaves the device and is never transmitted to Paswad.
There's no password database and no private keys to take — only public keys and an activity log. The most valuable target simply doesn't exist.
Recovery is anchored to live verification against your immutable web passport — not an emailed link. High-risk recoveries add an agent check and a post-recovery cool-down.
No. Reading and signing are separate grants, and every payment needs a fresh passkey tap. You can revoke any app anytime.
Security FAQs
How Paswad's architecture keeps accounts and payments safe.
Where are private keys stored, and does Paswad ever see them?
Your private key is generated on your device and protected by your biometric or device PIN. It never leaves the device and is never transmitted to Paswad. We only ever store the matching public key, which is useless to an attacker.
This is the core of the FIDO2 and WebAuthn model. See how passkeys work.
What data does Paswad actually store?
Paswad stores public keys, the verified claims of your web passport, and an activity log of sign-ins and signed transactions. There is no password database and no private keys, so the most valuable target simply does not exist.
We follow data minimisation, and selective disclosure means apps receive only the claims they need. Learn about the verified passport.
What standards and certifications does Paswad meet?
Paswad is built on the open FIDO2 and WebAuthn standards and is FIDO2 certified for phishing-resistant authentication. We support PSD2 strong customer authentication for payments and align with GDPR and CCPA through data minimisation.
Audited controls are covered under SOC 2 Type II, with compliance support available for regulated customers. See SCA in transaction signing.
What happens to my accounts if Paswad is breached?
Because there is no password database and no private keys on our servers, a breach exposes only public keys and an activity log — none of which can be used to sign in or move money on your behalf.
Reading and signing are separate grants, every payment needs a fresh passkey tap, and you can revoke any connected app at any time. Paswad never holds your funds.