Products
The Entersekt Approach
Entersekt provides a single authentication platform for all channels. Cross-channel authentication is an integral component of Context Aware™ Authentication, Entersekt's proprietary solution that uses risk-based authentication data, a customer’s cross-channel interactions, and personalized authentication preference to minimize friction, prevent fraud and deliver the best customer experience. Context Aware™ Authentication processes hundreds of real time data points about a customer’s device, behaviors, and the customer’s prior transactions, together with contextual understanding of what the user is trying to achieve to determine within split seconds whether the risk level warrants frictionless, decline or challenge. When an active challenge is indicated, Context Aware™ authentication taps into preferences expressed in other channels or on-file to send the customer-preferred challenge, ensuring a consistent experience with your organization regardless of the channel through which they are interacting. Our authentication solution helps financial institutions to easily build and introduce low friction experiences for their customers across all digital channels, closing gaps left vulnerable to fraud when customer engagement channels are authenticated in silos.
We use state-of-the-art app and web security and digital certificates to authenticate users on mobile app/s or web browsers. The Entersekt Authentication Solution establishes a trusted channel to end users on their mobile device or trusted browser, which enables the enterprise to offer all its transactional services on the mobile or web channel without fear. At the same time, the system also transforms the device or browser into a strong multi-factor authentication token for protecting transactions across various other channels.
Benefits
- Context Aware™ Authentication unifying the bank’s customer experience across channels
- Supports both app-less and passwordless implementations
- Device ID and digital transaction signing
- Compliance and certifications support
- Industry-leading service and support
- Risk-based authentication detects fraud and reduces unnecessary friction
- Authentication personalized to customer preferences
- Authentication experts with 120 patents
- Simplifies integration with a single API that unlocks all Entersekt’s authentication options for use in any channel
Our technology enables you to leverage multiple authentication factors, to be certain of the identity of the source and the integrity of the device and messages sent through a secure channel. Entersekt’s push-based, phone-as-a-token customer authentication solution is arguably the best solution in the market. It is proven to counter phishing attacks, man-in-the-middle or man-in-the-browser attacks, keylogging and call forwarding attempts, and number porting or SIM-swap attacks. Integrated into your customer’s mobile app or used to secure their browsers, our multi-patented technology combines strong device or Browser ID with biometrics, contextual, or knowledge-based factors, allowing you to identify every accountholder uniquely. The digital certificates underpinning our solution also guarantee the confidentiality and integrity of communications between you and your customer.
Entersekt Authentication Methods
Entersekt’s product suite spans core areas of Authentication, Identity and Payments and can be deployed across various hosting options. Across all these areas, authentication is at the core, and we continuously invest in R&D to ensure we remain at the cutting edge of technology to give financial institutions security that is one step ahead of fraudsters and the user experience that delivers value for their customers.
By connecting to the ESP with a single API, our customers are connecting to a future-proof authentication platform that will empower them to seize the advantage of new solutions and technologies, as well as advances in risk-data that allow them to stay ahead of fraud innovation with little or no incremental development effort.
Mobile Authentication
Entersekt’s Mobile Authentication solution helps safeguard your customers’ transactions in a compliant and user-friendly way, using true out-of-band, multi-factor authentication (MFA) in a mobile app. The solution helps financial institutions achieve numerous benefits including:
- Identify and trust a customer’s mobile device thanks to unique digital certificates deployed from our secure platform and SDK
- Get real-time information about a device, including its age, integrity, and current location, factors that can be signals of anomalous, potentially fraudulent behavior
- Send real-time authentication to a customer’s device and receive a digitally signed response in return as proof of authentication
- Offer smart, step-up authentication mechanisms allowing minimal-to-no friction when risk data signals indicate low risk
- Enable customers to digitally sign responses with just one touch
Browser Authentication with FIDO Passkeys
Browser authentication helps financial institutions to futureproof their browser channel and enable more secure, versatile user experiences. The solution helps avoid device drift and minimize collision. It also enables institutions to identify and protect their customers while delivering enhanced user experiences. FIDO passkeys, leveraging the available biometric capabilities such as face and fingerprint scans, can be used to enable biometric authentication on all major browsers with the following feature highlights:
- Supports both app-less and passwordless implementations
- Eliminates the risks of phishing, password theft and replay attacks
- Supports roaming hardware authenticators and on-device authenticators like fingerprint scanners
- Facilitates passkeys, the new standard in authentication driven across Google, Apple and Microsoft
- Digital transaction signing that supports non-repudiation
- Paves the way for seamless multi-factor authentication on your browser channel
Identity Verification
Entersekt Identity Verification is used to register endpoints and perform high risk authentication – a solution to scan and validate customer’s faces or identity documents. This solution offers further protection by utilizing robust AI liveness and verification technologies when adding new endpoints or conducting sensitive transactions. Real-time digital customer identification eliminates the need for physical presence and reduces human error complications; as a result, financial institutions save on operational costs while mitigating ever-evolving fraud risks. Benefits include:
- Additional layer of security, much safer than passwords
- Liveness detection as an additional layer of defense against stolen IDs
- Highly secure step-up alternative, when used in conjunction with Entersekt’s authentication suite
- Recover customer account without customer visiting branch
- Single vendor and single integration for all identity and authentication needs
- Great user guidance to streamline the face scan process
- Touchless guided capture experience for selfies on all capable devices
Silent authentication
Turning mobile apps and browsers into possession factors, with advanced technology that addresses privacy concerns. Friction can be reduced or even removed entirely in use cases like banking login, high-risk transactions, multi-factor authentication situations like PSD2’s SCA and even 3-D Secure authentication. Say hello to the frictionless future - The only solution of its kind, that enables frictionless and fraud free transactions, cryptographically signed with 100% proof and 100% certainty. A user registers and validates their Browser once, and then all subsequent transactions are frictionless. When combined with behavioral biometric signals, both possession and inherence factors can be proved passively.
Benefits include:
- App and Browser ID use a cryptographic identifier that recognizes the same browser or app with 100% certainty
- A cryptogram is generated without any user interaction, delivering frictionless transaction signing
- Fast, frictionless, cannot be intercepted, authenticating logins and transactions, silently and securely
- Unlike legacy methods, this is a long-lived credential, and doesn’t require periodic refresh and
- revalidation like most others
- Compliant with PSD2, offering frictionless SCA, and unlike cookies used within fingerprinting,
- Browser ID does not track users across domains, protecting personal information
3-D Secure Solutions
3DS ACS
Entersekt SaaS ACS provides a 3-D Secure (3DS) solution that maximizes flexibility, minimizes cost, and empowers FIs with the tools to combat fraud without compromising the cardholders’ experience. In the digital payment landscape where the best user experience is a market differentiator, we believe in delivering a technology platform that empowers our partners with the ability to own and curate a market leading 3DS experience for their cardholders.
3DS Directory Server
The Directory Server (DS) is at the center of the 3-D Secure (3DS) authentication process, the EMVCo security protocol designed to add an extra layer of authentication for card-not-present (CNP) transactions. It is the critical component in the “interoperability domain” responsible for routing 3DS messages between the 3DS Servers and the Access Control Servers, connecting merchants, issuers, and card schemes.
The Directory Server is a centralized hub that receives authentication requests from merchants, validates whether the Access Control Server (ACS) of the card issuer is enrolled in the 3DS program, and directs the request to the appropriate issuer associated with the payment card that was inputted by the purchasing customer. It is certified to support the EMVCo 3DS protocol and can be customized to include custom rules of the card scheme. The card schemes establish the 3DS program for their ecosystem, while the issuers of that card scheme must certify their ACS to the card scheme, and merchants who want to accept that card must certify their 3DS Servers to the card scheme.
3DS Server
The Entersekt SaaS 3DSS performs the core function of routing 3-D Secure protocol requests and responses. The implementation ensures that all requests from 3-D Secure versions 2.x are handled according to the established EMVCo and payment scheme specifications and implementation guidelines.
The Entersekt 3DS Server is fully certified to support mobile app flow transactions originating from a 3DS SDK. Additionally, we also offer an EMVCo certified 3DS SDK that is tightly integrated with our 3DS Server for enhanced user journeys and optimized user experiences, as detailed in the section below. The Entersekt mobile SDK is also compatible with 3DS Servers from other providers.