Polyguard AuthPoint

MFA that proves a person, not a device.

AuthPoint binds phishing-resistant multi-factor authentication to a verified, present person, not just a device or a code. The identity proven at hiring is the identity that logs in.

Where this fits in the employee lifecycle

  1. Apply PreScreen
  2. Interview ScreenTest
  3. You are here Secure AuthPoint
  4. Support TicketWatch

The person who logs in isn’t always the person you hired.

Fake candidates who make it through hiring do not stop at the offer letter. A stand-in takes the laptop, a proxy shares the credentials, or a stolen session is replayed from another country. Conventional MFA confirms a device or a code, and both can be handed to someone else.

Shared and proxied credentials

A verified hire hands the account to a worker who was never verified. The device is genuine, the code is correct, and the person is wrong.

Laptop farms and remote access

Corporate hardware runs from an address the employee never visits, driven over remote desktop. The device passes every check while the operator sits elsewhere.

Relayed one-time codes

Phishing kits relay one-time codes in real time. A code proves that someone typed it, not who that someone is.

How it works

Three steps, inside the identity provider you already run.

  1. 1

    Access is requested

    A login, step-up, or privileged action in your identity provider triggers a Polyguard Trust Check.

  2. 2

    The person proves presence

    On Polyguard Mobile, real-time facial recognition and PG-Presence confirm the enrolled employee is physically at the device, not relaying through a remote connection.

  3. 3

    Access is granted to the person

    The signed result reaches your identity provider and the session proceeds. Nothing to adjudicate, nothing to review later.

The right level of proof at each moment

Verification is proportionate to what the action requires. A quick presence check for routine sign-ins; full identity proof where the stakes are highest.

Login

Presence on first sign-in of the day, or on every sign-in for high-risk roles.

Step-up

Full identity proof before access to source code, production systems, or financial data.

Privileged actions

A verified, present administrator behind every change to access, payroll, or vendor records.

The same identity, from application to access

AuthPoint reuses the identity established by PreScreen and ScreenTest. There is no new enrollment and no new workflow: the same Polyguard Mobile app and the same proofs, applied at the moment of access.

Privacy first

Biometrics are processed on the employee’s device and never leave it. Your identity provider receives a signed result, not raw data.

Privacy First →

Close the gap between hired and logged in.

Talk to us about AuthPoint for your identity provider.