KeyHive is built on WebAuthn, the same standard trusted by Apple, Google, and Microsoft to eliminate the largest category of account compromise: the password.
Public-key cryptography stored in secure hardware. Credentials never leave the device, and there is no shared secret to phish or leak.
We never accept, store, or transmit a password. There is no password database — and therefore nothing to breach.
Origin-bound credentials mean a lookalike domain simply cannot receive a valid assertion. Users are protected by design.
Every sign-in, enrollment, and admin action is recorded with device, location, and outcome metadata for compliance review.
All customer data is encrypted at rest with AES-256 and in transit with TLS 1.3. Keys are rotated on a fixed cadence.
Designed against SOC 2, ISO 27001, and GDPR controls from day one. Sub-processor list and DPAs available on request.