Examine the foundations.
Explore Fidar’s approach to security, privacy and cryptographic resilience. Discuss the controls and evidence relevant to your deployment.
- ✓Device-bound identityUser · device · app boundVerified
- ✓Interaction signedSignature over the requestVerified
- ✓Domain-bound authenticationGenuine origin confirmedVerified
- ✓Device integrityNo root, jailbreak or malwareVerified
- ✓Algorithm-agile corePQC-ready suite negotiatedVerified
RSA and ECC are mathematically vulnerable to quantum algorithms, and encrypted identity data is already being harvested to decrypt later. Fidar's core is algorithm-agile, so the cryptography can move before the deadline does.
- HarvestCaptured today
Encrypted identity data, credentials and sessions are intercepted and stored. Nothing can read them — yet.
- MigrateFidar moves first
The algorithm-agile core evolves its cryptography toward post-quantum standards, without identity re-platforming.
- Q-dayRSA and ECC fall
Quantum algorithms break the maths classical identity rests on. Everything harvested under it opens.
- AfterStolen stays worthless
Device-bound identities with post-quantum signatures give attackers nothing actionable — then or now.
Non-forgeable identity primitives replace usernames and shared secrets as the root of trust. The core is algorithm-agile by design — able to adopt next-generation cryptographic standards, including post-quantum algorithms, without a platform rebuild.
- Cryptographic architecture
- Algorithm-agile / PQC-ready
- Encryption & key management
- Data minimization by design
- Regulated-industry deployments
- Continuous audit trail
Each control below is structural — it holds because of how identity is built, not because a policy says it should.
Device-bound identity
The user, the device and the app are bound together through biometrics, hardware attestation and certificate identity — a credential cannot be lifted and replayed elsewhere.
Every interaction signed
From login to payment, each consequential interaction is cryptographically signed — not only the session that started it.
Non-repudiable audit trail
Interactions and access events are signed and timestamped, giving regulators an immutable record without manual logging.
Domain-bound authentication
Authentication is bound to the genuine domain and app, so phishing pages and man-in-the-middle relays receive nothing usable.
Nothing reusable to steal
With passwords and OTPs removed, breached data gives attackers nothing actionable — stolen PII opens no account.
Device integrity checks
Rooted, jailbroken and malware-compromised devices are detected, and bot-driven sessions blocked, before authentication begins.
Fidar lists a certification only once it has been formally achieved — this page is updated as each one is.
Aligned by design
Requirements the architecture is built around from the first line of code.
FIDO2 / WebAuthn
AlignedPhishing-resistant, device-bound authentication
PSD2 & SCA
AlignedStrong customer authentication for payments
3DS 2.0
AlignedCard-not-present payment authentication
NIST
AlignedCryptographic guidance, including post-quantum standards