Security Stack Logo
Mobile-First Authentication logo

Identity & Access Management

Mobile-First Authentication

Passwordless mobile-first MFA for banks with NIST post-quantum cryptography and device binding.

Passwordless AuthenticationPost-Quantum Cryptography (PQC)

Mobile-First Authentication Overview

What it does

Mobile-First Authentication is a passwordless multi-factor authentication (MFA) product for banks and fintech companies, built on Wultra's PowerAuth protocol. It replaces passwords and one-time codes with device-bound cryptographic keys unlocked by biometrics or PIN, turning the customer's phone into a phishing-resistant authenticator for logins and transaction signing. Its distinctive mechanism is postquantum authentication: hybrid cryptographic suites pair elliptic curve P-384 with the NIST-standardized ML-DSA signature algorithm, keeping authentication secure against future quantum attacks.

How it works

Banks integrate the product through a mobile SDK embedded in their own app, a whitelabel mobile app, or a whitelabel web application, backed by a PowerAuth server deployed on-premises or consumed as a managed cloud service. During activation the mobile SDK generates device signing key pairs (ECDSA and optionally ML-DSA) and establishes a shared secret using ECDHE or ML-KEM key encapsulation. Users then approve logins, payments, and 3-D Secure transactions by signing them on the device under Face ID or PIN, with proximity checks and resistance to OTP interception, SIM swap, and overlay attacks. The Raiffeisenbank deployment serves 1.5M+ users handling 20M+ daily transactions.

Credentials and traction

Wultra is ISO 27001 certified, with the certificate published for download on its compliance page, and is the sole Sample Vendor named for postquantum authentication in the 2025 Gartner Hype Cycle for Digital Identity. Its PowerAuth technology is embedded in YRIS, the French digital ID whose SDK was reviewed by the French cybersecurity agency ANSSI and certified for CSPN, and in the Czech MojeID authenticator certified at eIDAS substantial assurance level. Customers include Raiffeisenbank, OTP Bank, NLB Group, Moneta, and Saldo Bank, among 70+ clients in 25+ countries.

Key Capabilities

mapped to solution categories
Passwordless Authentication

Binds passkeys to specific device hardware (TPM, Secure Enclave), the private key cannot be exported or used from a different device.

Implements FIDO2/WebAuthn for phishing-resistant authentication, binding credentials cryptographically to the registered origin to prevent use on phishing domains.

Post-Quantum Cryptography (PQC)

Implements CRYSTALS-Kyber (ML-KEM, FIPS 203), for key encapsulation and CRYSTALS-Dilithium (ML-DSA, FIPS 204), for digital signatures, the NIST-standardized post-quantum algorithms.

Supports hybrid key exchange combining classical (ECDH), and post-quantum (ML-KEM) algorithms, maintaining compatibility with non-PQC endpoints during the migration period.

Lets an organization swap cryptographic algorithms without re-architecting applications, so quantum-vulnerable algorithms can be replaced as standards evolve.

Compliance

certifications
ISO 27001

Implementation & support

Deployment model
On-PremisesSaaSSDK
Pricing structure
Per Seat
Support channels
Community ForumDocumentationTicketing Portal

Info last updated on July 30, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.