# The identity no one can steal.

> Passwordless authentication, privileged access and fraud detection that use the place as proof of identity. For banking, the public sector and industry.

URL: https://www.ironchip.com/en/


Passwordless authentication and fraud detection that verify person, device and place. A valid credential used outside its safe zone is blocked.

Request a pilot See how it works

They protect their access with Ironchip

- Banco Santander
- Basque Government
- Ibercaja
- Abanca
- Arquia Banca
- ULMA

## One access, four checks.

The same engine evaluates an employee, a vendor, a machine or a banking customer. The scenario changes, the logic does not.

## The attack almost never happens where the user is.

A legitimate identity repeats in a handful of trusted places. Fraud comes from outside, and it also repeats. That physical context is a signal that password, OTP and passkey do not have.

**92%** of attacks occur remotely, from a location where the user has never been.

**99%** of fraudsters commit fraud from the same location at least twice.

## How a place becomes proof of identity.

It is not GPS and there are no coordinates or personal data. It is an anonymous and unique signature of the place, linked to the device key.

### 1. Environmental signals
The device measures 2G to 5G cell towers, visible WiFi networks, latency, IP and the SIM actually in use. Nothing leaves the device yet.
### 2. Location signature
Our technology turns those signals into an anonymous signature of the place. No coordinates, no personal data, impossible to reproduce from anywhere else.
### 3. Link with the device
The signature is bound to the device's private key, which never leaves it. The result is a factor that cannot be copied or spoofed.
### 4. Safe zone and decision
The zone is declared by policy or learned from behavior. If the signature matches, access is granted. If not, it is blocked, an alert is sent and it is logged as evidence.

### Device

Private key that never leaves the device.

### Person

Device's own biometrics, no template on server.

### Place

Location signature of the authorized safe zone.

### One single gesture

Access resistant to phishing, malware and SIM swapping. No password to remember or code to type.

## Location feeds fraud prevention. Fraud prevention decides each access.

Three layers on the same core. The same intelligence that detects a money mule decides whether an employee, a vendor, a machine or an AI agent can enter.

risk score decides access location signature feeds the risk

### A location signature that cannot be copied.

The radio environment becomes an anonymous signature linked to the device key. Safe zones are declared by policy or learned from behavior.

- **safe zones** declared (offices, plants, remote work) or learned from everyday use.
- **Spoofing detection:** VPN, TOR, residential proxy, virtual SIM and impossible travel.
- **No coordinates or personal data:** the signature cannot be reversed to an address.

### Every access and every operation, scored in real time.

Location, device, network and behavior combine with each client's own rules. The result is a live risk score, not a yes or no in the first second.

- **Adaptive rules engine** with policies by scenario and by entity.
- **Device integrity:** root, malware, RAT, overlays and injection.
- **Behavior** and patterns consistent with known campaigns.
- **Case, forensic analysis** and evidence export.

### The score decides who enters, how, and with what privilege.

Low risk: direct access. Medium: one more factor or manager approval. High: block and alert. Same for a person, device, service or AI agent.

- **Approvals and least privilege** by profile, resource and time.
- **Identities of people, devices and machines,** also between machines.
- **Bots and AI agents** detected by call rate, origin and pattern.
- **Web and desktop applications,** plus RDP, SSH, VPN and APIs.

**People**: Employees, customers, vendors and third parties.

**Devices**: Mobile, desktop, USB, NFC card and passkeys.

**Machines and services**: Machine identities, APIs and traffic between services.

**Bots and AI agents**: Legitimate automations pass. Those outside pattern, do not.

**Infrastructure**: RDP, SSH, VPN and RADIUS, not just web applications.

**Applications**: Open standards: OIDC, SAML, and SCIM.

## Here's how it looks. Console for the admin, one gesture for the user.

Ironchip console managing a privileged access: request, approval, held connection, recorded session. And on mobile, all the user sees.

Ironchip console

_Ironchip app screen asking to confirm an access._

**Console:** privileged access, approvals, live sessions and recordings. **App:** a notification, mobile biometrics and location verified in the background.

## Identity and access platform.

One gesture to enter and no password to steal. If the right credential arrives from the wrong place, it doesn't open. All about the IdP, directory and applications you already use.

safe zones

### Location as access policy

Define the zone on the map, choose the verification level and apply it to the applications and groups you decide.

- Multiple zones per policy: head offices, plants or declared remote work homes.
- Strict mode: requires GPS and electromagnetic signals for maximum assurance.
- Applicable to critical resources and remote access via RDP or SSH.
- From IP whitelists to contextual analysis of multiple locations.

Single console

### Identities, devices and policies in one place

What credential each person has and on which device. Rules by application, group and zone, with log of every change and every access attempt.

- **Directory and inventory**: Users, groups, mobile, desktop, USB, RFID and passkeys SCIM
- **Policies and audit**: By application, group and safe zone, with history Zero Trust
- **Real-time dashboard**: Access, devices and events, exportable to SIEM Syslog and API

- Active Directory, Entra ID, Google Cloud Identity and LDAP as identity source.
- Authentication flows with corporate branding, also in OS login.

Zero Trust

### Conditional access

By device, location, identity, role and risk. Complex rules by profile without deployment.

Passkeys and FIDO2

### Phishing resistant

Synced passkeys or physical keys. With location, a stolen passkey is useless outside the zone.

Log in

### MFA at Windows logon

Second factor and safe zone also when logging in to the device, with RADIUS for VPN and network.

Machines and third parties

### Non-human identities

Services, traffic between machines and vendors with single-use link, with the same context.

### One method for each workstation. Also without mobile.

Including scenarios where no phone is available or software cannot be installed.

### Mobile app

Corporate mobile or BYOD. Approval with one gesture. Push + biometrics + location

### Desktop app

Workstations without mobile available. Device key + OTP + location

### Passkeys and FIDO2

Standard web access and security keys. WebAuthn + device biometrics

### Facial recognition

Mobile and desktop access without touching anything. Face + device + location

### USB token

Environments without mobile or biometrics. Split key device + token

### NFC / RFID card

Plant, shifts and shared workstations. Physical card + reader

### Magic link and SMS

Vendors and external third parties. Single-use link or code

### Agentless

Devices where software cannot be installed. Network context + existing credential

## Your brand on every screen.

The app, IdP login and notifications carry your logo and colors. Each company configures its look and feel from the console, also in OS login. Ironchip disappears. Your brand stays.

_Identity provider login page with client branding._

_Mobile app with client branding._

## Privileged access that asks at connection time.

A transparent broker for SSH, RDP, VNC, Kubernetes, HTTPS, MySQL and PostgreSQL. No client, no VPN and no one sees a password. Device, safe zone, ITDR and approval checked every time someone connects, not just when they were granted access.

- **Approval gate on the connection**: The broker holds the session while Ironchip evaluates device, safe zone and ITDR and asks approvers for yes. Policies with one or multiple approvers and windows that auto-expire. Not one ticket slips by.
- **Recorded and live sessions**: SSH terminal and RDP and VNC desktops from the console or with the native client. Full recording, live viewing and single-use tickets for those who prefer their own terminal.
- **Machine command control**: The agent decides what each person can execute with sudo and applies AppLocker on Windows. A command outside policy is held until approvers say yes, and what ran and who launched it is logged.
- **Secrets outside the database**: System credentials live in a secrets store (OpenBao or any Vault-compatible API). The broker reads them by reference and does not store a copy.
- **Managed passwords and rotation**: Ironchip manages the system password and rotates it daily and after each session: local accounts LAPS-style, databases and domain accounts in Active Directory, LDAP or Entra ID. Checkout and break glass with log of who took it.
- **Ephemeral credentials for applications and machines**: Short-lived credentials in AWS, Google Cloud, Azure and databases, and a Vault-compatible API for applications to read their secrets. Account inventory on each machine.

## Fraud also has a location. We see it.

Money mule, SIM swapping, authorized push payment fraud and location spoofing in banking and fintech. Integrates via mobile or web SDK and HTTP API, frictionless for the end customer.

**82%** of users log in to an application from usual places.

**74%** of purchases are made from usual places.

**66%** of logins are made from usual places.

**+90%** of high-value transactions occur from usual places.

Real case · Money mule

### Five minutes from Spain to Benin.

Four signals that separately look like noise and together describe a fraud attempt.

1. **Sudden use of VPN.**: First connection via NordVPN, a clear deviation from usual behavior.
2. **SIM operator change.**: The SIM goes from a Spanish operator to MTN Benin while maintaining the declared location in Spain.
3. **Impossible travel.**: A location jump logistically impossible in that interval without technological manipulation.
4. **ISP change.**: The provider changes to NordVPN at the same moment the Benin SIM appears.

Operation held and case opened with all the evidence.

Custom rules engine, session antimalware, antiphishing, SDK and API. [See the fraud detection platform](https://www.ironchip.com/en/fraud-platform)

ITDR · Identity threat detection and response

### Access is not decided once: the entire session is monitored.

Each access carries a live risk score. Changing context, a degrading device or a credential starting to behave like someone else's triggers the response.

**Detect**

- Location outside usual zones
- New device, with root or unpatched
- VPN, TOR or residential proxy
- Impossible travel and simultaneous sessions
- Resources that role doesn't usually touch

**Decide**

- Low risk: direct access
- Medium risk: one more factor or strict mode
- High risk: denied and session cut
- Least privilege by profile, resource and time

**Respond**

- Immediate block and alert to administrator
- Normalized event to SIEM via syslog or API
- Forensics tab with device and context
- Export of evidence for audit or legal use

Integrations and directories

### Single source of truth for local and cloud identities.

Each role change or removal propagates instantly. On-premise, cloud or hybrid deployment, with agentless access option.

OIDC SAML LDAP RADIUS SCIM HTTPS SDK

- **Active Directory on-premise**: ADConnect
- **Entra ID / Azure AD**: SCIM
- **Google Cloud Identity**: SCIM / OIDC
- **Local users and third parties**: CSV import
- **More than 5,000 applications, RDP and SSH**: OIDC, SAML, RADIUS, SDK

[Technical documentation](https://docs.ironchip.com)

## What traditional MFA cannot verify.

Each method resists some threats and yields to others. Only one knows from where the credential is used.

| Threat or scenario | Password + OTP by SMS or app | Push MFA approve on phone | Passkey / FIDO2 WebAuthn | Ironchip person + device + place |
|---|---|---|---|---|
| Real-time phishing (man in the middle) | Vulnerable | Vulnerable | Resistant | Resistant |
| SIM swapping | Vulnerable | Resistant | Resistant | Resistant |
| Notification fatigue (push bombing) | Not applicable | Vulnerable | Resistant | Resistant |
| Malware or RAT during session | Vulnerable | Vulnerable | Vulnerable | Resistant |
| Valid credential used from another place | Vulnerable | Vulnerable | Partial | Resistant |
| Workstations without phone or biometrics | Not covered | Not covered | Partial | Covered |
| Evidence of physical place for audit | Not covered | Not covered | Not covered | Covered |

## Calculate your exposed surface.

Four pieces of data you already know. An estimate of what an attacker can use today from anywhere and what changes with location as a factor.

## Certified for the most demanding environments.

LINCE certification from the National Cryptological Center and inclusion at HIGH level in the CCN CPSTIC catalog, with published secure use procedure (CCN-STIC 1633). Certified for ENS High category, ISO 27001 and ISO 27701. Aligned with PSD2, DORA, and NIS2.

- Qualified STIC product, HIGH level, CCN CPSTIC · HIGH level
- LINCE certification from the National Cryptological Center LINCE · CCN
- ENS High category certification ENS · High category
- ISO 27001 certified ISO 27001
- ISO 27701 certified ISO 27701

**2017** Foundation, Spanish capital. The Spanish Government participates as an investor.

**HIGH** Level in the CPSTIC catalog of CCN-CERT.

**4** Critical sectors deployed: banking, public sector, industry, and energy.

**0** Stored credentials. No passwords to exfiltrate.

Backed by

- Google for Startups
- ENISA
- INCIBE, National Institute for Cybersecurity
- Entrepreneur XXI, CaixaBank

## Three deployments, three different restrictions.

Banking with sophisticated fraud, public sector under ENS, and industry without phones on the floor. Same core, three answers.

[Banking Abanca Location enters mobile banking fraud detection. Read the case](https://www.ironchip.com/en/customers/abanca) [Public sector Alcobendas City Council Second factor for an entire municipal workforce, with the level ENS requires. Read the case](https://www.ironchip.com/en/customers/alcobendas) [Industry GHI Smart Furnaces An industrial plant with no phones, protected with a USB token. Read the case](https://www.ironchip.com/en/customers/ghi)

## The platform right now.

Aggregated and anonymized data from Ironchip's fraud detection engine in production. No specific operation, no identifiable customer.

**2,293,000** operations evaluated today, each with its location, its device and its behavior.

**2,293,000** in the last 24 hours

**69.7 M** in the last 30 days

**157,036** peak per hour, at 09:00 UTC

Figures estimated from the daily volumes of Ironchip's fraud and authentication engines; the hourly breakdown is real. Updated on October 4, 2026, 00:06 UTC.

## Start with a pilot.

A group of users and a critical application. Without replacing your current systems and with measurable results from the first week. We contact you within one business day.

[Technical documentation](https://docs.ironchip.com) sales@ironchip.com
