Most users understand that MFA is a good thing, but they won't tolerate intervention every time they log in. That's Spriv's sweet spot. We pair a known workstation with the environmental identifier from the user's phone, then authenticate both in the background some transactions clear in as little as 175 milliseconds.
Second factor verified out-of-band.
The user did nothing but sign in.
Spriv compiles multiple two factor authentication solutions into one product, and includes Adaptive Risk Based MFA the fastest MFA there is. If the user allows a transaction from a specific computer and the phone reports a particular environmental identifier, every future transaction is automated as long as that pair holds. Some transactions authenticate in as little as 175 milliseconds well below one second, with no user intervention.
On first sign-in from a workstation, the user confirms the request on their phone. That single approval is all the setup there is.
Two things are stored together: the identity of that specific computer, and the environmental identifier the phone reports from that location.
When both match, the second factor completes in the background. When either one doesn't, the user gets challenged exactly as you'd want.
Adaptive MFA is Spriv's default. When you need an extra layer, add SMS, Two-way SMS, TOTP or Allow / Deny at the same cost and user experience competitors charge for basic MFA. Try each method.
Background verification with no user interaction. Once the workstation-phone pair is trusted, later logins clear silently often under 175 ms.
A numeric code sent to the registered handset. Familiar to every user, no app required.
The user replies to confirm, closing the loop on a second, separate communication channel.
Standard time-based one-time passwords for teams already carrying an authenticator app.
A push prompt for high-risk events. Best used as an exception, not a daily habit.
Users enter username and password. Spriv authenticates the computer and mobile phone automatically in the background no touching the phone.
Get three-factor authentication for the same cost and user intervention as other companies offer for two.
Hardware tokens are so 90s. With Spriv's automatic MFA your users complete the second factor before they can get a token out of their pocket.
Is another MFA telling you when the user has left the desk? What if a foreign IP connection begins from their computer while they're half a mile away? Wouldn't you want to know?
IT teams get install files and a management console. Developers get an API with code samples in five languages. Neither has to change how the rest of the stack works.
Credential provider for Remote Desktop, with adaptive authentication at the login screen.
Drop-in PAM module covering SSH and sudo across your server estate.
REST API with sample code in five languages for web and customer-facing logins.
Deploy through your existing AWS account and consolidate the billing.
Spriv's multi factor authentication is FFIEC, PCI, HIPAA and SOX compliant and does not transfer any personally identifiable information. FFIEC, PCI, HIPAA and SOX set authentication as the floor Spriv does out-of-band authentication across two separate communication methods instead of one, and substantially improves the baseline requirement. PCI DSS requires organizations to "incorporate two-factor authentication for remote access to the network by employees, administrators, and third parties." Spriv makes that requirement effortless.
The verification channel is physically separate from the login channel two separate communication methods, not one.
Nothing personally identifiable is transferred between your systems and Spriv.
The adaptive pairing method is covered by several granted patents.
Know when a session no longer matches the environment it started in.
All plans include up to two free users and two free servers. No credit card required to sign up, and the install process takes less than five minutes.