Historically, standard encryption like HTTPS could be bypassed through SSL stripping downgrade attacks. Today, even two-factor authentication can be intercepted by a Web Relay MitM or by leveraging a compromised Certificate Authority. Every HTTPS site is one compromised CA and a DNS attack away from completely broken.

Long-term Certificate Pinning
Your phone and the resource (e.g., a web server, computer, or door) are paired by exchanging public keys
Every subsequent connection can be mutually authenticated with these shared keys
These keys can be used to establish a secure, authenticated connection — even in the face of a MitM attack

End-to-end Encryption
Allthenticate technology generates a secure session from the phones Trusted Execution Environment to the resource and does not depend on any secure communication protocols. You can confidently communicate over unencrypted networks without any risk of your authentication being compromised.

Fully Decentralized
Since Allthenticate’s technology is built on a fully-decentralized architecture it is not dependent on the security of centralized, third-party services like DNS and Certificate Authorities. If the two parties are not compromised, you will be secure.

Your Secrets Are Safe
Your private keys are stored in your phone’s Secure Element - a dedicated security chip designed to resist both software and physical attacks - and they never leave. Even if an attacker compromises your phone’s software or intercepts all of your traffic, they cannot extract these keys.
A hardened cryptographic chip in your phone to securely store private keys that is resistant against physical attacks
Hardware-backed isolation to enable trusted interactions with the phone and protect against software attacks






