Security & Trust
Built for enterprise and government from the protocol up. The most secure credential is the one that doesn't exist.
Read the detailed Security FAQ — entropy, brute-force resistance, hashing, and device loss →
Never stored in recoverable form
Your word is never stored in any recoverable form — not even by us. Sign-in compares a one-way hash; there is no encrypted copy, no plaintext, and no key that could bring a word back. If WordKey were breached tomorrow, there would be no words to steal.
Argon2id hashing
Your device sends only a SHA-256 pre-hash, and our servers harden it with Argon2id — the OWASP-recommended, memory-hard function — under a server-side pepper. Even against a stolen database, guessing a word is deliberately slow and expensive.
Server-enforced device binding
A word alone is not enough. Every sign-in is checked against your enrolled device server-side. A correct word from an unrecognized device does not authenticate — it is routed to phone approval instead.
Single-use signed tokens
Every sign-in mints a short-lived signed token bound to a single business and spendable exactly once. A replayed or intercepted token is rejected.
No password database
No user-chosen passwords exist to leak, stuff, or reuse. There is no shared-secret vault — the thing attackers usually exfiltrate simply isn't there.
SIM-swap resistant
WordKey never sends SMS codes, so there's no phone number to hijack. Sign-ins from a new device are approved on your own enrolled device — your carrier is never in the loop.
Word rotation & recovery
We never recover old words — we rotate. Because nothing stores a word in recoverable form, the only path forward is a new one. Rotating a word requires your enrolled device, biometric confirmation on that device, and your current word. The new word propagates to every connected site instantly, and the old word stops working the moment you rotate.
No phone-number dependency
Nothing in WordKey binds to a phone number. There are no SMS codes to intercept and no number to SIM-swap. Recovery and new-device sign-in both run through your enrolled device — the thing you hold, not a carrier record an attacker can socially engineer.
Protocol roadmap
On our v2 protocol roadmap — planned, not yet shipped.
- →Hardware-backed device binding — device keys held in the secure enclave, never leaving the device
- →WebAuthn / FIDO2 layering for regulated deployments
- →Multi-device enrollment with per-device revocation
- →Independent third-party protocol audit
Compliance roadmap
Certifications planned as WordKey scales into regulated markets.
