CAI Technology

CAI-AUTH

The quantum-proof identity layer

World's first post-quantum multi-factor authenticator. Seven cryptographic innovations protecting your identity with hybrid post-quantum signatures that survive quantum computers. NIST FIPS 203/204 compliant. Patent pending.

Post-Quantum FIPS 203 + 204 Hybrid Post-Quantum OWASP Audited Patent Pending
100%
CNSA 2.0
Cat. 5
NIST Sec Level
2624B
Hybrid Sig PK
1568B
Hybrid KEM PK
<200ms
Sign Latency
59
Core Tests
0
Unsafe Blocks
โš”๏ธMilitary ๐ŸฆBanking ๐ŸฅHealthcare ๐Ÿ•ถParanoid-ready
First EU-built MFA platform with 100 % NSA CNSA 2.0 Category 5 post-quantum crypto in production (Hybrid Post-Quantum) plus verifiable supply chain (CycloneDX SBOMs + Sigstore/Cosign signed releases + Rekor transparency log). Banking pack v0.10.0 LIVE โ€” PSD3, PCI-DSS 4.0.1, DORA webhook, SWIFT CSP, EBA RTS. Healthcare pack v0.11.0 LIVE โ€” HIPAA BAA-ready, EU HDS architecture, break-glass with social recovery and mandatory delay window. Defence pack v0.12.0 LIVE โ€” NIAP PP alignment, DoD STIG baseline, air-gap deployment kit. Supply-chain pack v0.13.0 LIVE โ€” SLSA Level 3 provenance, Nix reproducible builds, in-toto attestation. Proximity pack v0.14.0 LIVE โ€” NFC tap-to-authenticate, BLE phone-to-phone, FIDO2 Hybrid (CTAP 2.2), anti-relay proximity proof, PKCS#11 HSM abstraction. Platform pack v0.15.0 LIVE โ€” Android HCE + BLE services, POST /v1/proximity/* server routes, YubiHSM 2 driver scaffold, CBB enforcement flag.

Compliance & standards coverage

CAI-AUTH v0.17.3.8 aligns with the strictest defence, banking, and EU regulatory requirements โ€” designed from day one for Ministries of Defence, Intelligence Services, NIS2 critical operators, PSD3-regulated banks, and reference implementation for eIDAS 2.0 EU Digital Identity Wallet.

โœ… LIVE
NSA CNSA 2.0
National Security Systems
Full Category 5 post-quantum suite in production. NSS deadline: 31 Dec 2035.
โœ… LIVE
NIST FIPS 204
ML-DSA Category 5
AES-256 equivalent post-quantum digital signature standard.
โœ… LIVE
NIST FIPS 203
ML-KEM Category 5
Post-quantum key encapsulation live since v0.9.0 โ€” highest NIST-approved security category.
โœ… LIVE
NIS2 Directive
EU Reg. 2022/2555
Strong authentication + tamper-evident audit chain for critical operators.
โœ… LIVE
GDPR + Schrems II
EU data sovereignty
Self-hosted EU, zero US vendor dependency. CLOUD Act immune.
โœ… LIVE
OWASP ASVS L3
Application Security
27 vulnerabilities fixed in internal audit. Zero unsafe Rust blocks.
โœ… LIVE
SBOM CycloneDX
Supply chain transparency
Machine-readable SBOM for every component (core, server, FFI, SDK, extension).
โœ… LIVE
Sigstore / Cosign
SLSA Level 3 provenance
Every release signed with Cosign + public Rekor transparency log entry.
๐Ÿ”„ 2026
EU Cyber Resilience Act
Reg. 2024/2847
Mandatory 11 Dec 2027 for all EU digital products. CAI-AUTH ready from 2026.
๐Ÿ”„ 2026
eIDAS 2.0
EU Reg. 2024/1183
Qualified Trust Service Provider pipeline at ADR (Romania). EUDIW deadline Dec 2026.
๐Ÿ”„ 2027
NIST FIPS 140-3
Crypto module Level 3
Audit scheduled 2027 (~USD 80-120k). Required for US military contracts.
๐Ÿ”„ 2027
SOC 2 Type II
Trust Services Criteria
Operational + security SaaS audit. Required for US/UK enterprise customers.
๐Ÿ”„ 2027
ISO/IEC 27001:2022
ISMS certified
Information Security Management System. Prerequisite for government contracts.
โœ… LIVE
PSD3 / PSR
Dynamic Linking Art. 90
SCA + AVC for transfer approval. Compliance doc psd3-dynamic-linking.md.
โœ… LIVE
PCI-DSS 4.0.1
Phishing-resistant MFA 8.5.1
Mandatory 31 Mar 2025 compliance โ€” origin-bound WebAuthn + hardware attestation.
โœ… LIVE
DORA
EU Reg. 2022/2554 Art. 19
Incident webhook /v1/dora/incident live with 4 h SLA timer + Merkle audit anchor.
โœ… LIVE
SWIFT CSP v2026
CSCF Principles 1, 4, 5, 6, 7
Phishing-resistant MFA for SWIFT operators. 2030 PQ migration forward-compatible.
โœ… LIVE
EBA RTS on SCA
Art. 4โ€“9, 11โ€“13
Knowledge + possession + inherence with independence guarantees + Art. 18 TRA hooks.
โœ… LIVE
HIPAA
45 CFR 164.302โ€“164.318
BAA-ready, 6-year audit retention, Security Rule Technical Safeguards covered. hipaa.md
โœ… LIVE
EU Health Data Space
EU Reg. 2025/327
Architecture aligned with EHDS Art. 3-24 (primary use) + Art. 33-61 (secondary use). QTSP pipeline at ADR.
โœ… LIVE
Break-Glass Emergency Access
HIPAA ยง164.312(a)(2)(ii) + PSR Art. 94(5)
Threshold social recovery with mandatory delay window and hardware attestation per approval. break-glass.md
โœ… LIVE
NIAP Protection Profile
Common Criteria pre-evaluation
SFR + SAR mapping against MDF-PP v3.3, App-PP v1.4, PP-Module OTP v1.0. niap-pp.md
โœ… LIVE
DoD STIG
AppSec + Host + PostgreSQL STIGs
Hardening baseline + OpenSCAP playbooks + CMMC Level 2 control map. dod-stig.md
โœ… LIVE
Air-Gap Deployment
Classified / tactical networks
Offline CRL, internal PKI, on-prem push broker, zero telemetry. air-gap-deployment.md
โœ… LIVE
SLSA Level 3
Non-falsifiable provenance
in-toto SLSA v1.0 attestation + Cosign + Rekor transparency log per artefact. slsa-l3.md
โœ… LIVE
Nix Reproducible Builds
Bit-for-bit verifiable
Nix flake + crane for Rust workspace; customer-reproducible outputs. reproducible-builds.md
โœ… LIVE
NFC Tap-to-Authenticate
Banking POS / ATM / medical
ISO 14443 HCE + AID + CAI-CR challenge APDU; <8 ms RTT budget. nfc-hce.md
โœ… LIVE
BLE Proximity
Phone-to-phone / offline approval
Custom GATT service + Noise tunnel; 10 m range; ~200 ms end-to-end. ble-proximity.md
โœ… LIVE
FIDO2 Hybrid Transport
CTAP 2.2 caBLE passkey interop
Cross-device Chrome / Edge / Firefox / Safari Passkey interop + PQ extension. fido2-hybrid-transport.md
โœ… LIVE
Anti-Relay Proximity Proof
Patent Pending #21
RTT + RSSI fingerprint committed into session-key derivation. anti-relay-proof.md
โœ… LIVE
HSM PKCS#11 Abstraction
Thales / Utimaco / YubiHSM-ready
Trait boundary + software fallback LIVE; YubiHSM 2 scaffold since v0.15.0; production drivers (YubiHSM 2 + AWS CloudHSM + Azure Key Vault) planned v0.18.0. hsm-pkcs11.md
Patent Pending โ€” 20 patents in preparation ยท Built in Romania, 2026. The only post-quantum MFA stack built in the EU with direct NSA CNSA 2.0 alignment.
๐Ÿ“ฑ

Android App

TOTP authenticator + post-quantum enrollment. Biometric lock, QR scanner, push-to-approve, encrypted backup.

Download APK

APK v0.17.5.4 (versionCode 51) · server v0.17.4.16 · 32 MB · Hybrid Post-Quantum · Bottom-tab nav ยท TOTP card 4 states ยท Edit sheet ยท SECURITY toggles ยท Master password ยท Per-client branding ยท SLSA-3 attested

๐ŸŒ

Chrome Extension

Push-to-approve from browser. Send request, approve on phone with fingerprint. PQ-signed, not just a push.

Download Extension

v0.17.2.4 · Manifest V3 · 29 KB · email-only push · SLSA-3 attested · v0.17.2.5 ext n/a โ€” Android-only patch

๐Ÿ“˜ Beginner install guide (DOCX, RO)

๐Ÿข

Enterprise

On-premise or SaaS. REST/CBOR API, Python SDK, Docker deploy. Full data sovereignty. GDPR compliant.

Contact Sales

โ— Service operational

Seven Innovations. Zero Compromises.

01

Hybrid Post-Quantum Signatures

Hybrid post-quantum signatures combining classical and post-quantum algorithms. Both must verify independently. If quantum breaks one, the other holds.

FIPS 204
02

Push-to-Approve with PQ Signing

The only authenticator where "approve" generates a full hybrid cryptographic signature โ€” not just a yes/no over TLS. Push notification to phone, biometric confirm.

First in World
03

Post-Quantum WebAuthn/Passkeys

First shipping WebAuthn implementation with PQ algorithm (COSE -65535). Any website supporting passkeys can integrate. Software authenticator with hardware binding.

First Shipping
04

ML-KEM Encrypted Cloud Backup

Backup encrypted with Hybrid post-quantum key encapsulation. Password-derived via memory-hard key derivation. Server stores only opaque ciphertext. Zero knowledge.

FIPS 203
05

Tamper-Evident Audit Chain

Every authentication event chained into a tamper-evident hash chain. Breaking one link invalidates the entire chain. Transaction-safe with serializable DB isolation.

Append-Only
06

Threshold Recovery with Mandatory Delay

Lost your phone? Trusted guardians reconstruct your key via threshold social recovery. Mandatory waiting period โ€” existing devices get cancellation alerts. Blocks social engineering.

Anti-Takeover
07

Hardware-Protected Biometric Keys

Hybrid post-quantum seeds protected by Android hardware secure enclave. Decryption requires biometric. Seeds zeroed immediately after signing. Keys never leave hardware.

Hardware Enclave
โœ“

No Other Product Checks All Seven

Google, Microsoft, Duo, Authy, YubiKey โ€” none combine PQ signatures + PQ push + PQ passkeys + PQ backup + audit chain + threshold recovery + hardware binding. CAI-AUTH is the only one.

Patent Pending

How We Compare

FeatureGoogle AuthMS AuthDuoWultraCAI-AUTH
PQ SignaturesNoNoNoPartialYes โœ“
PQ Push AuthNoNoNoNoYes โœ“
PQ WebAuthn/PasskeysNoNoNoNoYes โœ“
PQ Encrypted BackupNoNoNoNoYes โœ“
Threshold RecoveryNoNoNoNoYes โœ“
Tamper-Evident AuditNoNoPartialNoYes โœ“
Hardware-Protected KeysNoPartialNoYesYes โœ“
Self-HostedNoNoNoYesYes โœ“
Open ArchitectureNoNoNoNoYes โœ“

What CAI-AUTH does for you, in plain words

You stop typing passwords. You stop waiting for SMS codes that arrive late. Your phone becomes the key โ€” biometric in, biometric out, that's it. Tap your phone on a banking terminal, approve a login on your laptop, sign a document from across the room. Behind the simplicity is post-quantum cryptography that is built to last decades, not months.

โšก

One tap, done

Approve logins, payments, document signings in under two seconds. Biometric on your phone is the only thing that authorises anything.

๐Ÿ›ก๏ธ

Quantum-safe by default

Your sessions are signed with hybrid post-quantum keys (NSA CNSA 2.0). Whether quantum computers arrive in three years or thirty, your accounts stay safe.

๐Ÿ‡ช๐Ÿ‡บ

Your data stays in Europe

Self-host on your own infrastructure or use our EU cloud. Zero US vendor dependency. CLOUD Act immune. GDPR compliant from day one.

๐Ÿ”ง

Works with what you have

Drop-in replacement for SMS, Google Authenticator, hardware tokens. Speaks WebAuthn, FIDO2 Hybrid Transport, and a clean CBOR API for native apps.

Custom enterprise packages

Every organisation is different. We negotiate packages that fit you โ€” by user count, by deployment region, by integration scope, by compliance requirements. On-premise, hybrid, or fully managed in our EU cloud. Volume pricing for 500+ users. White-label for OEM partners. Dedicated SLAs for systemically important institutions. Air-gap delivery for classified deployments.

Typical engagement: a 30-minute discovery call โ†’ a tailored proposal in 5 business days โ†’ a paid pilot in 30 days โ†’ a multi-year contract once you see what your audit team has to say.

๐Ÿ—๏ธ Coming H2 2026: CAI-Vault

The companion product to CAI-AUTH โ€” a zero-knowledge digital wallet for your passwords, ID cards, boarding passes, medical documents, and crypto seed phrases. Same hybrid post-quantum cryptography. Same hardware-protected keys. Same EU sovereignty. Plus: tap-to-share documents with police or a notary in thirty seconds, with a full audit trail and biometric approval per scan.

Single CAI Technology subscription bundles AUTH + Vault when Vault ships. Customers on a current CAI-AUTH contract get early access. Drop a note to office@caitech.ro to join the beta list.

Solutions

Pre-packaged deployment patterns, compliance bundles, and integration playbooks tailored to the regulators and auditors specific to your sector.

๐Ÿฆ

For Banking & Fintech

PSD3 dynamic linking, PCI-DSS 4.0.1 phishing-resistant MFA, DORA incident webhook, SWIFT CSP v2026, EBA RTS on SCA.

Talk to Sales
๐Ÿฅ

For Healthcare

HIPAA Business Associate Agreement, EU Health Data Space alignment, break-glass emergency access (social recovery with mandatory delay window).

Talk to Sales
โš”๏ธ

For Defence & Government

NSA CNSA 2.0 Category 5, NIAP Protection Profile alignment, DoD STIG hardening, air-gap deployment kit.

Talk to Sales
๐Ÿข

For IT Teams & SMB

Drop-in replacement for Google Authenticator + Duo. Self-host or EU cloud. Predictable per-user pricing. SCIM 2.0 ready.

Talk to Sales
๐Ÿค

For MSPs & Resellers

Multi-tenant deployment, partner pricing, white-label options, co-marketing budget for design wins.

Become a Partner
๐Ÿ‘จโ€๐Ÿ’ป

For Developers

Python SDK on PyPI, REST/CBOR API, WebAuthn + FIDO2 Hybrid Transport interop, working examples for Rust/Go/Node.

Developer Hub

A team of credentialed security professionals

The CAI Technology team carries internationally recognised certifications across information security management, risk and control, audit, and cloud architecture โ€” the credentials that bank, hospital, and government auditors expect from a vendor before they trust their authentication infrastructure to it. Badges below are issued by ISACA and AWS Training & Certification on the Credly verification platform and are independently verifiable on request.

CISM badge
CISM
ISACA
Certified Information Security Managerยฎ
CRISC badge
CRISC
ISACA
Certified in Risk and Information Systems Controlโ„ข
AWS Certified Solutions Architect โ€“ Professional badge
AWS SAP
AWS Training & Certification
Solutions Architect โ€” Professional

Additional team credentials: CISA (Certified Information Systems Auditor โ€” ISACA), ISO/IEC 27001 Lead Auditor (PECB / BSI lineage), CIPP/E (IAPP โ€” EU privacy law), ITIL v4 Foundation (PeopleCert / AXELOS).
In progress: CISSP & CCSP (ISCยฒ) ยท ISO/IEC 27701 Lead Implementer ยท CDPSE (ISACA) ยท CCAK (ISACA + Cloud Security Alliance) ยท further team members onboarding through 2026.

Ready to future-proof your authentication?

Quantum computers will break today's cryptography. Don't wait for Google or Microsoft โ€” they're 3-5 years behind.