Platform
One proof of identity.
Set by your standards.
CypherID verifies people, not credentials, and it does the same job at a login screen and at a door. Underneath it, the ThinOps Cypher platform ties identity to keys that can't be duplicated, and OneTiCK stands by for the moments that call for extra proof. Licensed software, built to run inside your own products and brand.
Get a CypherID demo How it works
01
Applications
Sign in with proof instead of passwords. No codes in sight.
02
AI & agents
Every agent action verified against the human who authorized it.
03
Transactions
Payments, transfers, and approvals, verified both ways, every time.
The product family
One product carries the claim.
CypherID is what you buy and what your customers see. The Cypher platform and OneTiCK work underneath it, so employees, customers, contractors, and AI agents all prove themselves the same way, and you evaluate once.
CypherID
Proof of identity.
Proves a person, or an AI agent, is who they say they are, online and in person, without a password. Runs inside your own infrastructure, so identity data never leaves your walls, and white labels into the products you already ship.
ThinOps Cypher
The platform underneath.
The foundation CypherID runs on. PKI Entanglement ties a person's identity to cryptographic keys that can't be duplicated or intercepted, and both sides prove themselves on every transaction, in under a second. Math, not trust.
OneTiCK
Extra proof, on demand.
The patented One-Time Cognitive Keyboard confirms the person behind the keystroke when a workflow calls for it. An embedded capability of the platform, not a separate purchase.
Control
Verification you configure, factor by factor.
You define the steps, the factors, and the pass/fail confidence threshold, by transaction value and by user. A standard selfie for a routine login; a document-in-hand liveness check for a high-value transfer; native device biometrics where they exist. CypherID supplies the tool. The policy is yours.
Document capture & OCR
Integrates with your existing camera and OCR providers, including a fully local option.
Selfie & passive liveness
No install and no app. Runs off the device's native camera and a QR code.
Native biometrics & device signals
Face and touch where the device supports it, plus location and device entanglement.
OneTiCK step-up
The cognitive keyboard reinforces the highest-risk actions, when your policy calls for it.
Human and non-human identity
People, service accounts, and AI agents, one proof model, one policy engine.
Verification policy High-value transfer
Document + OCRREQUIRED
Selfie + livenessREQUIRED
Device entanglementREQUIRED
GPS / locationOPTIONAL
Pass threshold≥ 0.90
Match 0.97 · verified, transfer released
Self-hosted
Runs on your own infrastructure. No document, biometric, or extracted text leaves your network.
AES-256-GCM
Personal data is encrypted at rest, everywhere it is held.
PII purge
Automated on the schedule you set, so you choose your own compliance scope.
Audit logging
Full, exportable record of who proved what, and when.
01 · Applications
Sign-in that doesn't ask anything of anyone.
CypherID entangles each user with your app once. From then on, every session is proven cryptographically in the background. No passwords, no codes, no prompts to fatigue. The credential your back office keeps in Active Directory or Entra stays exactly where it is. It just can't be shared anymore.
Drop-in SDKs for web, iOS, and Android. Most teams ship in under two weeks.
Continuous session verification, not just at the front door.
Zero stored credentials: nothing to breach, nothing to reset.
OneTiCK cognitive keyboard for high-risk actions: a patented challenge that phishing kits, keyloggers, and shoulder-surfers can't read.
Welcome back Verified
DM
Dana M.
entangled · device + org + user
Control how this user signs in and verifies, on your own terms.
Agent authorization chain live
H
Human authorizes
Dana M. · "reconcile Q2 invoices"
A
Agent acts
finance-agent · scoped to invoices, 24h
Every action verified
org + system + agent + authorizing human
02 · AI & agents
Agents move fast. Verification moves with them.
The agents are not the risk. The credentials the agents carry are the risk, and enterprises are handing AI agents the same broken system of shared secrets that people struggle with. CypherID entangles each agent to its operator, so every action carries a verifiable chain of authorization: human to agent to system.
Scope it, expire it, or revoke it, per agent and per task. When an agent is compromised or goes off-script, its entanglement dies. The rest of your fleet doesn't notice.
Stopping agent abuse →
03 · Transactions
The money moves only when both sides prove it should.
Wires, card payments, transfers, approvals: each one triggers a bidirectional handshake. The service proves itself to the user; the user proves themselves to the service. Fraud needs both to fail. Both never do.
<1s
median verification
99.97%
fraud blocked
0
phishable secrets involved
Approve transfer Both sides verified
$4,820.00
Wire → Acme Supply Co · 0x9f3a·c21e
Approve Decline
How it works
PKI Entanglement, in four moves.
Verification runs both ways: the user proves themselves to the service, and the service proves itself to the user. *essentially: unbreakable bonds.
01
User initiates
A purchase, a transfer, a records request: anything worth protecting.
02
Cypher reaches out
PKI Entanglement confirms the service is who it's entangled to.
03
The service reaches back
Both parties validate org, system, user, and device, all behind the scenes.
04
Verified in <1s
No codes. No phishable secrets. Users don't even notice. (For real.)
Rollout
Adopt by use case. Expand on the numbers.
Start where a single shared credential does the most financial damage, then expand outward on your own infrastructure, at your own pace. Licensing leads; services follow where you want the help.
01
Land on the costliest credential
Start with the one shared credential that does the most financial damage: a high-value transaction, a privileged admin account, a fraud-heavy workflow. One use case, tied to a number the CFO already owns.
02
Deploy inside your walls
Self-hosted, sovereign SaaS on your chosen infrastructure. The server is stateless and holds no credentials or PII. Identity data never leaves your environment.
03
Embed in minutes
Out-of-the-box connectors for SAML 2.0, OpenID Connect, RADIUS, and reverse proxy, plus white-labeling inside your own app and brand. CypherID integrates into your systems, not the other way around.
04
Set the rules
You configure the verification steps, the factors, and the pass/fail confidence threshold, by transaction value and by user. Four challenge levels — notification, push, biometric, OneTiCK — match friction to risk: high-risk actions get reinforced, everyday logins stay invisible.
05
Prove the number
Every verification leaves a defensible, audit-ready record of who verified what, and when. The credential liability you retired and the fraud losses that went with it start to fall, and disputes and compliance reviews go from days to minutes.
06
Expand across every identity
Roll the same proof to the next workflow and every identity — employees, customers, contractors, and non-human AI agents. Each expansion carries its own board-ready business case, on the number the CFO already owns.
See the platform on your own stack.
Sandbox keys and a solution architect, within a day. CypherID integrates into your systems, not the other way around.