FAQ
Questions, Answered.
Cyber One introduces a new way to think about digital trust. Here are the questions we hear most often.
Cyber One is a hardware-based identity and authorization device designed to allow a person to cryptographically authenticate themselves and explicitly authorize sensitive digital actions. Rather than relying exclusively on a password, SMS message, mobile session or software credential, Cyber One introduces a physical hardware component into the trust decision. Its purpose is simple: make important digital actions harder to perform without the authorized human being involved.
Not necessarily. Cyber One uses the familiar card form factor, but its fundamental purpose is digital identity, authentication and authorization. Where appropriately integrated with an issuer or financial institution, payment functionality and Cyber One security capabilities may potentially coexist. These functions should remain logically separated so that an identity or authorization interaction is not confused with a payment transaction.
Modern security often depends upon software proving something about other software. Passwords can be stolen. Sessions can be hijacked. SMS messages can be intercepted or socially engineered. Devices can become compromised. AI agents can increasingly initiate actions without a human manually performing every step. Cyber One introduces an additional question: where is the authorized human? For designated high-value actions, an organization can require cryptographic authorization associated with the person's hardware credential before proceeding.
At a simplified level: request → challenge → card → human action → cryptographic response → verification → approve or deny. A participating application requests authorization. A unique challenge is generated for that action. The Cyber One Card interacts with the user's device. The appropriate cryptographic operation occurs through the card's protected environment. The resulting response is verified. Only then is the requested action allowed to proceed.
Cyber One should be architected specifically to make duplication of protected cryptographic credentials extremely difficult. A visual copy of the card is not equivalent to possessing the cryptographic credential protected by its hardware.
No. No legitimate cybersecurity technology should claim to stop every cyberattack. Cyber One addresses a specific and extremely important part of cybersecurity: proving identity, possession and authorization before sensitive actions are allowed.
No. Cyber One should be architected around privacy and data minimization. Using Cyber One should not mean that Keyra needs visibility into a person's general browsing activity, communications or unrelated digital behavior.
AI systems are becoming capable of doing things rather than merely recommending things. An AI agent may potentially send information, access systems, execute workflows, make purchases, move data, interact with APIs, schedule activity, or initiate transactions. That creates a new security problem: how does a system know when the human actually authorized the agent's action? Cyber One is designed to provide a hardware-backed human authorization layer for designated agent actions.
No. A Cyber One authorization interaction can be logically separate from a payment interaction. Tap to authorize does not automatically mean tap to pay. The requested operation determines what the interaction means.
Yes. Cyber One should be exposed through carefully controlled APIs, SDKs and integration services appropriate to the implementation.
A lost credential must have a secure lifecycle process. The system should support revocation or suspension of the affected credential and enrollment or provisioning of a replacement.
Still looking?
Talk with the Keyra team.
