
There is no password
to steal
Every login generates a fresh one-time key of 300+ characters and destroys it the moment authentication ends.
With no secret in storage, the attack surface for theft and credential stuffing is simply not there.
On top of BSA — an authentication engine that stores no password — sit desktop sign-in and unified credential management. They run on the infrastructure you already have.
See how the login worksA structure that establishes trust with no password, no central server and no master key — a pipeline that leaves nothing behind, from material to ledger.
See how the login worksFor the core systems of finance, government and enterprise — meeting regulatory duty and user experience at the same time.
Talk to usA method recognised by international bodies. Third-party verification, not a company's claim.
See every standard
Every login generates a fresh one-time key of 300+ characters and destroys it the moment authentication ends.
With no secret in storage, the attack surface for theft and credential stuffing is simply not there.

Multiple randomly selected nodes verify at the same time, and the result is recorded across the Public and Private Chains.
Nothing rests on a single point, so there is no centre for an attacker to seize.

The ITU, the United Nations agency for telecommunications, adopted the BSA technology as an international standard.
Patents in 8 countries and a presence in 57 carry that competitiveness into world markets.
Every extra layer of security is one more step for the user.
And most authentication still comes down to guarding a single stored secret.
One login means an SMS, an app approval, a security card. More layers, but the same point still gives way.
Sixteen characters of upper case, lower case, digits and symbols. Nobody remembers it, so it ends up written down somewhere.
A change-every-90-days policy satisfies the rulebook. It does not remove what has already leaked.
Certificates, OTPs, security tokens — devices to carry and certificates that expire. The cost of managing all of it lands on the organisation.
SIG ONE does not block attacks one at a time. It structurally removes the two premises every attack depends on — the fixed credential and the single verification point.
If no password is used, what actually proves who the user is? It is the question we hear most.
Here is that average 2.4-second authentication, laid out in 8 steps.
Played back slower than real time so it can be followed.

Just your ID is enough.
There is no password field
With no stored secret, there is nothing to ask forA login screen running SIGONE has no password field. There is no stored password to ask for in the first place.
The Public Chain receives the authentication request and hands it to the Private Chain. No password and no fixed secret travels through this step.
A new combination is composed for every request out of separate authentication factors — registered handset, device, location, knowledge and biometrics. Even the same user never repeats a fixed combination.
No storageNo fixed combinationFrom the newly composed factors a one-time key of 300+ characters is generated. The key exists only for that one request and is discarded when authentication ends.
This is where the user's part ends. The data itself is never transmitted off the device; only the verification result needed for authentication moves on to the next step.
Biometric never leaves the deviceThe nodes that take part are selected at random for every request. The selected nodes verify the authentication data in parallel and confirm the result under the consensus rules. Verification authority never concentrates in one single node.
No single verification pointThe result is written to a distributed ledger, so any forgery or tampering can be verified afterwards. It gives you the basis to trace and audit the authentication history.
Distributed recordAuditable afterwardsOnce the access grant reaches the service, authentication is complete. The OTAK that was used is discarded at once, and the next authentication generates a new combination and a new key. An authentication key that has been used cannot be used again.
Used key discarded at onceCannot be reusedWe resolve the structural limits of existing authentication.
Authentication is safer and faster with no password, no central server and no master key.

Passwords are not hidden or replaced —
no fixed password is stored at all.
Each authentication uses a new value.
Verification authority is never concentrated in one place.
Several randomly selected nodes verify in parallel,
lowering reliance on any single point of verification.
The user authenticates only once.
The process finishes in 2.4 seconds on average,
raising security and convenience together.
Adopted as an ITU-T international standard,
Common Criteria EAL2,
and an OIC-CERT Global Award —
a record of international recognition.
Material → key → verification → record. Each stage uses only what it needs and leaves behind no reusable credential.
It is a one-way structure: no secret from one stage is handed to the next.

For each request a subset is selected and combined from distinct factor sets — possession, device, location, knowledge and biometrics.
Even for the same user the combination differs request to request, so nothing depends on a fixed credential.
No fixed credential is kept
A one-time key of more than 300 characters is generated and used for that request alone.
Once authentication completes it is destroyed at once and is never reused by a later request.
Destroyed right after authentication
Verification authority is not concentrated in one place; several nodes are drawn at random for every request.
The selected nodes verify in parallel and settle the result by the consensus rule.
No single point of verification
The public chain and private chain share the work and record the process and its outcome.
The distributed record keeps the authentication history traceable and checkable after the fact.
Traceable history · checkable afterwards
You cannot see for yourself how trustworthy a security technology is.
SIGONE proves its technology through international standards and third-party verification, not its own claims.
The International Telecommunication Union (ITU) is the UN agency for information and communication technology. The core of BSA was adopted as an ITU-T international standard and is formally part of the global standards framework.
It was established as a national standard by the Telecommunications Technology Association (TTA), so alongside the international standards it is formally part of Korea's ICT standards framework.
The technology was recognised at the 2021 Global Cybersecurity Award run by OIC-CERT, the international cybersecurity cooperation body.
Common Criteria is the international information-security evaluation scheme based on ISO/IEC 15408. SIGONE achieved an EAL2 evaluation under it.
Patents on the core technology are registered in eight countries including Korea, the United States, the United Kingdom, China and Japan, securing a global basis for rights protection.
Full records of the standards, certifications,
awards and patents — with the source documents.

Bring SIGONE to the core systems of a bank, a public body or an enterprise. Keep the infrastructure you already run and extend authentication through the API and SDKs.
From sign-in to payment authentication and transfer approval, with no password anywhere.
Citizen authentication and access to public services, safely and without a password.
Every request for VPN or internal system access is verified, tightening enterprise access control.
Electronic signatures, and the access history of sensitive documents, kept in a form you can verify.
Trusting one login for the rest of the day is useless against an account that has already been taken.
SIGONE verifies again at every access point — user, device, behaviour, data, cloud —
and settles the outcome by consensus among distributed nodes.
Why authentication without a password matters — the essentials, in short films.
A cloud subscription to start quickly, and a self-hosted build for air-gapped or large-scale environments.
Two ways to adopt it, whichever fits how you operate.
Per user · monthly subscription
Passwordless authentication delivered as SaaS, live quickly. Nothing to build and no infrastructure to stand up.
Site licence · unlimited apps
A self-hosted build for air-gapped networks, regulated industries and large organisations, shaped around your security policy and the way you operate.
Every plan is quoted individually after we understand your environment.
Contact Us
Contact us and our specialists will design an authentication architecture tailored to your environment.