Identity Security
Data Security
Issuance
 
Identity Verification

Automate identity verification with drag-and-drop workflows.

Launch Demo

Identity Security for Banking

Drive customer acquisition, prevent fraud, and meet compliance requirements.

Launch Demo

Entrust IDV and Microsoft Entra Verified ID

Secure the remote employee onboarding experience and ensure your workforce remains protected against sophisticated AI-driven threats during high-risk moments.

Signhost

Sign your documents from anywhere with one compliant e-signature platform.

eIDAS AES for Customer Onboarding

Onboard customers faster by combining identity verification and e-signatures in one platform.

Launch Demo

Citizen Identity Orchestration

Onboard, issue verifiable credentials, and orchestrate a seamless experience for citizens accessing digital government services.

Launch Demo

Self-Service Password Reset with Entrust IDV

Secure Microsoft Entra ID password resets for employees with Entrust Identity Verification.

Launch Demo

Biometric Authentication with Entrust Identity Verification

Secure the customer identity lifecycle and prevent account takeovers with phishing-resistant passkeys.

Launch Demo

Entrust Biometric Passkey combines phishing-resistant passkeys with verified identity to protect against account takeover attacks across enrollment, authentication, and account recovery journeys.

Enrollment begins with a standard username and password sign-in. The customer is then prompted to enroll a phishing-resistant passkey for future passwordless authentication. Before the passkey is created, identity verification is performed by scanning a government-issued ID document. A biometric check using liveness detection confirms the customer is a real person and guards against presentation attacks and deepfakes. The passkey is then bound to the verified identity and stored on the customer's device. The binding links the passkey to a verified individual rather than just the device.

For everyday authentication, returning customers tap to initiate sign-in using the stored passkey. Face ID or device biometrics authenticate the customer, with no password, SMS code, or OTP required. The process completes in seconds.

When a transaction exceeds a defined risk threshold, a step-up authentication request is triggered. The customer completes a biometric verification, and a live biometric is compared in real time against the identity enrolled at registration. If the match is confirmed, the transaction is authorized. This step-up flow reuses the trusted identity from enrollment without requiring passwords, one-time codes, or knowledge-based questions.

For account recovery on a new or replacement device, the original device-bound passkey is no longer available. The customer identifies their account and completes a biometric verification to confirm they are the same individual who originally enrolled. Once identity is confirmed, a new passkey is created and bound to the account, restoring passwordless access without help desk intervention or password resets.

The identity established at enrollment is reused across everyday login, high-risk transaction approval, and account recovery.

Streamline KYC Compliance in Australia with Entrust

Navigate Australia’s new KYC/AML regulations, prevent fraud, and onboard customers quickly and securely.

Launch Demo

ETSI-Compliant IDV with QES for France

Deploy identity verification with qualified electronic signatures in France with a single workflow

Launch Demo

Entrust Workflow Studio supports orchestration of identity verification, fraud checks, and qualified electronic signatures in a single workflow. The platform offers no-code, drag-and-drop editing and built-in workflow templates, including compliance packages.

The ETSI Compliant IDV with QES for France workflow is a pre-built template compliant with Article R561-5-2 of the French Code monétaire et financier and ETSI 119 461. The workflow is viewable and configurable in a single interface.

Workflows contain three task types: Capture Tasks define what end users see and what actions they must take, such as capturing ID documents, faces, or biometric motions; Processing tasks run automated checks in the background; Decision Logic determines how the workflow proceeds based on results.

Certain tasks are locked and cannot be deleted, ensuring mandatory compliance steps remain in place. Customer-facing capture steps include identity document capture, face capture, and document signature.

In the qualified electronic signature capture step, the user reviews and signs a document, establishing a trusted link between the verified identity and the electronic signature. The document signed is typically a standard document such as terms and conditions.

Automated processing reports include a Document Report that analyzes the captured identity document video to detect fraud, prevent injection attacks, and verify document authenticity. A Face and Liveness Validation report detects deepfakes, injection attacks, and spoofing attempts. An optional Known Faces Report flags repeat face usage across onboarding attempts. A Device Intelligence Report checks that the same device was used to capture both the document and the face, to prevent injection attacks.

Automated decisioning routes compliant applicants to QES and directs exceptions for manual review.

QES provides the highest level of signature assurance under eIDAS, combining document authentication and identity verification. Document authentication creates legal evidence and reduces signing risk. Identity verification supports AML and KYC requirements for digital onboarding.

Okta Password Recovery with Entrust IDV

Secure the password recovery process in Okta Workforce Identity with Entrust Identity Verification.

Launch Demo

Entrust Identity Verification integrated with Okta Workforce Identity adds biometric identity verification to the self-service password reset process. Instead of relying on security questions, email codes, or SMS codes, the system requires a live biometric check to complete account recovery, preventing account takeovers even when a password, inbox, or device is compromised.

Setup is a one-time admin configuration in Okta. In the Okta Account Management Policy screen, the admin adds a rule requiring Entrust Identity Verification for password recovery and points the password authenticator's self-service reset to that policy. No custom code is required. The rule-based configuration means verification is triggered only at defined high-risk moments, such as account recovery.

When an employee initiates a forgotten password reset by selecting "Forgot password?" on the Okta sign-in page and entering their corporate username, Okta evaluates the account management policy to determine recovery requirements. Rather than proceeding with a standard verification method, Okta securely redirects the employee to an Entrust verification session on their device.

The employee completes a liveness check using facial biometrics. The biometric technology is iBeta PAD Level 1 and Level 2 conformant, designed to detect presentation attacks and AI-generated threats such as deepfakes.

If verification succeeds, Entrust returns a confirmed result to Okta, which authorizes the account recovery and allows the employee to set a new password. If verification fails due to a detected deepfake, presentation attack, or biometric mismatch, Entrust returns a failed result, Okta denies the recovery action, and the password is not reset.

Okta Employee Onboarding with Entrust IDV

Secure employee onboarding in Okta Workforce Identity with Entrust Identity Verification.

Launch Demo

Okta Workforce Identity integrated with Entrust Identity Verification to add identity assurance during employee onboarding. The integration uses a standards-based OIDC connection with no custom code required. It is designed to counter deepfakes, synthetic identities, AI-driven social engineering, and account takeovers by verifying the real person behind credentials, not just the credentials themselves.

In the Okta Admin Console, an IT admin adds Entrust as an identity verification vendor, connecting Okta to Entrust's document and biometric verification services. The admin then configures an authentication policy rule that requires identity verification at onboarding, allowing verification to be triggered at specific high-risk moments rather than universally. A drag-and-drop Workflow Studio is used to build the onboarding flow by adding tasks including document scan and facial biometrics.

From the employee side, a new hire receives an activation email and is prompted to verify their identity with Entrust before completing account setup. The employee selects the issuing country and type of government-issued ID (such as a passport or driver's license), then captures photos of the front and back of the document. The system automatically checks document authenticity and data consistency. The employee then completes a selfie with a liveness check. Entrust's iBeta PAD Level 1 and Level 2 conformant biometrics match the selfie to the ID photo and protect against presentation attacks and deepfakes.

After Entrust validates both the document and biometric results, the outcome is returned to Okta. Once identity is confirmed, the employee continues account setup. The verified result is tied to the employee's Okta identity for future high-assurance actions such as account recovery. Upon completion, the employee accesses their Okta dashboard with verified identity established from the first login.

Cryptographic Security Platform

Streamline enterprise-wide cryptographic management with one unified security platform.

Launch Demo

Entrust Cryptographic Security Platform Key Manager

Manage encryption keys across hybrid environments—secure, automated, and compliant.

Start Trial

CloudControl

Secure your cloud infrastructure—centralized access, compliance, and visibility in one solution.

Start Trial

PKI as a Service

Deploy secure, scalable PKI built for modern enterprise needs in minutes.

Launch Demo

Cryptographic Security Platform: Public Key Infrastructure (PKI)

Manage your PKI and all your cryptographic assets with one unified security platform.

Launch Demo

Digital Card Solution

Issue secure, spend-ready digital cards instantly from your banking app.

Launch Demo

Credential Builder

Explore secure credential issuance for corporate, government, or student IDs.

Launch Demo

Web Push Provisioning with Digital Card Solution

Enable cardholders to add cards to their digital wallets from any web browser.

Launch Demo

Instant Financial Issuance Software

Instantly issue ready-to-use credit and debit cards to your customers.

Launch Demo

Sigma DS3 with 600 dpi

See the benefits of 600 dpi printing for ID cards and employee badges.

Launch Demo

Dynamic EMV Solution

Explore our EMV data preparation and personalization platform for central card issuance.

Launch Demo

Instant ID as a Service

Issue secure IDs instantly from the cloud with one secure platform.

Start Trial

At Entrust, we're laying the secure foundation that protects identities, payments, and data and advances your organization in an ever-changing world.