Identity services for state, county, city and K–12 agencies

The attacker doesn't need a zero‑day. They need one employee's password.

We move public agencies off passwords, SMS codes and push prompts onto FIDO2 passkeys, and we build the authentication system that has to stand up to your auditor afterwards. Two services, one outcome: a login an attacker cannot phish.

Nothing to sign to start. No cost, no procurement, and you are talking to the person who would run the work rather than a salesperson. If we are not the right fit for your agency, we will say so on that first call and point you somewhere better.

Find your agency on this ladder

Three rungs of authentication. Only one of them survives a convincing email.

  • Passwords and SMS codesRelayed to the attacker in real time. Phishable by design.
  • Push-approval MFABetter, still phishable. Fatigue an employee at 11pm and you are in.
  • FIDO2 passkeys and security keysCryptographically bound to the real domain. A lookalike site gets nothing.

Ladder as described in CISA's Implementing Phishing-Resistant MFA fact sheet. The free posture call tells you which rung each of your logins is on.

What we do

Two services. We move you, then we keep you defensible.

They are designed to be bought in that order, but either one stands on its own and neither requires the other.

Service 01

Phishing-resistant migration

We take an agency that runs on passwords and shared MFA and land it on FIDO2 passkeys, department by department, without breaking the way people actually work.

  • Inventory of every way a person can authenticate into your environment
  • Enrollment plans for staff without smartphones, shared workstations and field devices
  • Help-desk runbook for the calls you will actually get in week one
  • A written cutover plan per legacy login you are retiring
How the migration works →
Service 02

Compliant auth systems

We design, build and operate the authentication system itself, on a dedicated service and database that belongs to your agency alone, with the evidence trail your auditor, insurer and grant administrator will ask for.

  • A dedicated authentication service and database for your agency alone
  • Controls mapped to NIST SP 800‑63B authenticator assurance levels, documented
  • Authentication and admin event history your auditors can read and export
  • Annual posture report for audit response, insurance renewal and grant reporting
What compliant means here →
Underneath both services: Seamless Auth, open source and free.The platform stays free to run yourself, with no user cap and no expiry. Your security team can read the whole authentication path before you ever talk to us. That does not change.
Read the source →
Why this keeps stalling

Nobody disagrees with the goal. The migration is what gets deferred.

If you are reading this, you already know passwords are the exposure. Three things stop the fix, and all three are a scoping problem rather than a technology problem.

"We already have MFA"

Texted codes and push prompts count as MFA on the audit checklist and fail against an attacker-in-the-middle kit. The checkbox is satisfied. The agency is not protected.

Everyone shares one identity pool

The common model puts your agency in a multi-tenant directory and separates you from every other customer with a tenant boundary. It works until it doesn't, and when it doesn't your agency is one row in someone else's incident report.

No appetite for "rip and replace"

A full identity replacement does not fit a single budget cycle, so we do not sell one. Each stage is scoped and delivered on its own, and leaves the agency better off if the next stage waits a year.

Start without committing to anything

Four ways in. None of them cost you a dollar or a signature.

You should be able to find out whether we are worth your time without opening a procurement file. Take any of these and owe us nothing.

A 30-minute posture call

You describe how staff log in today. We tell you which rung of the ladder each login sits on and what we would do first. Straight answers, no deck.

Book the call →

The self-assessment checklist

The same questions we ask in an assessment, written so your team can answer them without us. Download it and run it yourself. No email gate.

A technical review with your team

Put your security staff in a room with ours, source open on the screen, no NDA. If we cannot answer something we will say so in the room.

Set one up →

Just run the software

Seamless Auth is open source and free to self-host, permanently. Stand it up in a lab and decide for yourself before any conversation about services.

Get started →
How the engagement runs

Four stages, each one scoped and approved on its own.

Fixed scope and a written deliverable at the end of each stage. Stop after any of them and keep everything produced up to that point. The first stage is small on purpose, so the decision to continue is made on evidence rather than a pitch.

On pricing

We quote per agency, because a 40-person town and a 4,000-person county are not the same job. Ask on the first call and you will get a number and the scope behind it in writing, before anything goes to procurement.

Stage 01Free call first

Posture assessment

The free call tells you roughly where you stand. This stage is the version in writing: we inventory every authentication path in your environment, rank each against the CISA ladder, and hand you a posture report with a prioritized migration order you can attach to a budget request.

Typical duration 2 to 4 weeks

Stage 02

Pilot on one department

A dedicated auth instance stood up for your agency, passkeys enrolled for one real department, and the help-desk runbook written for your staff. Small enough to prove, large enough to be evidence for the rest of the rollout.

Typical duration 4 to 8 weeks

Stage 03

Agency-wide rollout

The pilot pattern repeated across the agency, one department at a time, on a schedule your help desk can absorb. Each department gets its own cutover date and its own rollback plan, so a bad week for one team never stalls the rollout.

Typical duration one fiscal year

Stage 04

Operate and evidence

We keep the system patched, on call when something breaks, and re-run the posture assessment every year so the evidence in front of your auditor is current rather than a snapshot from the year you migrated.

Renews annually

Compliance status, in public

Certification is underway. Until it lands, here is exactly where we stand.

Public buyers get told half-truths about certification constantly. We would rather you shortlist us knowing the whole picture, or rule us out early and keep your evaluation time.

In place today, verifiable by you

Nothing here requires you to take our word for it.

  • Built on FIDO2 / WebAuthn. The open standard behind passkeys and hardware security keys, not a proprietary scheme.
  • A dedicated instance per agency. Nothing your agency depends on is reachable from another customer's environment, because there isn't one in it.
  • Source is public. Your security team, or an assessor you hire, can read exactly how authentication works before you buy anything.
  • Mapped to NIST SP 800‑63B. Which authenticator types we support at each assurance level, published so your assessor can check our work.

Under way, reported as it actually moves

In progress

We have opened a formal certification program. This page gets updated as each item moves, not once a year. We do not publish a target date for a step we do not control.

  • FIDO Functional Certification. The FIDO program that applies to a server, and the credential we are closest to earning. Conformance self-validation is under way.
  • GovRAMP. Our primary target for public-sector work. We are a member today. A Single Security Snapshot is the next step, and we are not on the Authorized Product List.
  • SOC 2 Type II. Not on our roadmap this year. Buyable if a contract or insurer makes it a condition of award.
  • CJIS Security Policy. Tell us on the first call if your workload touches criminal justice data and we will say plainly whether we can serve it.
  • Accessibility / VPAT. Login screens are the surface that matters, and every employee has to use them. No VPAT yet, and the built site has not been independently tested, so we claim no conformance level anywhere.
  • FedRAMP and CMMC. Not in scope. We are not selling into those markets today and will not imply otherwise.
See the full status page →
The first conversation is free

Find out how phishable your agency is before someone else does.

Thirty minutes with the person who would run your migration, not a salesperson. You leave knowing which logins are exposed, what we would do first, and what it would cost. No obligation to do any of it with us.