We move public agencies off passwords, SMS codes and push prompts onto FIDO2 passkeys, and we build the authentication system that has to stand up to your auditor afterwards. Two services, one outcome: a login an attacker cannot phish.
Nothing to sign to start. No cost, no procurement, and you are talking to the person who would run the work rather than a salesperson. If we are not the right fit for your agency, we will say so on that first call and point you somewhere better.
Find your agency on this ladder
Ladder as described in CISA's Implementing Phishing-Resistant MFA fact sheet. The free posture call tells you which rung each of your logins is on.
They are designed to be bought in that order, but either one stands on its own and neither requires the other.
We take an agency that runs on passwords and shared MFA and land it on FIDO2 passkeys, department by department, without breaking the way people actually work.
We design, build and operate the authentication system itself, on a dedicated service and database that belongs to your agency alone, with the evidence trail your auditor, insurer and grant administrator will ask for.
If you are reading this, you already know passwords are the exposure. Three things stop the fix, and all three are a scoping problem rather than a technology problem.
Texted codes and push prompts count as MFA on the audit checklist and fail against an attacker-in-the-middle kit. The checkbox is satisfied. The agency is not protected.
The common model puts your agency in a multi-tenant directory and separates you from every other customer with a tenant boundary. It works until it doesn't, and when it doesn't your agency is one row in someone else's incident report.
A full identity replacement does not fit a single budget cycle, so we do not sell one. Each stage is scoped and delivered on its own, and leaves the agency better off if the next stage waits a year.
You should be able to find out whether we are worth your time without opening a procurement file. Take any of these and owe us nothing.
You describe how staff log in today. We tell you which rung of the ladder each login sits on and what we would do first. Straight answers, no deck.
Book the call →The same questions we ask in an assessment, written so your team can answer them without us. Download it and run it yourself. No email gate.
Put your security staff in a room with ours, source open on the screen, no NDA. If we cannot answer something we will say so in the room.
Set one up →Seamless Auth is open source and free to self-host, permanently. Stand it up in a lab and decide for yourself before any conversation about services.
Get started →Fixed scope and a written deliverable at the end of each stage. Stop after any of them and keep everything produced up to that point. The first stage is small on purpose, so the decision to continue is made on evidence rather than a pitch.
On pricing
We quote per agency, because a 40-person town and a 4,000-person county are not the same job. Ask on the first call and you will get a number and the scope behind it in writing, before anything goes to procurement.
The free call tells you roughly where you stand. This stage is the version in writing: we inventory every authentication path in your environment, rank each against the CISA ladder, and hand you a posture report with a prioritized migration order you can attach to a budget request.
Typical duration 2 to 4 weeks
A dedicated auth instance stood up for your agency, passkeys enrolled for one real department, and the help-desk runbook written for your staff. Small enough to prove, large enough to be evidence for the rest of the rollout.
Typical duration 4 to 8 weeks
The pilot pattern repeated across the agency, one department at a time, on a schedule your help desk can absorb. Each department gets its own cutover date and its own rollback plan, so a bad week for one team never stalls the rollout.
Typical duration one fiscal year
We keep the system patched, on call when something breaks, and re-run the posture assessment every year so the evidence in front of your auditor is current rather than a snapshot from the year you migrated.
Renews annually
Public buyers get told half-truths about certification constantly. We would rather you shortlist us knowing the whole picture, or rule us out early and keep your evaluation time.
Nothing here requires you to take our word for it.
We have opened a formal certification program. This page gets updated as each item moves, not once a year. We do not publish a target date for a step we do not control.
Thirty minutes with the person who would run your migration, not a salesperson. You leave knowing which logins are exposed, what we would do first, and what it would cost. No obligation to do any of it with us.