Step-up authentication, bound to the action
Some actions need a real person.
Yuthent confirms it’s the person, on their own phone — with a fingerprint or face, before the action runs. Not just at login.
Biometric never leaves the device · Designed for evidentiary use under eIDAS






The problem
Nobody broke in. Everyone was logged in.
A person, an automated agent, an attacker: once past the login, every action looks the same. The system can’t tell who is really behind any one of them.
In 2024, 74% of the value of fraudulent EU credit transfers came from manipulating the payer — not from breaking in. (EBA/ECB, Dec 2025)
How it works
One person confirms, on the phone already in their hand.
The action pauses
Your own systems decide which actions need a person. Everything else runs untouched.
They confirm on their phone
The action is shown on their enrolled phone. A fingerprint or face confirms it’s them, before it runs.
A signed record stays
What was approved is kept as a signed record, verifiable against the exact action: by your backend now, and against Yuthent’s published keys later.
When it matters, the screen asks what the action is.
No code to read out: a choice, then a fingerprint or face.
It stops a secret being handed over; a person fully talked into the action still approves it.
Where it fits
Where do you need to know it’s really them?
The same layer sits in front of the action wherever the consequence is.
Financial & payments
The payee and amount approved are the ones that move the money — not a click a scammer talked someone into.
ExploreHealthcare
Which clinician actually authorized this record, prescription, or dispensing — not whoever’s login was open.
ExploreWorkforce & shifts
Who’s actually on shift or at the terminal — the person, not whoever tapped the badge.
ExplorePrivileged access
Who ran the deploy, opened the console, or granted the role — carried by the action, not the session.
ExploreInsurance & claims
A signed record of who approved, so a disputed action can be settled on evidence, not on the log.
ExploreAlongside automated agents
When people and agents act in the same system, each human decision keeps its own signed record, so who did what stays separable.
ExploreA precise trust statement
What the approval says, and what it does not.
Yuthent is execution-authority infrastructure. It is not identity proofing, not fraud detection and not monitoring, and saying so plainly is what makes the rest credible.
- An enrolled person approved, on their enrolled device
- A local biometric check happened, and the biometric never left the phone
- The decision is tied to the exact action and verifiable by your backend
- The approval happened before the action ran
- Legal identity: proofing stays with you or your identity provider
- Human intent: a person can approve after being misled
- Fraud detection: your risk engine decides what is suspicious
- Continuous monitoring: it sits on the action, not the session
Why it matters
The record stops being a guess.
Every system writes down that something happened. None of them proves a person decided it. Yuthent turns that line in the log into evidence: who confirmed, on which enrolled device, before it ran.
- Accountability
A signed decision from an enrolled person, not an inference from a shared credential.
- People and agents, told apart
When people and automated agents act in the same system, telling who did what is a guess today, and what an agent did is often not cleanly separable. Yuthent keeps each decision attributable: a human approval carries that person’s signed confirmation, and an action taken under a standing mandate is recorded as one, not as a person’s decision.
- Evidence
Designed for evidentiary use under eIDAS and equivalent frameworks.
Straight answers
The questions a buyer asks first.
- Do you verify identity?
- No. It confirms a person approved this action. Who that person is in the world is your system’s business, not ours.
- Do you prevent fraud?
- No. It makes an approval a person signed, bound to the action. A person fully talked into an action still approves it.
- Where does the biometric go?
- Nowhere. It stays on the device, in Android’s StrongBox or TEE, or in the iOS Secure Enclave. We receive a signed decision, never the biometric.
- Does it slow every action down?
- No. Your policy picks the few actions that need a person; everything else runs untouched.
- Can we verify approvals ourselves?
- Yes. Each decision is verifiable against published keys, in your own backend, without us in the loop.

See it on your own flow.
Your app, your call, our SDK.