← All solutions

For defence and secure systems

Passkey authentication that stays inside the boundary.

A future assured RustyAuth profile could operate with local trust, device-bound authenticators and an entirely offline software lifecycle.

Illustrative reference scenarioNot a customer or compliance claim
4-step authentication pathCustomer boundary
  1. 01
    Issued security keyHolds a device-bound credential
  2. 02
    Local applicationRuns on the trusted internal origin
  3. 03
    RustyAuth enclaveVerifies locally and issues tokens
  4. 04
    Private persistenceKeeps identity and signing state inside

The operating reality

An engineering application operating in a disconnected enclave

Personnel authenticate with organisation-issued, device-bound security keys. RustyAuth verifies every ceremony against local state, creates a revocable session and issues a short-lived token to the protected application. DNS, certificates, time, backups and operational evidence all remain inside the enclave.

01

No public dependency

The authentication path must continue operating without internet access, hosted identity or licensing phone-home.

02

Approved authenticators

Credential policy must distinguish issued, device-bound hardware from unmanaged or synchronised passkeys.

03

Controlled operations

Installation media, updates, keys, recovery and audit export need reviewable offline procedures.

What the core contributes

Authentication stays small.
The product stays authoritative.

RustyAuth establishes who authenticated and issues narrow claims. Sector-specific systems keep every business decision.

01

Self-contained core

RustyAuth and its private data store can run within one controlled network.

02

Phishing resistance

WebAuthn binds authenticator output to the configured relying-party identity.

03

Fail-closed state

Invalid configuration, missing trust state and incomplete recovery prevent normal operation.

Honest boundary

What this story does—and does not—claim.

Regulated infrastructure earns trust through evidence. These boundaries remain explicit while RustyAuth is pre-release.

RustyAuth does not replace

  • Personnel vetting or identity proofing
  • Endpoint and network security
  • Application authorisation policy
  • Formal accreditation or approved cryptographic modules

Production profile requires

  • Offline signed release bundles and SBOMs
  • Authenticator attestation and allowlisting
  • HSM or approved cryptographic integration
  • Independent assessment and assured support

Begin with evidence

Evaluate the boundary
inside your environment.

RustyAuth is pre-release. Start with a synthetic account and a controlled evaluation—not a sole production identity dependency.