01 · WebAuthn / FIDO2
Browser and platform APIs for registration and assertion — origin-bound credentials that defeat classic phishing.
A practical framework for FIDO readiness — FIDO2, WebAuthn, CTAP and passkeys mapped into policy, recovery, enterprise rollout and evidence. Educational only; not a FIDO Alliance certification.
Open the frameworkFIDO Alliance standards (FIDO2 / WebAuthn / CTAP) enable phishing-resistant, public-key authentication — including passkeys. This portal turns that into a workable programme: scope, authenticator policy, recovery without secret questions, IdP integration, operations and assurance evidence.
Mark each item as you build evidence. Use this as a rollout and assurance conversation — not as a certificate.
This framework is educational. It is not legal advice, a FIDO Alliance certification, or a determination of product or programme conformity.
Browser and platform APIs for registration and assertion — origin-bound credentials that defeat classic phishing.
Client-to-authenticator protocol for roaming security keys and platform authenticators under user presence / verification.
Synced or device-bound credentials with discoverable credentials, UX for sign-in, and ecosystem recovery paths.
When and how to verify authenticator make/model (AAGUID), enterprise allowlists, and privacy trade-offs.
PIN, biometric or local factor on the authenticator — and when UV is required vs user presence alone.
Enrolment friction, lost-device recovery, helpdesk social engineering, and how people actually adopt passkeys.
ISO/IEC 27001
Map FIDO adoption to access control, authentication and cryptography themes in your information security management system.
Open ISO 27001 frameworkISO/IEC 42001
Agentic and AI-augmented workflows amplify account takeover risk — phishing-resistant auth remains foundational.
Open ISO 42001 frameworkWP-01
SanRa thought leadership on human factors and security in the age of AI-augmented systems.
Download whitepaperRead our privacy notice.