CAI Technology
Menu ☰
01 / 08
🔐 Cipher AI Authenticator · CHAP-1

CAI-AUTH
Post-quantum authentication

Sovereign digital identity for regulated companies. Built in Romania. Aligned with eIDAS 2.0 EU Digital Identity Wallet.

02 / 08
The problem

Passwords are no longer enough. And every current MFA alternative forces you into a compromise.

SMS

SIM swap exposes the codes. The carrier sees them. Deprecated as MFA by NIST since 2017.

Google / Microsoft Authenticator

The secret is copyable text; if the phone is compromised, it leaks. Vulnerable to real-time phishing.

Duo Push (US SaaS)

Data transits US servers. CLOUD Act + Schrems II = GDPR headache. 6-8 €/user/month.

YubiKey hardware

Technically excellent. But 60 € per key × 200 users = 12,000 € + distribution logistics.

FIDO2 Passkeys (Apple / Google)

Sync via iCloud / Google = total vendor lock-in. Data on US servers. Apple / Google can lock the account.

03 / 08
The solution

CAI-AUTH checks every box at once.

One solution: as simple as Google Auth, as secure as YubiKey, 0 € per-user licence, EU-only data, post-quantum ready, eIDAS 2.0 compatible from day one.

Step 1

The app requests authentication

You log in with username + password (or passkey). The app sends a confirmation request.

Step 2

Push to your phone

You get a notification with details: which site, which action, from which IP. You tap fingerprint/face → sign locally.

Step 3

Server verifies, lets you in

Your key NEVER leaves the phone's secure hardware element. The server sees only the signature.

Total: 3 seconds · no TOTP typing · no SMS · no third-party redirects

04 / 08
Direct comparison

The only solution that ticks every critical box.

Criterion Google Auth Duo Push YubiKey Passkeys CAI-AUTH
Hybrid post-quantum (patent application in preparation — OSIM, May 2026)
HW-bound key (never leaves the chip) ~
Native anti-phishing (origin binding) ~
Sensitive-action confirmation ~
100% self-hosted
Data in the EU (Schrems II safe)
Social Recovery without vendor cloud
eIDAS 2.0 EUDI ready ~
Licence cost · 200 users · 3 years 0 €~300k €~12k € HW0 €0 €
05 / 08
Why us

Four things nobody else ticks.

🇪🇺

Absolute EU sovereignty

Data 100% in the EU (Romania / Frankfurt). Schrems II safe by architecture. For regulated companies (banking, public sector, healthcare) — the only honest option.

🛡️

Post-quantum from day one

Hybrid classical + post-quantum cryptography (patent application in preparation — OSIM Romania, May 2026). "Harvest now, decrypt later" — a real attack today against long-lived tokens. PQ must be applied now, not when Q-day arrives.

📅

eIDAS 2.0 ready

EU Digital Identity Wallet becomes mandatory in December 2026 (Reg. 2024/1183). The only Romanian-built product architecturally aligned with the EU wallet.

💰

Zero per-user cost

Unlike Duo (~300k € for 200 users over 3 years) or YubiKey (12k € hardware), CAI-AUTH is per-cluster licensed. You scale from 50 to 50,000 users without cost explosion.

06 / 08
Use cases

Three real scenarios, three problems solved.

🏦

Bank login

Login to internet banking: password + CAI-AUTH push. The code is never typed — the signature is generated locally on the phone.

PSD3 SCA · DORA aligned

💸

Financial transfer

See the transfer on the phone's HW-protected screen BEFORE you confirm it. A virus controlling the browser cannot forge the recipient.

Action-Visible Confirmation

🏢

Enterprise SSO

Single sign-on to 50+ internal apps via OIDC. New-hire onboarding: scan QR, biometric setup, done in 2 minutes.

OIDC + 4 grant types

07 / 08
Roadmap

Aligned with EU regulatory deadlines.

  1. 2026 Q2

    Production GA + commercial licensing

    Python SDK + Chrome extension shipped on install (source on request, commercial licence). OIDC discovery + 4 grant types. Deploy from 1 VM up to HA cluster. Public SDKs (Python on PyPI, Node, Rust) — on roadmap, not contractual commitment.

  2. 2026 Q3

    iOS native

    iOS app with secure hardware element attestation. 100% parity with Android: same protocols, same UX.

  3. 2026 Q4

    BLE offline + Digital Inheritance

    Offline authentication via Bluetooth (areas without signal). Social recovery with a safety interval.

  4. 2027 H1

    FIPS 140-3 + eIDAS 2.0 GA

    FIPS 140-3 certification of the cryptographic module. eIDAS 2.0 EUDI-compliant wallet for the EU December 2026 deadline.

08 / 08
Next step

Let's talk.

30 minutes. Live demo on your scenario. Free AI-readiness audit for companies with 50+ employees.

© 2026 CAI Technology · CAI TECHNOLOGY SRL · Tax ID 39185206 · Romania · Book a demo