2
3 Comments

Got breached by credential theft, so I built passwordless SSO to fix it

A while back my Ingram Micro account got compromised through stolen credentials. Not a sophisticated attack, just a password that ended up somewhere it shouldn't have. That was the moment I decided passwords themselves were the problem, not the policies around them.

So I built VeriLink, a passwordless authentication platform on top of OIDC and OAuth2. The idea is simple: remove the password entirely instead of layering more rules on top of it.

Where things stand:

We just went live with our first production design partner, an e-commerce storefront running full OIDC integration in the wild, not a demo environment.

We also completed a third party pen test and remediated every finding, 8 out of 8. That mattered more to me than I expected. It is one thing to say your auth flow is secure, another to have someone try to break it and then fix everything they find.

The harder problem I am working through now is the one a lot of early security vendors hit: enterprise buyers want SOC 2 before they will even take a call, but SOC 2 takes real revenue and time to earn. It is a catch-22 that keeps solid tools stuck outside the door. Right now I am leaning into smaller dev teams and indie shops first, the people who care about not getting breached but do not need a compliance binder to say yes.

If you have dealt with the SOC 2 catch-22 from either side, as a buyer who wanted to say yes but could not, or as a vendor stuck waiting on the audit, I would like to hear how you navigated it.

VeriLink: passwordless SSO for secure, frictionless access.

posted toAvatar for product VeriLink
VeriLink
  1. 1

    The strongest proof point is having a real production design partner plus an independent pen test behind the product. That moves VeriLink beyond an authentication concept into something people can actually evaluate in a real environment.

    1. 1

      Exactly that’s been the biggest shift for me. Our first production design partner, B² Apparel Plus, is now running VeriLink through a live OIDC implementation, so we’re getting validation from an actual production environment rather than a controlled demo.

      Pairing that with the independent pen test gives us something much stronger than our own security claims. Now the focus is proving that same reliability across more implementations and developer teams.

      1. 1
        That’s a meaningful validation step. I’d be interested to see what you learn as more teams put it through real production environments.