Security Guide · For Organisations

Switch on passkeys — without the jargon.

You don't need to understand the cryptography. This is the short version: what you, as the person running the organisation, need to understand and do so your customers or staff can sign in with a fingerprint, face, or PIN instead of a password.

No passwords to store No TOTP app Works on phones & laptops
The Short Version

What signing in becomes.

A passkey replaces the password with the fingerprint, face, or PIN.

Nothing to remember

They unlock with a fingerprint, face, or PIN. No password to type, reset, or forget.

Nothing to steal

There's no shared password sitting on your servers to be grabbed — or tricked out of your customer by a fake site.

They tap a sensor they already own — and they're in.

Before You Switch It On

Check it works where your users are.

Try it on the devices your people actually use. You're checking one thing: can a normal person sign in, first time, without calling for help?

Device What the user does
Windows laptopUsing Windows Hello, Looks at the camera, uses the fingerprint reader, or types a PIN
MacTouches the Touch ID button
iPhone / iPadFace ID or a fingerprint
Android phoneFingerprint or screen unlock
Security keyPlugs in the key and touches it (e.g. a YubiKey)
The Good News

What you don't have to do.

Passkeys take work away rather than adding it. Here's what stops being your problem.

No passwords to store

For accounts that use a passkey, there's no password database to protect, reset, or lose sleep over.

No TOTP app

No authenticator app to set up, and no six-digit codes to copy across from your phone. The check happens on the device.

No hardware for most people

Nearly everyone already has a phone or laptop that can do this. Only sensitive roles might need a security key.

No big project

For most businesses this is a feature your existing login system or vendor can switch on — not a rebuild.