Adaptive challenge
A 30-question profile becomes the private key behind every code. Each request asks a different question, verified server-side, with lockout after repeated mismatches.

Ydenticator is a next-generation two-factor authenticator that binds every code to three factors: something you know (a private 30-question profile), something you are (your device biometrics), and something you own (the device itself). A stolen phone, a leaked seed, or a compromised inbox is never enough to sign in as you.
A 30-question profile becomes the private key behind every code. Each request asks a different question, verified server-side, with lockout after repeated mismatches.
Your profile is encrypted with AES-GCM-256 using a non-extractable key derived via WebAuthn PRF — anchored in Face ID, Touch ID, or Windows Hello. The key never leaves the hardware.
Register any RFC 6238 provider by scanning its QR code, with replay protection and audit logging. Enroll a second device with a signed one-time link — no cloud sync of seeds, ever.
Opt in to 10 single-use recovery codes, each independently wrapping your profile with PBKDF2 + AES-GCM. Export as a password-protected PDF. Rate-limited to 10 attempts per 15 minutes to defeat brute force.
Install Ydenticator to your home screen on iOS, Android, or desktop. GDPR-compliant, TLS 1.3 with post-quantum key exchange end-to-end, and no third-party trackers.