Beyond Identity
Passwordless, phishing-resistant authentication platform using X.509 certificate-based device binding instead of passwords or push notifications.
Visit Website ↗Overview
Beyond Identity was founded in 2019 by Jim Clark (a co-founder of Netscape and Silicon Graphics), Nelson Melo, and Jasson Casey, with a mission to eliminate passwords entirely rather than layer MFA on top of them. Its architecture uses X.509 certificate-based cryptography bound to a specific device, so authentication is tied to a private key that never leaves the device rather than a shared secret that can be phished, replayed, or fatigued via push-notification bombing.
The company raised a $100 million Series C in February 2022, bringing total funding to $205 million at a $1.1 billion valuation, with backing from New Enterprise Associates and co-founder Jim Clark personally. No larger public funding round has been reported since, which is a relevant data point on recent momentum relative to newer passwordless and NHI entrants.
Beyond Identity’s core technical differentiation — device-bound asymmetric cryptography rather than a shared secret or an out-of-band push approval — directly addresses the MFA-fatigue and SIM-swap attack classes that have undermined push- and SMS-based MFA at companies like Uber and Twilio in widely reported incidents.
Innovation Matrix Assessment
Core passwordless architecture has been stable since launch; recent public product news has been less frequent than in its 2020-2022 growth period.
Removing passwords and push-approval prompts entirely eliminates both password-reset help-desk load and the MFA-fatigue social-engineering vector in one step.
Reached a $1.1B valuation in 2022 but no larger funding round has been publicly reported since, suggesting momentum has plateaued relative to more recently funded category peers.
Device-bound certificate authentication is a genuinely different mechanism than password-plus-second-factor, though FIDO2/passkeys have since brought similar phishing-resistant properties into mainstream platforms.
Certificate-based authentication is cryptographically well-understood, but independent, large-scale third-party efficacy evidence beyond vendor case studies is limited in public sources.
Phishing-resistant authentication remains a priority as push-fatigue and SIM-swap attacks continue to defeat weaker MFA, though the rise of passkeys as an open standard is a competitive pressure on proprietary approaches.
Why CISOs Should Care
Beyond Identity eliminates both the password and the push-notification approval step that attackers repeatedly abuse via MFA fatigue and SIM-swapping, closing two of the most commonly exploited authentication weaknesses at once.
What Makes It Different
It binds authentication to a device-held private key via X.509 certificates rather than a shared secret or an approvable push notification, removing the phishable and fatiguable elements of conventional MFA entirely.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
A technically sound, genuinely phishing-resistant approach that predated mainstream passkey adoption, but funding and public momentum appear to have slowed since its 2022 raise. An Incremental-to-Meaningful Innovator.
Editorial Note: Claims vs. Verified Findings
Funding and valuation figures are corroborated by the company's own press release and Crunchbase; no independent funding news has been found more recent than the 2022 Series C, which is itself a relevant momentum signal rather than an oversight.
Sources
- Beyond Identity Raises $100 Million — https://www.beyondidentity.com/announcements/beyond-identity-raises-100-million-to-accelerate-adoption-of-invisible-un-phishable-mfa-for-customers-and-employees
- Beyond Identity Raises $75 Million — https://beyondidentity.com/news/beyond-identity-raises-75-million
- TechStartups — https://techstartups.com/2020/12/08/beyond-identity-secures-75-million-funding-advance-usher-new-era-passwordless-authentication/
Alternatives to Beyond Identity
Silverfort
Agentless unified identity protection platform that extends MFA, ITDR, and access policy to legacy and unmanaged systems traditional…
Veza
Identity security platform built around an authorization graph that maps who and what can actually access data and…
Oasis Security
Non-human identity management platform discovering, classifying, and governing service accounts, API keys, and machine credentials, now extending to…
Semperis
Identity resilience platform specializing in Active Directory security posture, attack-path discovery, threat detection, and disaster recovery.
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Microsoft Entra ID
Microsoft's cloud identity and access platform (formerly Azure AD) providing SSO, conditional access, MFA, and identity governance across…