Idenprotect
A UK identity and access management vendor offering certificate-based, passwordless multi-factor authentication and secure browsing for organizations moving off passwords entirely.
Visit Website ↗ + Add to CompareOverview
Idenprotect (trading name of Apply Mobile Limited) builds passwordless, phishing-resistant authentication built on device-bound cryptographic certificates rather than shared secrets. Its Idenprotect Passport product links a user’s registered mobile device to their identity and uses certificate-based authentication and biometrics on that device to authorize access, removing the password, and with it credential stuffing, password reuse, and most phishing vectors, as an attack surface entirely. The company also offers a secure browsing capability aimed at reducing exposure from compromised or unmanaged endpoints.
Founded in 2014 by CEO Craig McDermott and based in the United Kingdom, Idenprotect is a small, privately held vendor (roughly 15-20 employees) that has recently achieved ISO 9001:2015 and ISO 27001:2022 certification, formal evidence of a maintained quality and information security management system rather than a marketing claim. The company positions its authentication approach as helping customers meet GDPR, ISO 27001, and NIST authentication guidance, and continues to post regular product and industry commentary, including on the UK’s Cyber Security and Resilience Bill.
Idenprotect operates in a passwordless/phishing-resistant MFA category now crowded with much larger identity vendors (Microsoft, Okta, Yubico, and others) that have made passkeys and FIDO2 broadly available. The company’s differentiation rests on its certificate-based device-binding approach and integrated secure browsing, but publicly available detail on named enterprise customers, deployment scale, or independent security testing is limited, which should temper expectations for buyers doing vendor comparison against larger, better-documented competitors.
Innovation Matrix Assessment
Publicly visible product development is limited to periodic LinkedIn updates and channel-partner announcements rather than documented release notes or a public roadmap, making shipping cadence hard to verify from the outside.
Recently achieved ISO 9001:2015 and ISO 27001:2022 certification is a genuine, checkable operational maturity signal, but the company discloses little about deployment scale, customer count, or support infrastructure.
No external funding rounds are publicly disclosed and the company appears to be operating on a small, steady-state basis (roughly 13-18 employees) after more than a decade in business, with no clear evidence of accelerating growth.
Certificate-based, device-bound passwordless authentication is sound technology, but it is now a well-established approach (FIDO2/passkeys are mainstream) rather than a novel one, and Idenprotect is a small player in a category now served natively by much larger identity platforms.
No independent penetration test results, named enterprise case studies, or third-party security evaluations are publicly available; the ISO certifications speak to process maturity but not to demonstrated attack-resistance in production.
Passwordless authentication remains a high-priority initiative for most security teams given the persistence of credential-based attacks, keeping the underlying use case relevant even though the specific vendor has limited public visibility.
Why CISOs Should Care
Organizations that want a UK-based, certificate-based passwordless authentication vendor with formal ISO 27001 information-security certification have a smaller, more attentive alternative to the large identity platforms here.
What Makes It Different
Idenprotect binds authentication to a certificate issued to a specific registered device plus biometrics, combined with a secure browsing layer, rather than relying solely on a passkey or authenticator-app model.
The Matrix Verdict
45/100 — EMERGING / UNRANKED
A legitimate, ISO-certified passwordless MFA vendor with a sound technical approach, but thin public evidence of scale, named customers, or independent validation limits confidence relative to larger, better-documented identity platforms; worth a look for UK-based buyers wanting a specialized, smaller vendor.
Editorial Note: Claims vs. Verified Findings
Vendor-sourced and unverified: specific risk-reduction and customer-outcome claims found in Idenprotect marketing copy, and the exact current employee count (sources range from 13-18). Independently verifiable: the 2014 founding date, UK incorporation as Apply Mobile Limited, and the ISO 9001:2015 / ISO 27001:2022 certifications referenced in the company's own LinkedIn announcements.
Sources
Alternatives to Idenprotect
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
AppViewX
Machine identity management platform automating certificate lifecycle management (CLM) and PKI operations at enterprise scale, including post-quantum cryptography…