Covr Security
A Malmo, Sweden-based provider of cloud-based, BankID-inspired passwordless multi-factor authentication for banks, payment networks, and mobile carriers.
Visit Website ↗ + Add to CompareOverview
Covr Security sells cloud-based, phishing-resistant multi-factor authentication as a service, aimed at banks, payment networks, card issuers, eID providers, mobile carriers, and IoT device makers that need to verify a user’s identity without relying on a password or an SMS one-time code. Its model is explicitly inspired by Sweden’s BankID scheme — a device-bound, three-layer verification approach (something the user has, is, and knows) delivered as an API/SDK that a bank or carrier embeds directly into its own app rather than routing users through a separate authenticator app.
Founded in 2015 by Peter Alexanderson and based in Malmö, Sweden, Covr Security has raised roughly $5 million across a handful of rounds from investors including SecurIT, Bangkok Bank InnoHub, and Accelerator Frankfurt — a Bangkok Bank-linked accelerator investment that also signals real interest from an Asian banking customer. The company is small, with roughly 20 employees, reflecting an API/SDK business model that does not require a large sales or services organization to support each customer integration.
Passwordless and phishing-resistant authentication is now a crowded category dominated by much larger, better-funded identity vendors, and Covr Security’s realistic niche is banks and telecoms in markets (Northern Europe, Southeast Asia) that want a BankID-style national-identity-verification model without building it themselves.
Innovation Matrix Assessment
Covr has expanded its API/SDK platform to serve multiple verticals (banking, payment networks, eID, IoT, mobile carriers) beyond its original banking focus, a moderate pace consistent with a ~20-person team.
The authentication-as-a-service model is delivered via API/SDK embedded directly into a customer's own app, which scales operationally without a large services organization, though the company's small headcount limits how many concurrent enterprise integrations it can support.
Total disclosed funding of roughly $5.3M across several small rounds, most recently a 2024 seed-stage round, indicates modest but real investor interest rather than strong growth momentum.
Applying a BankID-style device-bound verification model to a broader set of banks and carriers is a sensible adaptation of a proven national-identity scheme, but passwordless/phishing-resistant MFA is now a crowded category with larger incumbents offering similar device-bound approaches.
Investment from a Bangkok Bank-affiliated accelerator (Bangkok Bank InnoHub) suggests real interest from at least one banking customer, but no independently published deployment case study, breach-prevention statistic, or third-party security assessment of Covr's platform was found.
Banks, telecoms, and payment networks are under sustained pressure to move users off passwords and SMS one-time codes toward phishing-resistant authentication, keeping a turnkey, API-delivered MFA service relevant to smaller institutions that lack BankID-scale infrastructure of their own.
Why CISOs Should Care
Covr lets a bank or carrier's security team offer BankID-style device-bound authentication inside their own app via API, without the multi-year, national-scale infrastructure investment that building an in-house equivalent would require.
What Makes It Different
Covr's differentiation is explicitly modeling its verification approach on Sweden's BankID, a scheme with proven high consumer trust and adoption, rather than a generic authenticator-app or push-notification MFA flow.
The Matrix Verdict
47/100 — EMERGING / UNRANKED
A small, focused authentication vendor with a credible product thesis borrowed from a proven national model; realistic value for banks and carriers in Northern Europe and Southeast Asia, but thin disclosed funding and no independent efficacy evidence limit confidence in claims of accuracy at scale.
Editorial Note: Claims vs. Verified Findings
Covr's specific customer base (named banks, carriers, or eID providers) was not independently verifiable; descriptions of its clientele come from the company's own site. The BankID-inspired verification model, 2015 founding, Malmo headquarters, and approximate $5.3M in disclosed funding are corroborated across independent sources (Crunchbase, PitchBook, Tracxn).
Sources
Alternatives to Covr Security
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
CyberArk
The market-leading privileged access management vendor, extending from vaulted human credentials into machine identity and secrets management.