Shush
Shush operates a silent, SIM-based mobile network authentication platform (Sherlock) that lets banks and CPaaS providers verify a phone's identity directly through mobile carriers, without SMS one-time passcodes.
Visit Website ↗ + Add to CompareOverview
Shush is a very young company, launched to market in September 2024, built around a specific and increasingly important authentication problem: SMS one-time passcodes are both a poor user experience and an increasingly exploited fraud vector (SIM swap, SMS interception, and OTP-relay social engineering). Shush’s platform, Sherlock, works with mobile network operators directly, using SIM-based APIs to silently verify that a device and phone number are genuinely paired to a live, un-swapped SIM, without sending a code the user has to read and retype.
The company’s pitch is aimed at financial institutions and CPaaS (communications platform as a service) providers that currently rely on SMS OTP for step-up authentication and want a way to verify network-level authenticity underneath that flow. In under two years, Shush says it has brought more than 100 million mobile subscribers under coverage across a number of carriers, an early but notable distribution signal for a company this young, and has raised early-stage funding to build out its MNO partnerships.
Shush is early-stage: it has not yet accumulated the multi-year track record, named enterprise case studies, or independent security evaluations that more established identity-verification vendors have. For CISOs and fraud teams evaluating it, the appeal is a technically sound answer to a well-understood weakness in SMS-based authentication, balanced against the execution risk of a company still proving out its carrier-partnership model at scale.
Innovation Matrix Assessment
Shush moved from platform launch in September 2024 to claimed coverage of over 100 million subscribers across multiple carriers in under two years, indicating rapid execution for a pre-Series-A company, though the product surface (a single authentication API) is still narrow.
As a company founded in 2024 with roughly $4.7 million raised and around 30 employees per third-party trackers, Shush has limited operating history and financial cushion compared to established identity vendors; carrier-partnership businesses also carry meaningful execution risk.
Reported subscriber-coverage growth (0 to 100 million-plus in under 18 months) and continued carrier onboarding are strong early momentum signals, though this is self-reported and momentum this early is inherently harder to verify than at a mature company.
Silent, SIM-based network authentication directly attacks a well-known weakness in SMS OTP (SIM swap and OTP interception fraud), offering a genuinely different mechanism than most step-up authentication vendors, which still rely on the SMS channel it aims to replace.
There is no independent, third-party efficacy testing or named enterprise case study publicly available yet for Shush's Sherlock platform; claims of fraud reduction and subscriber coverage are vendor-reported and unverified at this stage.
SIM-swap fraud and SMS OTP interception are a persistent, well-documented attack path against financial institutions and consumer apps, making carrier-level silent authentication a directly relevant answer to a current, high-profile fraud vector.
Why CISOs Should Care
SMS one-time passcodes remain widely deployed despite known SIM-swap and interception weaknesses; Shush gives fraud and identity teams a way to verify network-level device authenticity underneath that flow without a user-facing code.
What Makes It Different
Shush works directly with mobile network operators on SIM-based verification rather than relying on the SMS channel itself, differentiating it from most OTP and identity-verification vendors that still depend on a code being sent and read.
The Matrix Verdict
57/100 — INCREMENTAL INNOVATOR
A high-relevance, technically sound approach to a real authentication weakness, but still an early-stage company without the operating history or independent validation to be judged a proven platform; one to watch rather than a safe default choice yet.
Editorial Note: Claims vs. Verified Findings
Subscriber-coverage and revenue figures (100 million-plus subscribers, employee count, funding total) come from third-party data aggregators (ZoomInfo, PitchBook) reflecting company-reported data and were not independently verified through a named customer or auditor; treat all growth and coverage figures as vendor-sourced until confirmed.
Sources
Alternatives to Shush
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
AppViewX
Machine identity management platform automating certificate lifecycle management (CLM) and PKI operations at enterprise scale, including post-quantum cryptography…