Secfense
Secfense is a Krakow-based identity security vendor whose User Access Security Broker sits as a network proxy in front of existing applications, adding FIDO-based passwordless multi-factor authentication without requiring any code changes.
Visit Website ↗ + Add to CompareOverview
Secfense is a Krakow, Poland-based identity and access security company, founded in 2018, built around a product it calls the User Access Security Broker (UASB). Rather than requiring an application to be modified or re-coded to support strong authentication, the UASB sits as a network-layer proxy between users and applications, learns existing authentication traffic patterns, and inserts an additional FIDO2/WebAuthn-based passwordless MFA layer in front of the login flow. That no-code integration model is the company’s central pitch: adding FIDO-grade authentication to a legacy or vendor-supplied application in days rather than the months a native SDK integration would typically take.
This matters most for large, authentication-fragmented organizations — banks, insurers, ministries — running dozens of internal and customer-facing applications, many of them old or third-party systems whose vendors won’t prioritize a FIDO integration. Secfense’s proxy approach lets a security team roll out strong authentication centrally without needing cooperation from every individual application owner or vendor.
The company’s clearest independent validation is a named enterprise deployment: BNP Paribas Bank Polska adopted Secfense to introduce FIDO-based MFA across its banking operations, and Poland’s Ministry of Infrastructure selected the UASB to support two-factor authentication — both are publicly confirmed, named customers rather than anonymized case studies. Secfense raised a $2 million seed round in 2022 from Tera VC, Presto Ventures, and RKKVC, along with a syndicate of individual angel investors.
At roughly 16 employees, Secfense is a small company relative to the identity giants (Okta, Ping Identity, Microsoft Entra) it indirectly competes with; its realistic niche is organizations that need to retrofit strong, phishing-resistant authentication onto systems those larger identity platforms can’t easily reach without native integration work, particularly in regulated European markets like banking and government.
Innovation Matrix Assessment
Secfense has extended the User Access Security Broker to support a broad set of MFA methods and FIDO2/WebAuthn flows since founding, but as a small, seed-stage company it does not publish an extensive independent research track record.
The company reports rolling out full FIDO protection to customers within 7-14 days of deployment via its no-code proxy model, and its production use inside a regulated bank (BNP Paribas Bank Polska) is a strong indicator the architecture works reliably in a demanding operational environment.
A $2M seed round in 2022 from Tera VC, Presto Ventures, RKKVC and an angel syndicate is modest funding for a company founded in 2018, indicating the business has grown cautiously rather than through large venture-fueled expansion.
The proxy-based, no-code approach to inserting FIDO2 passwordless MFA in front of legacy or vendor applications is a genuinely different integration model than the SDK-based approach most identity vendors require, directly solving the 'can't get the app vendor to add MFA support' problem.
Two named, verifiable enterprise/government deployments (BNP Paribas Bank Polska, Poland's Ministry of Infrastructure) in security-sensitive regulated sectors are meaningful independent adoption evidence, though there is no published third-party study quantifying phishing-resistance improvement or fraud reduction from these deployments.
Retrofitting phishing-resistant, FIDO-based authentication onto legacy or third-party applications without vendor cooperation is directly relevant to CISOs at banks, insurers, and government agencies running large portfolios of internal systems they can't easily re-architect.
Why CISOs Should Care
CISOs running large portfolios of legacy or vendor-supplied applications that can't be natively re-coded for MFA get a way to add FIDO2 passwordless authentication centrally, in days, without per-application integration work.
What Makes It Different
Secfense inserts strong authentication at the network/proxy layer rather than requiring native SDK integration into each application, letting it protect legacy and third-party systems that identity platforms requiring code changes typically can't reach.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A small but technically differentiated identity vendor with genuine, verifiable deployments in regulated European institutions; its funding and scale are modest, so its realistic role is a specialist retrofit solution for authentication-fragmented enterprises rather than a broad identity-platform replacement.
Editorial Note: Claims vs. Verified Findings
The BNP Paribas Bank Polska and Poland's Ministry of Infrastructure deployments are named, publicly confirmed customers reported in company case studies and corroborated by independent press coverage. The specific '5 minutes to add FIDO to any application' and '7-14 days to full protection' integration-speed claims are vendor-sourced marketing figures that CDMG has not independently timed or verified.
Sources
Alternatives to Secfense
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
CyberArk
The market-leading privileged access management vendor, extending from vaulted human credentials into machine identity and secrets management.