swIDch
swIDch is a London-based authentication technology company that licenses OTAC, a one-time dynamic code protocol developed by parent company SSenStone, into financial services, IoT, and industrial authentication markets.
Visit Website ↗ + Add to CompareOverview
swIDch is the UK-based commercialization arm of OTAC (One-Time Authentication Code), a dynamic authentication protocol originally developed by its Korean parent company, SSenStone. Where SSenStone has concentrated its own direct deployments in Korean critical infrastructure and manufacturing, swIDch’s role is to license and adapt the same core OTAC technology for financial services, IoT device authentication, and industrial/OT systems in international markets, primarily through partnerships and an Auth SDK that integrates FIDO-certified biometric authentication, mobile one-time-password (mOTP) authentication, and OTAC login into client applications.
The technical proposition is the same as SSenStone’s: a single dynamic code that both identifies and authenticates in one step, generated without a live network connection and without leaving reusable key material stored anywhere, which OTAC-Holderless Card and OTAC Dynamic Token products apply to card-present and card-not-present payment authentication scenarios respectively. swIDch states its technology has been provided to more than 50 clients, though as with most authentication vendors that figure is company-disclosed rather than independently audited.
swIDch is a small company (roughly 9 employees per recent data) with about $3.5M in disclosed funding, considerably smaller in headcount and funding than its Korean parent. Because SSenStone and swIDch share the same core OTAC intellectual property, buyers evaluating either company should understand they are evaluating variations of the same underlying authentication technology deployed through different regional go-to-market structures rather than two independently developed products.
Innovation Matrix Assessment
swIDch has extended the core OTAC protocol into payment-specific products (OTAC Holderless Card, OTAC Dynamic Token) and an OT-focused Trusted Access Gateway, but as a very small team its pace of independent product development is inherently limited and closely tracks its parent company's roadmap.
With roughly 9 employees and a claimed 50+ client relationships, swIDch operates as a lean licensing and integration business for its parent's technology rather than a large-scale independent operation.
Public information on new swIDch-specific funding, partnerships, or customer wins in the last two years is limited compared to the more visible momentum (Hyundai investment, K-water deployment) at parent company SSenStone.
The underlying OTAC approach — a single dynamic, self-authenticating code with no stored key material and no network dependency — remains a genuinely different authentication architecture compared to standard token or certificate-based methods, regardless of which entity is commercializing it.
The '50+ clients' figure is company-disclosed and not independently broken out with named case studies specific to swIDch (as opposed to SSenStone); FIDO certification of its Auth SDK component is independently verifiable through the FIDO Alliance's certified product registry.
Dynamic, network-independent authentication remains relevant for financial services fraud prevention and for IoT/OT devices that can't support always-on connectivity, though swIDch's specific market traction in these areas is less independently documented than its parent's.
Why CISOs Should Care
For CISOs at financial institutions or IoT/OT device manufacturers evaluating alternatives to standard OTP or certificate-based authentication, swIDch offers licensed access to the same OTAC technology validated in SSenStone's critical infrastructure deployments, packaged for international financial and IoT markets.
What Makes It Different
swIDch's differentiation is inherited from the underlying OTAC protocol rather than independent innovation: a single dynamic code that authenticates without stored keys or network connectivity, now packaged with FIDO-certified biometric options via its Auth SDK.
The Matrix Verdict
50/100 — INCREMENTAL INNOVATOR
A small, technically credible licensee of a genuinely differentiated authentication protocol; buyers should recognize that swIDch and parent SSenStone share the same core technology, and should weigh swIDch's more limited independent scale and momentum against SSenStone's more visible critical-infrastructure track record.
Editorial Note: Claims vs. Verified Findings
The '50+ clients' figure is vendor-disclosed and not independently broken out by name. FIDO certification of the Auth SDK is independently verifiable via the FIDO Alliance registry. The parent-subsidiary relationship with SSenStone is confirmed on swIDch's own site and independently reported by multiple business-data sources (Crunchbase, Tracxn).
Sources
Alternatives to swIDch
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
AppViewX
Machine identity management platform automating certificate lifecycle management (CLM) and PKI operations at enterprise scale, including post-quantum cryptography…