Queralt offers the QX.509 platform, a passwordless authentication solution that binds a user’s verified identity to an X.509 certificate stored in the device’s Secure Enclave or TPM. By using hardware‑backed private keys and biometric plus PIN protection, it provides seamless, device‑bound logins that integrate with existing enterprise PKI and eliminate shared secrets, reducing phishing and credential‑theft risks for large organizations.
Funding
$749.8K raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.
Founders
Product
Problem
Enterprise users are forced to manage passwords and other shared secrets, which are vulnerable to phishing, credential theft, and large‑scale breaches. Reliance on these secrets creates a high administrative burden and weakens overall security posture. A more robust method is needed that eliminates shared credentials while providing seamless access.
Solution
Queralt’s QX.509 platform replaces passwords with a passwordless authentication flow that binds a verified user identity to an X.509 certificate stored in the device’s Secure Enclave or TPM. The certificate is issued based on the user’s business email and biometric data, then locked by a biometric factor and a personal PIN. During login, the device’s hardware‑protected private key performs an asymmetric cryptographic handshake with the service’s public key, instantly proving identity without transmitting secrets. Because the private key never leaves the hardware enclave, it is resistant to extraction even if the endpoint is compromised. QX.509 integrates with existing PKI infrastructure, requiring no replacement of corporate certificate authorities or directory services. The result is a frictionless, device‑bound login experience that dramatically reduces phishing and credential‑theft attack vectors.
Target Audience
Primary customers are large enterprises and regulated industries (e.g., healthcare, finance, government) that manage internal applications and need strong, passwordless authentication for their workforce.
Features
- Hardware‑backed isolation of private keys in Secure Enclave (iOS) or TPM (Windows/Linux) prevents key extraction
- Biometric (Face ID, fingerprint) plus user‑defined PIN provides multi‑factor protection on the device
- Seamless issuance of X.509 certificates linked to corporate email identities using existing PKI systems
- Real‑time asymmetric cryptographic handshake (FIDO2‑compatible) eliminates passwords and shared secrets
- Transparent integration with enterprise applications via standard PKI and FIDO2 protocols, no new infrastructure required
- Supports a wide range of FIDO2‑certified devices, including smartphones, PCs, smart cards, and USB tokens