Identity & Access Management,
Multi-factor & Risk-based Authentication,
Security Operations
Keyless’s Biometric Technology Enhances Privacy, Account Recovery, and User Experience

Ping Identity has acquired a biometrics startup led by a former Accenture business strategy analyst, a strategic move aimed at bolstering authentication for frontline workers and shared terminal environments. The Denver-based leader in identity security emphasized that traditional device-based authentication methods fall short for employees who do not have dedicated devices, highlighting the rising importance of privacy-focused technologies like zero-knowledge biometrics. Founder and CEO Andre Durand stated that this acquisition allows for server-side biometric authentication while ensuring privacy and regulatory compliance.
In an interview with Information Security Media Group, Durand articulated the necessity for solutions specifically designed for frontline workers rather than solely for white-collar employees. Many frontline workers operate in environments—such as call centers and factory floors—where personal devices are either restricted or not permissible. These unique contexts pose challenges for traditional authentication methods, including push notifications and passkeys. With the incorporation of Keyless technology, Ping aims to provide biometric-based account recovery features for lost or stolen devices, significantly improving both security measures and user experiences.
Durand further explained that a significant percentage—up to 80%—of enterprise employees are frontline workers who frequently rely on shared terminals without mobile device access. He emphasized the need for a robust, privacy-preserving alternative capable of authenticating users when personal devices are not available. Keyless facilitates biometric authentication capable of resisting deepfakes and social engineering attacks, thus strengthening overall security.
Traditional biometric solutions typically involve storing biometric templates, a practice Durand cautioned against due to its potential risks following a security breach. Keyless’s innovative approach deviates from this norm, utilizing a method that enables biometric authentication without retaining any biometric data on centralized servers.
Durand described this innovation as “zero-knowledge biometrics,” a methodology that allows for server-side biometric processes without compromising sensitive data. This approach ensures that if biometric information is never stored, it cannot be subject to unauthorized access or theft.
Moreover, Durand underscored the critical significance of privacy and deepfake resistance in modern biometric solutions. As malicious actors increasingly target IT support channels using deepfake techniques for account access, Keyless offers mechanisms to detect such threats, empowering organizations to employ biometric authentication securely for logins, re-verification processes, and account recovery.
Looking ahead, Ping Identity plans to initially implement Keyless technology in scenarios with the most pressing need for device-less authentication, such as shared desktops and factory terminals. Following deployment in these critical use cases, Ping aims to more broadly integrate Keyless biometrics within its existing suite of solutions, encompassing passwordless login and identity verification services.
Ultimately, Durand emphasized that a holistic identity solution is essential to ensure secure authentication for all users, independent of device availability. Historically reliant on passwords, organizations can now transition to a user experience akin to facial recognition technologies, vastly improving accessibility across a wide array of scenarios. With Keyless, Ping Identity extends the concept of passwordless access to encompass all users, thus promoting an inclusive solution that meets evolving cybersecurity needs.
As organizations continue to explore biometric strategies, understanding the potential adversarial tactics outlined by the MITRE ATT&CK framework—such as initial access, persistent threat management, and privilege escalation—will be crucial in navigating this complex landscape effectively. With escalating threats in the cybersecurity realm, embracing innovative technologies such as those developed by Keyless will be vital for maintaining robust security postures.