Skip to main content
PQC is being rolled out across the MyID product family. View our roadmap →

Trusted Identity.
Anywhere. At Any Scale.

Intercede protects the world's most security-critical organisations from the number-one cause of breach: weak and stolen credentials. From password screening against 11 billion+ compromised credentials to phishing-resistant smart cards and FIDO2 passkeys, the MyID® platform delivers the right level of authentication for every user, simply, securely and at scale.

Trusted by
The Authentication Scale

Where are you today?
We'll show you what fits.

Authentication maturity is a scale, not a ladder. Even with PKI in place, you still manage passwords for some users, passkeys for others, and basic MFA for others. Drag the marker to your highest point today. MyID covers the whole scale, not just one area.

Passwords
only
SMS / Email
codes
Push /
OTP MFA
Passkeys
PKI Smart
Cards
Drag me
You are here

Passwords only

No second factor in place. Every employee credential is a single point of failure, and there's no visibility into which ones are already on the dark web.

  • 81% of breaches start with a stolen or weak credential
  • Credential stuffing attacks succeed in seconds against re-used passwords
  • No visibility into which of your staff are already compromised
Your next move with MyID
P
MyID PSM Password Security Management

Find your exposure. Block the worst passwords.

Continuously screen every workforce credential against 11 billion+ breached passwords and enforce NIST SP 800-63B policy at every change, with employee self-service that removes IT overhead.

  • Screen every password against 11B+ breached credentials
  • NIST SP 800-63B policy at the point of change
  • Self-service reset, less helpdesk load
The MyID Platform

One integrated identity
security family.

From detecting breached passwords to issuing PKI smart cards and FIDO Passkeys, MyID has you covered every step of the way.

PKI & FIDO Credential Management

MyID CMS

Enterprise Credential Management System

The identity credential platform trusted by large enterprises, financial institutions and government organisations worldwide. Full credential lifecycle management for PKI and FIDO2 passkeys, from issuance and renewal to revocation and recovery, at scale, across on-premise, cloud, hybrid and air-gapped deployments.
Platform Agnostic
Native connectors for Microsoft, Entrust, DigiCert and EJBCA.
Every form factor
Smart cards, USB security keys, mobile, Windows Hello for Business and FIDO2 passkeys
Air-gap ready
Private cloud, on-premise or offline air-gapped networks
FIPS 201 PIV & PIV-I credential issuance
Enterprise FIDO2 passkey management, with or without PKI
Post-quantum ready: ML-DSA & ML-KEM via EJBCA
Native multi-CA: Entrust, DigiCert, ADCS & EJBCA
Microsoft Entra ID native integration
Offline, air-gapped operation
Cryptographic Key Management

MyID SecureVault

Secure Credential Vault

CA-independent key archival, recovery and biometric data storage. Generate, store and recover RSA and ECC private keys with optional HSM-backed protection, OAuth2 or mutual TLS authentication and a full audit trail. The secure foundation for PKI credential key management.

CA-independent key escrow and recovery
Optional HSM-backed keys (Entrust nShield, Thales Luna)
RSA and ECC key algorithms
Encrypted biometric data storage
OAuth2 or mutual TLS, full audit trail
REST API with Swagger documentation
Password Security Management

MyID PSM

Breached Password Detection

Enforce NIST SP 800-63B password policy in Active Directory and screen every password against 11 billion+ known compromised credentials.

11 billion+ breached credentials
Beyond complexity rules
NIST SP 800-63B policy enforcement
Active Directory native, no proxy
Detects shared and dormant accounts
Self-service reset with a full audit trail
Multi-Factor Authentication

MyID MFA

Phishing-Resistant Authentication

Phishing-resistant authentication built on FIDO2 passkeys. Device-bound and synced passkeys are the primary factor for cloud, on-premise and Windows logon, with supplementary factors available for fallback and step-up.

FIDO2 passkeys, device-bound and synced
Resistant to phishing, replay and push-bombing attacks
Passwordless Windows desktop logon, online or offline
Works with Microsoft Entra ID via SAML 2.0
Supplementary factors: push, OATH TOTP, YubiKey and grid
Self-service enrolment, less helpdesk load
Industries

Trusted where identity
security is non-negotiable.

From federal agencies issuing millions of PIV credentials to global banks securing tens of thousands of employees, organisations with the highest security requirements choose MyID.

Federal

Two million credentials, live in three months.

A US federal transportation-security agency issues tamper-resistant FIPS 201 credentials to maritime workers with MyID CMS, combining central bureau production with self-service biometric activation across 160+ enrolment centres. Over 2 million cards and 8 million certificates issued, at peak throughput of 10,000 cards a day.

2M+
Credentials issued Tamper-resistant PIV cards in live production
8M+
Certificates managed Full issuance and lifecycle across 160+ centres
3 mo
Order to production FIPS201 / HSPD-12 go-live
Public Sector

Tens of thousands of credentials, managed across air-gapped national networks.

A national Ministry of Defence body modernised its PKI with MyID CMS and MyID SecureVault, issuing FIPS 201 credentials with Biometric Match-on-Card and CA-independent key storage across multiple separated networks. From defence to healthcare and education, public bodies rely on MyID to issue trusted identities that meet the strictest standards, even where there is no internet connection.

10,000s
Credentials managed Across multiple air-gapped networks
Match-on-card
Biometric assurance FIPS 201 PIV with on-card verification
Air-gap
Zero connectivity CA-independent key storage with SecureVault
Government

Passwordless smart-card login for a national government agency.

A German federal institute replaced password logon with PKI smart-card two-factor authentication using MyID CMS, deployed entirely on-premise against its existing Microsoft CA and Active Directory, with no cloud dependency and full self-service card recovery.

100%
On-premise No cloud dependency, air-gap capable
2FA
Smart card + PIN PKI logon across the agency workforce
AD
Native integration Microsoft CA and Active Directory
Enterprise

Secure, audited engineer access to every customer network.

A major international services company gave its field engineers phishing-resistant access to customer devices and systems with MyID CMS, automating certificate distribution straight to their smart cards and granting each engineer only the access they are currently authorised to hold. Existing smart cards and USB devices were reused, so roll-out caused minimal disruption. From services and finance to energy and technology, enterprises use MyID to secure their workforce without replacing what already works.

Zero
Soft certificates Certificates issued straight to smart cards
Auto
Certificate distribution Dynamic per-engineer authorisation and revocation
PKI
Smart card based Existing smart cards and USB devices reused
Financial Services

12,000+ bank staff on strong PKI, using the infrastructure they already had.

A leading European bank moved its entire workforce onto centrally-managed PKI two-factor authentication with MyID CMS, integrating through the Lifecycle API and reusing its existing Microsoft certificate authorities, HSMs and in-house card printing. Credentials are issued, replaced and revoked from one auditable platform across branches in multiple countries.

12K+
Employees secured Strong 2FA across all branches and countries
100%
2FA coverage Mandated centrally, PKI across the workforce
Existing
Infrastructure reused Existing CA, HSM and card printing retained
Credential Intelligence

Is your email already in criminal hands?

Check your email against the worlds largest breach database containing over 11 Billion breached credentials Enter a work email to find out instantly.

11B+
Stolen credentials
in our database
88%
Web application attacks
involve stolen credentials*
241 days
Avg. time to identify
and contain a breach**

* 88% of web application attacks involve stolen credentials - Verizon's 2025 DBIR

** 241 days average time to identify and contain a breach - IBM's Cost of a Data Breach Report 2025.

Password Exposure Check

Check an Email Address

See if this address appears in any confirmed data breach across our database of over 11 billion stolen credentials.