Secfense
Secfense is a Kraków- and San Francisco-based cybersecurity company whose agentless reverse-proxy User Access Security Broker injects FIDO2 passkeys and phishing-resistant MFA into any application without code changes, serving regulated enterprises in banking, insurance, government, and healthcare across Central Europe.
- Company typePrivate
- Founded2018
- HeadquartersKraków, Poland
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Secfense does
Secfense is a Kraków-based cybersecurity company (founded March 2018, with a US entity in San Francisco) that builds a User Access Security Broker (UASB) — an agentless, no-code reverse-proxy layer that intercepts authentication traffic and injects FIDO2-based multi-factor authentication or passkeys into any application without modifying source code. The platform supports any identity provider (Microsoft Entra ID, Okta, Ping Identity, Active Directory, RADIUS, LDAP), authenticates against standards (SAML, OIDC, OAuth 2.0, FIDO2/WebAuthn), and works across web apps, VPN, Citrix VDI, and legacy systems. Complementary products extend the core broker: Secfense IdP (lightweight identity provider acting as an Identity Dispatcher), Passkeys for Enterprises (FIDO2 credential management), Secfense Ghost (invisible VPN/remote access protection launched August 2025), Secfense Authenticator (mobile push app), Extended Windows Hello, and Passkey-Based Password Recovery. A U.S. patent (No. 12273332, granted April 2025, valid until 2043) protects the core method.
The company targets regulated enterprises in financial services, insurance, government, healthcare, and critical infrastructure, with documented deployments including a leading European bank (150+ legacy applications in 8 weeks, 85% phishing reduction), a leading European insurer (8,000+ agents activated in two weeks, MFA available to 5M+ customers), SALTUS Insurance, Sandis/WAGAS (5,000+ users across 27 applications under DORA/KNF), UNIQA, two Polish ministries, the Polish Geological Institute, a 5,500-employee university hospital, PKP Intercity, and BS Brodnica. A direct partnership with Yubico provides hardware security key integration, and FIDO Alliance membership (since June 2022) provides standards-body positioning.
Secfense makes money through annual or multi-year subscription licensing of the UASB platform (deployable as cloud SaaS or self-managed on-premises), enterprise perpetual or subscription licenses for the broader suite, and professional services for integration and rollout. Pricing is quote-based and not publicly disclosed; the enterprise sales motion targets CISOs, IAM architects, and security leaders in regulated industries with proof-of-concept pilots and direct contract negotiations. Distribution combines direct enterprise field sales (Kraków and San Francisco) with a partner channel (Yubico, system integrators) and event-led demand generation (webinars, insurance forums, FIDO Alliance events).
Secfense firmographics
Firmographics- Name
- Secfense
- Legal name
- Secfense Inc.
- Website
- https://secfense.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Secfense is a Kraków- and San Francisco-based cybersecurity company whose agentless reverse-proxy User Access Security Broker injects FIDO2 passkeys and phishing-resistant MFA into any application without code changes, serving regulated enterprises in banking, insurance, government, and healthcare across Central Europe.
- Ownership category
- akta.pro rank
Where Secfense is headquartered
LocationHeadquarters
- HQ city
- Kraków
- HQ country
- Poland
- HQ region
- Europe
Offices2 records
Markets served
Secfense business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Licensing: Annual or multi-year subscription licensing for the User Access Security Broker (UASB) platform. Deployable as cloud SaaS or self-managed on-premises solution.
- Enterprise Software Licenses: Perpetual or subscription licenses for the Secfense Suite covering User Access Security Broker, Secfense IdP, and related components.
- Professional Services: Implementation and deployment services for enterprise customers requiring assistance with integration, configuration, and rollout support.
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
Secfense product offering
Product offeringCore offering
Secfense provides a User Access Security Broker (UASB), a reverse-proxy-based platform that adds phishing-resistant multi-factor authentication and FIDO2 passkey support to any web, VPN, VDI, or legacy application without code changes. The portfolio includes the Secfense IdP lightweight identity dispatcher, Passkeys for Enterprises, Secfense Ghost for invisible remote access, and a Secfense Authenticator mobile app, sold primarily to regulated enterprises in banking, insurance, healthcare, government, and critical infrastructure.
Product overview
Secfense is a cybersecurity company offering a platform-plus-modules architecture centered on the User Access Security Broker (UASB), a reverse proxy that injects multi-factor authentication and passkeys into any application without code changes. The core platform is complemented by Secfense IdP (lightweight identity provider for passwordless authentication), Passkeys for Enterprises (FIDO2 credential management), and Secfense Ghost (invisible VPN protection). The platform addresses enterprise use cases including Passwordless IAM for workforce, Passwordless CIAM for customers, Legacy App Protection, Phishing-Resistant MFA, Secure Remote Access, and Regulatory Compliance. The solution supports various authentication methods including FIDO2/WebAuthn passkeys, TOTP, SMS, email, RADIUS, and hardware keys, and integrates with existing IdPs like Microsoft Entra ID, Okta, and Active Directory.
Differentiator
Problem solved
Functional benefit
Brands
- User Access Security Broker (UASB): Lightweight layer that adds passkeys and FIDO2-based MFA to any application or system without code changes
- Secfense IdP
- Passkeys for Enterprises
- Secfense Ghost
- Secfense Authenticator
Products and services
- User Access Security Broker (UASB) Core reverse-proxy platform that brokers strong authentication and FIDO2 passkeys in front of any application—web, VPN, VDI, or legacy—without code changes or replacement of the existing identity provider. Designed for CISOs, IAM architects, and IT security teams at regulated enterprises that need to roll out phishing-resistant MFA across large, heterogeneous application estates.
- Secfense IdP Lightweight identity provider / identity dispatcher that brokers identity to applications without replacing existing authentication stacks. For organizations that want passkey-grade MFA without ripping out their current IAM/IdP investments.
- Passkeys for Enterprises FIDO2 / WebAuthn passkey enablement layer that delivers phishing-resistant, passwordless login across the application estate, supporting hardware keys and platform passkeys. Targeted at enterprises rolling out passkeys to employees, agents, and customers.
- Secfense Ghost Invisible remote access solution that hides VPN infrastructure and remote access endpoints from the public Internet. Provides secure access to corporate applications, desktops, and the company network without exposing VPN addresses to attackers.
- Secfense Authenticator Mobile authenticator app for iOS and Android that pairs with the Secfense platform to deliver passkey-based and TOTP authentication for end users, including employees, agents, and customer identities.
Quantifiable outcome
- 85% reduction in phishing incidents within one month at Leading European Bank
- +7 more outcomes
Companies that use Secfense
Customer profileNamed customers14 records
Segments6 records
Ideal customer profiles3 records
Secfense technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration17 records
Feature4 records
Secfense partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered major customer, regulatory and core.
- UNIQAmajor customerOne of Central and Eastern Europe's largest insurers with 30+ years presence in Polish market. Partnership focuses on deploying advanced digital protection measures strengthening UNIQA's position in digital security.
- Polish Financial Supervision Authority (UKNF)regulatoryRegulatory recommendation body for Polish financial sector. Recommended FIDO-based multi-factor authentication mechanisms, validating Secfense's approach to financial sector security.
- YubicocoreStrategic collaboration to make modern, hardware-based MFA easy to deploy across all organizations. Yubico provides hardware security keys (YubiKey) integrated with Secfense User Access Security Broker for phishing-resistant authentication. Marcin Majchrzak, Regional Sales Manager DACH & CEE at Yubico, quoted in partner program.
- FIDO AlliancecoreIndustry alliance membership alongside Apple, Amazon, Meta, and other leaders to accelerate move toward passwordless world. Secfense recognized in FIDO Alliance Passkey Pledge update. Contributes to FIDO2/WebAuthn standards development and adoption.
Scale indicators12 records
Recent moves6 records
Expansion highlights6 records
Secfense competitors and assessment
Company assessmentDirect peers
- Transmit Security: Transmit Security provides identity and authentication orchestration, including passwordless and MFA capabilities, for large enterprises. Comparable to Secfense in serving regulated industries with modern authentication, though with a broader identity platform scope.
- HYPR: HYPR provides passwordless multi-factor authentication for enterprise workforce and customers using FIDO2 standards. Direct comparable to Secfense's no-code, phishing-resistant MFA platform approach, though HYPR focuses more on workforce MFA while Secfense emphasizes the reverse-proxy/no-code integration angle.
- Beyond Identity: Beyond Identity offers a passwordless identity platform built on FIDO2 that combines device-bound credentials with risk-based authentication. Closely comparable to Secfense in targeting phishing-resistant authentication for regulated enterprises and replacing legacy MFA.
Broad incumbents
- Microsoft (Entra ID): Microsoft Entra ID (formerly Azure AD) is the dominant cloud identity platform with built-in MFA, Conditional Access, and passwordless capabilities. Native integration partner for Secfense and the largest potential competitive threat given enterprise market reach.
- Okta: Okta is a leading identity and access management platform with workforce MFA, SSO, and customer identity products. Already integrated with Secfense as an IdP, Okta represents both a partner and the broadest incumbent threat if it extends phishing-resistant MFA natively.
- ForgeRock: ForgeRock (now part of Ping Identity) provides enterprise identity and access management with strong MFA and passwordless features. Comparable to Secfense in serving regulated industries but with a much broader IAM platform footprint.
- Ping Identity: Ping Identity provides enterprise identity, SSO, and authentication solutions including MFA and passwordless options. Direct IdP integration partner for Secfense; competitor in regulated enterprise authentication, though broader in scope.
- Cisco Duo: Cisco Duo provides multi-factor authentication and zero trust security for enterprise workforce access. Comparable in MFA use case but bundled into Cisco's broader security portfolio, contrasting with Secfense's standalone no-code platform focus.
Others
- Yubico: Yubico is the leading provider of hardware security keys (YubiKey) for FIDO2 authentication. Strategic technology and channel partner of Secfense — they sell complementary hardware authenticators rather than competing software — making them an ecosystem ally rather than direct competitor.
Emerging players
- Keyless: Keyless offers privacy-preserving biometric authentication for workforce and customer use cases. Comparable to Secfense in the passwordless/FIDO2 space but with a focus on biometric-centric authentication rather than Secfense's reverse-proxy legacy-app layer.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Secfense compliance and trust
Trust signalCompliance9 records
Secfense financial estimates
Financial estimateRevenue estimate
Valuation estimate
Secfense leadership team
Management profileNumber of profiles
Profiles7 records
Secfense funding detail
Funding detailFunding overview
Funding rounds3 records
Investors5 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Secfense M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Secfense
What does Secfense do?
Secfense provides a User Access Security Broker (UASB), a reverse-proxy-based platform that adds phishing-resistant multi-factor authentication and FIDO2 passkey support to any web, VPN, VDI, or legacy application without code changes. The portfolio includes the Secfense IdP lightweight identity dispatcher, Passkeys for Enterprises, Secfense Ghost for invisible remote access, and a Secfense Authenticator mobile app, sold primarily to regulated enterprises in banking, insurance, healthcare, government, and critical infrastructure.
Is Secfense a public or private company?
Secfense is a private company. It is classified as venture growth investor backed and is currently operating.
When was Secfense founded?
Secfense was founded in 2018. It employs 1 to 10 people.
Where is Secfense based?
Secfense is headquartered in Kraków, Poland, in the Europe region.
How does Secfense make money?
Three revenue lines are on record. Software Licensing is the primary driver. The others are enterprise Software Licenses and professional Services.
Who are Secfense's main competitors?
Direct peers on record are Transmit Security, HYPR and Beyond Identity. Broad incumbents are Microsoft (Entra ID), Okta, ForgeRock, Ping Identity and Cisco Duo. Yubico is listed as an others. Keyless is listed as an emerging player.
Does Secfense have an API?
Yes. Secfense exposes a full REST API for automation and customization, enabling organizations to automate and customize the solution for specific needs. The API integrates with existing systems and workflows. All events are saved locally and can be sent to SIEM using the open remote syslog protocol. Developer documentation is at docs.secfense.com.