njokey
Products · Anchor V1 · Coming soon

Prove where work happened.

Anchor V1 is a hardware key in development that binds a person, their machine and their place — so sensitive work only happens where it's allowed to, and a stolen login opens nothing.

USB-C key FIDO2 / WebAuthn Continuous location
At a glanceDesign partner phase
Category
Zero-trust location & security key
Form factor
USB-C hardware key
Authentication
FIDO2 · WebAuthn · passkeys
Location
Continuous multi-signal attestation while connected
Access control
Presence-gated documents & systems
Management
Central console · SCIM provisioning · remote revocation
Host platforms
Windows · macOS (Linux planned)
Status
In development · onboarding design partners
Security architecture

Location becomes evidence, not a claim.

A password proves knowledge. A software check proves a plausible signal. Anchor V1 binds the machine, the identity and the place into one attestation that a host can't fake and a stolen credential can't replay.

01

Hardware root of trust

A secure element on the key holds credentials that can't be exported or cloned. Location and presence attestations are signed on-device, so what the server receives is cryptographic evidence — not a value the host could forge.

02

Key-to-machine binding

At enrollment the key and the workstation are paired and mutually attested. The bond is specific: the same key inserted into a different, unenrolled machine cannot assume the identity or unlock anchor-gated resources.

03

Continuous attestation

While connected, the key emits a signed presence-and-location heartbeat. Multi-signal verification (satellite-assisted position, network trust and device attestation) is fused into a confidence score your policy can reason about.

04

Policy evaluation at access

Every gated resource checks live presence and location against your policy at the moment of access — not a cached login from hours ago. In or out of policy is decided per open, per action.

05

Break-and-revoke

Unplugging, moving out of an approved region, or swapping the key breaks the session and flags it for review. A lost or stolen key is revoked centrally in seconds, and anything it gated stays sealed.

How it works

Plug in. Bind. Verify. Unlock.

01

Plug it in

Insert the key. The driver and Njokey agent install automatically on first use — no manual setup for the employee.

02

Bind laptop and key

The key and machine are cryptographically paired at enrollment. Neither can impersonate the other afterward.

03

Verify by policy

Continuous, scheduled or on-access verification — the admin decides per role and per data class.

04

Unlock what's gated

Sensitive documents and systems open only while the key is present and the location is in policy.

See it work

Present and in policy — or nothing opens.

Unplug the key, or move out of an approved place, and the sealed document stays sealed. Try it.

Try itSimulated · Anchor V1 design intent
Key present
Location in policy
Anchor-only document
Q3-financials.xlsx
Access granted

Unplugging ends the session instantly — a stolen login opens nothing

Verification modes

Match the assurance to the risk.

Not every role needs constant verification. Anchor V1 is designed to run in three modes, set centrally per role or per data class.

Highest assurance

Continuous

The key attests presence and location continuously while connected. The session ends the instant it's removed or leaves an approved region.

Best for

Always-on access to the most sensitive systems.

Balanced

Scheduled check-in

Re-verification at admin-set intervals — hourly, at shift start, or before each sensitive action — rather than a constant stream.

Best for

General regulated roles and hybrid teams.

Targeted

Presence-gated

Verification runs only when a flagged document, dataset or system is opened. The asset stays sealed without the key present.

Best for

Protecting specific files or datasets, not whole roles.

Technical specifications

Built to an enterprise bar.

Target specifications — design intent, subject to change before launch. This is a preview for evaluation, not a final datasheet.

Form factorUSB-C hardware key, keyring-sized
ConnectivityUSB-C; NFC tap (target)
Secure elementHardware root of trust, non-exportable keys
Auth protocolsFIDO2, WebAuthn, passkeys
Location signalsSatellite-assisted position, network trust, device attestation
Verification modesContinuous · scheduled check-in · presence-gated
Host platformsWindows, macOS at launch; Linux planned
ProvisioningSCIM, bulk enrollment, self-service pairing
ManagementCentral console, remote revocation, fleet status
Data handlingSigned verdict + attestation stored; no continuous movement trail
DurabilityWater- and crush-resistant (target)
Identity integrationSits behind existing SSO (SAML / OIDC)
Deployment & administration

Fits your stack, not the other way around.

Anchor V1 is designed to sit behind your existing identity provider and feed the Njokey policy engine — so it adds a place dimension without adding a console your team has to babysit.

Zero-touch provisioning

Enroll keys in bulk via SCIM or hand out self-service pairing. Employees plug in and go — no ticket, no IT visit.

Central policy console

Approved regions, verification modes and gated resources are set per role and per data class, in one place, and enforced locally on every key.

Fleet visibility

See key status across the workforce, spot dormant or offline keys, and revoke a lost or stolen unit in seconds.

One engine, one trail

Anchor feeds the same policy engine and signed audit trail as Verify and Compass — one source of truth for Finance, HR, Security and Legal.

Built for regulated work

Where a login from the wrong place is a problem.

Anchor V1 is aimed at the teams for whom software verification is necessary but not sufficient — where access to sensitive work has to be bound to a place in hardware.

Defence & export-controlled

ITAR, EAR and dual-use work that must provably stay on approved soil, with hardware-backed evidence per session.

Financial services

Market-access rules and PE-sensitive roles where a login from the wrong country is a reportable event.

Healthcare & life sciences

Regulated data whose access must be tied to a verified, permitted location — not just a credential.

Government & public sector

Sovereign, region-locked deployments where presence and place are conditions of access.

For the CISO

Zero trust gets a place dimension.

Identity keys answer who. Anchor V1 adds where — cryptographically bound to the machine, so a stolen credential in the wrong country opens nothing.

01Hardware-bound sessions
02Location as an access-control signal
03Signed, exportable evidence
For the data owner

Your most sensitive files, anchored.

Mark a document, dataset or system as anchor-only. Without the key present — and the location in policy — it simply doesn't open.

01Presence-gated documents
02Per-data-class policies
03Instant revocation by unplugging
Questions

Anchor V1, answered.

Not ready for hardware?

Start with Verify.

The same consent-based verification, in pure software — desktop and phone cryptographically paired, no procurement, no rollout project. Move to Anchor V1 when the data you protect demands hardware.

Explore Verify
In development — honestly
  • Anchor V1 is not yet shipping. Specifications on this page are design targets and will be confirmed at launch.
  • We describe what the device is designed to do — we don't claim security certifications we haven't earned yet.
  • Design partners get early hardware and shape the admin policy model. Join the waitlist and mention hardware.
Early access

Anchor work to a place.

Join the waitlist for early hardware, or start with Verify — pure software — today.