Prove where work happened.
Anchor V1 is a hardware key in development that binds a person, their machine and their place — so sensitive work only happens where it's allowed to, and a stolen login opens nothing.
- Category
- Zero-trust location & security key
- Form factor
- USB-C hardware key
- Authentication
- FIDO2 · WebAuthn · passkeys
- Location
- Continuous multi-signal attestation while connected
- Access control
- Presence-gated documents & systems
- Management
- Central console · SCIM provisioning · remote revocation
- Host platforms
- Windows · macOS (Linux planned)
- Status
- In development · onboarding design partners
Location becomes evidence, not a claim.
A password proves knowledge. A software check proves a plausible signal. Anchor V1 binds the machine, the identity and the place into one attestation that a host can't fake and a stolen credential can't replay.
Hardware root of trust
A secure element on the key holds credentials that can't be exported or cloned. Location and presence attestations are signed on-device, so what the server receives is cryptographic evidence — not a value the host could forge.
Key-to-machine binding
At enrollment the key and the workstation are paired and mutually attested. The bond is specific: the same key inserted into a different, unenrolled machine cannot assume the identity or unlock anchor-gated resources.
Continuous attestation
While connected, the key emits a signed presence-and-location heartbeat. Multi-signal verification (satellite-assisted position, network trust and device attestation) is fused into a confidence score your policy can reason about.
Policy evaluation at access
Every gated resource checks live presence and location against your policy at the moment of access — not a cached login from hours ago. In or out of policy is decided per open, per action.
Break-and-revoke
Unplugging, moving out of an approved region, or swapping the key breaks the session and flags it for review. A lost or stolen key is revoked centrally in seconds, and anything it gated stays sealed.
Plug in. Bind. Verify. Unlock.
Plug it in
Insert the key. The driver and Njokey agent install automatically on first use — no manual setup for the employee.
Bind laptop and key
The key and machine are cryptographically paired at enrollment. Neither can impersonate the other afterward.
Verify by policy
Continuous, scheduled or on-access verification — the admin decides per role and per data class.
Unlock what's gated
Sensitive documents and systems open only while the key is present and the location is in policy.
Present and in policy — or nothing opens.
Unplug the key, or move out of an approved place, and the sealed document stays sealed. Try it.
Unplugging ends the session instantly — a stolen login opens nothing
Match the assurance to the risk.
Not every role needs constant verification. Anchor V1 is designed to run in three modes, set centrally per role or per data class.
Continuous
The key attests presence and location continuously while connected. The session ends the instant it's removed or leaves an approved region.
Always-on access to the most sensitive systems.
Scheduled check-in
Re-verification at admin-set intervals — hourly, at shift start, or before each sensitive action — rather than a constant stream.
General regulated roles and hybrid teams.
Presence-gated
Verification runs only when a flagged document, dataset or system is opened. The asset stays sealed without the key present.
Protecting specific files or datasets, not whole roles.
Built to an enterprise bar.
Target specifications — design intent, subject to change before launch. This is a preview for evaluation, not a final datasheet.
Fits your stack, not the other way around.
Anchor V1 is designed to sit behind your existing identity provider and feed the Njokey policy engine — so it adds a place dimension without adding a console your team has to babysit.
Zero-touch provisioning
Enroll keys in bulk via SCIM or hand out self-service pairing. Employees plug in and go — no ticket, no IT visit.
Central policy console
Approved regions, verification modes and gated resources are set per role and per data class, in one place, and enforced locally on every key.
Fleet visibility
See key status across the workforce, spot dormant or offline keys, and revoke a lost or stolen unit in seconds.
One engine, one trail
Anchor feeds the same policy engine and signed audit trail as Verify and Compass — one source of truth for Finance, HR, Security and Legal.
Where a login from the wrong place is a problem.
Anchor V1 is aimed at the teams for whom software verification is necessary but not sufficient — where access to sensitive work has to be bound to a place in hardware.
Defence & export-controlled
ITAR, EAR and dual-use work that must provably stay on approved soil, with hardware-backed evidence per session.
Financial services
Market-access rules and PE-sensitive roles where a login from the wrong country is a reportable event.
Healthcare & life sciences
Regulated data whose access must be tied to a verified, permitted location — not just a credential.
Government & public sector
Sovereign, region-locked deployments where presence and place are conditions of access.
Zero trust gets a place dimension.
Identity keys answer who. Anchor V1 adds where — cryptographically bound to the machine, so a stolen credential in the wrong country opens nothing.
Your most sensitive files, anchored.
Mark a document, dataset or system as anchor-only. Without the key present — and the location in policy — it simply doesn't open.
Anchor V1, answered.
Start with Verify.
The same consent-based verification, in pure software — desktop and phone cryptographically paired, no procurement, no rollout project. Move to Anchor V1 when the data you protect demands hardware.
- Anchor V1 is not yet shipping. Specifications on this page are design targets and will be confirmed at launch.
- We describe what the device is designed to do — we don't claim security certifications we haven't earned yet.
- Design partners get early hardware and shape the admin policy model. Join the waitlist and mention hardware.
Anchor work to a place.
Join the waitlist for early hardware, or start with Verify — pure software — today.
