The New York firm trying to make the password - and the attacks that ride on it - disappear.
Beyond Identity, Inc. — founded 2019, New York City. Passwordless, device-bound authentication built by the internet pioneers behind Netscape, SGI and @Home Network. Photograph: company logo mark.
The password turns 65 this decade, and it has aged badly. It gets phished, reused, guessed, leaked in bulk, and forwarded across the very networks it was meant to guard. Beyond Identity's founding argument is unusually blunt for a security company: you do not harden a weak link, you remove it. Instead of a secret you type, the company issues a cryptographic key that is created inside your device and never leaves it. There is no password on a server to steal, and no code to intercept.
Founded in 2019 by Thomas "TJ" Jermoluk, Jim Clark and Nelson Melo - two of them veterans of Netscape, Silicon Graphics and @Home Network - Beyond Identity set out to rebuild authentication from the silicon up. The pitch resonated with investors who had watched breach after breach begin with one stolen credential. By February 2022 the company had raised roughly $205 million and crossed into unicorn territory at a $1.1 billion valuation, backed by New Enterprise Associates, Koch Industries and Evolution Equity Partners.
Today the company, led by CEO Jasson Casey - a computer engineer with a Ph.D. and a national-security fellowship at George Mason University - describes its work as an "Identity Defense Platform." The phrasing matters. Beyond Identity is no longer selling only a passwordless login; it is selling the claim that it can tell you, deterministically, who is on the other end of a connection and whether their device can be trusted.
At its core, Beyond Identity binds a person's identity to a specific device using public-key cryptography. When you sign in, the device proves possession of a private key that never travels the network - the same class of assurance behind TLS and passkeys, packaged for enterprise access. That single design choice removes the shared secret attackers depend on.
The second half of the platform is device trust. The authenticator continuously checks the security posture of the machine - is it patched, encrypted, running the right controls - and can revoke access the moment a laptop drifts out of compliance. Access becomes a live state rather than a one-time gate, on managed and unmanaged devices alike.
Its customers are enterprises and mid-market firms in financial services, technology, healthcare, government and education. Publicly named users include Snowflake, Boomi, Cornell University, Monolithic Power Systems, Taulia and FireHydrant. The company sells to security and IT teams, not consumers.
The problems it targets are the ones that fill breach reports: phishing, credential theft, MFA-bypass and push-fatigue attacks, and - increasingly - AI impersonation. Each traces back to a system trusting something that can be faked. Beyond Identity's answer is to make the proof unforgeable.
Most authentication stacks ask a fuzzy question - "does this look like you?" - and score the answer. Beyond Identity aims for a hard yes or no: this exact device holds the right key, and here is its security state right now. That shift from probability to proof is the crux of how it positions against incumbents like Okta, Microsoft Entra, Ping Identity and Duo.
Passwordless, device-bound authentication using cryptographic passkeys across macOS, Windows, iOS and Android. Standards-based: OpenID Connect, SAML, X.509.
Continuous verification of device security posture on managed and unmanaged devices, granting or revoking access based on live health and compliance.
An identity-assurance plugin for Zoom and Microsoft Teams that certifies participants are authenticated humans on trusted devices (AAL3), with a visible verified badge.
The unifying Identity Defense Platform - adaptive, risk-based policies governing access across users, devices and AI agents, wired into SSO, MDM, EDR and SIEM.
Beyond Identity is a B2B SaaS business. It sells its cloud-native platform on subscription, typically priced per identity, and delivers the authenticator, device-trust engine and integrations as a managed service. Crucially, it is designed to sit alongside existing SSO, MDM and security tooling rather than rip and replace it - lowering the barrier to adoption inside large security stacks.
Third-party estimates put annual revenue around $37.8 million, a figure the company has not officially confirmed. With roughly 150 employees, it is a focused, mid-stage player rather than a sprawling platform vendor.
In the market map, Beyond Identity competes in identity and access management against Okta, Microsoft Entra ID, Ping Identity, Cisco's Duo, and hardware-key makers like Yubico, as well as passkey-forward challengers such as HYPR and Transmit Security. Its differentiator is the tight coupling of passwordless authentication with continuous device trust.
Its newest frontier - deepfake defense with RealityCheck - places it in an emerging category alongside a wave of AI-impersonation detection tools. As AI agents proliferate as a new class of network "user," Beyond Identity's move to secure non-human identities may prove as consequential as killing the password.
Veteran of Silicon Graphics and @Home Network; a driving force behind the company's founding vision.
Internet pioneer and co-founder of Netscape and Silicon Graphics.
Engineer and technical co-founder behind the passwordless architecture.
Ph.D. computer engineer, ex-CTO at SecurityScorecard and VP Engineering at IronNet; national-security fellow at GMU.
Jermoluk, Clark and Melo start the company to eliminate passwords with device-bound cryptographic credentials.
Exits stealth with its passwordless authenticator and raises $75M led by NEA and Koch Disruptive Technologies.
Adds continuous device-security verification and expands across regulated industries.
Closes a $100M Series C in February, reaching unicorn status with $205M total raised.
Releases an identity-assurance plugin for Zoom and Teams to defend against deepfakes and AI impersonation.
Extends the Identity Defense Platform to AI agents and non-human identities amid rising AI-impersonation threats.
Two co-founders helped build Netscape - the browser that opened the web - and now work to secure it.
The product's whole premise is subtraction: it makes login safer by removing the password entirely.
RealityCheck puts a literal "verified" badge on your face during a video call.
CEO Jasson Casey holds a Ph.D. and is a national-security fellow at George Mason University.
The authenticator works on unmanaged personal devices using cryptographic keys - no authenticator app required.
It provides an identity security platform that eliminates passwords by binding authentication to a cryptographic key stored on a user's device, then continuously verifies the device's security posture to grant or revoke access.
Traditional MFA relies on shared secrets like passwords and OTP codes that can be phished or approved by mistake. Beyond Identity uses device-bound cryptographic credentials with no shared secret, making authentication phishing-resistant and deterministic.
RealityCheck is a plugin for Zoom and Microsoft Teams that certifies each participant is an authenticated human on a trusted device (AAL3) and displays a verified badge, helping organizations defend against deepfakes and AI impersonation on calls.
It was founded in 2019 by TJ Jermoluk, Jim Clark and Nelson Melo, and is headquartered in New York City. Jasson Casey serves as CEO.
The company has raised approximately $205M in total, including a $75M Series B in 2020 and a $100M Series C in February 2022 that gave it a $1.1B valuation.