Human Verification
Deviceless MFA

Identity
Challenge Card

Prevent Hacker Attacks

Iranian Stryker attack exposes device-dependent MFA vulnerability. Deviceless MFA authentication closes every exception. It verifies the human not the device.

  • 100% workforce coverage
  • 100% of the Time
  • Cost 75% less than current MFA
Identity Challenge CardCard ID: B7eCB15
#ABCDE
1
INSTALL
POWDER
GARDEN
BRIDGE
MARBLE
SILVER
ROCKET
WINDOW
GUITAR
CASTLE
2
PLANET
ANCHOR
TURTLE
FOREST
BASKET
TEMPLE
VELVET
PIRATE
COTTON
DRAGON
3
CANYON
MAGNET
PUZZLE
ORANGE
VIOLET
BEACON
COPPER
JUNGLE
CARPET
MONKEY
4
HARBOR
KNIGHT
VISION
QUARTZ
JASPER
WILLOW
SUMMIT
STREAM
PARROT
FABRIC
5
MEADOW
COBALT
FABRIC
SPHINX
FALCON
BINARY
ORCHID
PRISM
LANTERN
OXYGEN
Three-Factor Challenge
Card Word
BASKET
+
PIN
1234
+
Emp ID
EMP-48291

Protecting the world's workforce since 1997

U.S. Air Force trusts Avatier Identity Challenge Card for deviceless MFA
U.S. Army trusts Avatier Identity Challenge Card for deviceless MFA
Bayer trusts Avatier Identity Challenge Card for deviceless authentication
BBC trusts Avatier Identity Challenge Card for deviceless MFA
Broward County trusts Avatier Identity Challenge Card for deviceless MFA
Build-A-Bear trusts Avatier Identity Challenge Card for deviceless authentication
The Cosmopolitan trusts Avatier Identity Challenge Card for deviceless MFA
DHL trusts Avatier Identity Challenge Card for deviceless MFA
Emerson trusts Avatier Identity Challenge Card for deviceless authentication
ESPN trusts Avatier Identity Challenge Card for deviceless MFA
Fox News trusts Avatier Identity Challenge Card for deviceless MFA
GSA trusts Avatier Identity Challenge Card for deviceless MFA
Humana trusts Avatier Identity Challenge Card for deviceless authentication
ING trusts Avatier Identity Challenge Card for deviceless MFA
Lockheed Martin trusts Avatier Identity Challenge Card for deviceless MFA
Marriott trusts Avatier Identity Challenge Card for deviceless MFA
MillerCoors trusts Avatier Identity Challenge Card for deviceless MFA
NASA trusts Avatier Identity Challenge Card for deviceless MFA
Nordstrom trusts Avatier Identity Challenge Card for deviceless MFA
Oscar Mayer trusts Avatier Identity Challenge Card for deviceless authentication
Pfizer trusts Avatier Identity Challenge Card for deviceless authentication
Rockwell Collins trusts Avatier Identity Challenge Card for deviceless MFA
SC Johnson trusts Avatier Identity Challenge Card for deviceless authentication
Sprint Canada trusts Avatier Identity Challenge Card for deviceless MFA
Starbucks trusts Avatier Identity Challenge Card for deviceless authentication
Steak 'n Shake trusts Avatier Identity Challenge Card for deviceless MFA
USA Today trusts Avatier Identity Challenge Card for deviceless MFA
Welch's trusts Avatier Identity Challenge Card for deviceless authentication
Vail Resorts trusts Avatier Identity Challenge Card for deviceless MFA
Visa trusts Avatier Identity Challenge Card for deviceless MFA
Volkswagen trusts Avatier Identity Challenge Card for deviceless MFA
Zep trusts Avatier Identity Challenge Card for deviceless MFA
U.S. Air Force trusts Avatier Identity Challenge Card for deviceless MFA
U.S. Army trusts Avatier Identity Challenge Card for deviceless MFA
Bayer trusts Avatier Identity Challenge Card for deviceless authentication
BBC trusts Avatier Identity Challenge Card for deviceless MFA
Broward County trusts Avatier Identity Challenge Card for deviceless MFA
Build-A-Bear trusts Avatier Identity Challenge Card for deviceless authentication
The Cosmopolitan trusts Avatier Identity Challenge Card for deviceless MFA
DHL trusts Avatier Identity Challenge Card for deviceless MFA
Emerson trusts Avatier Identity Challenge Card for deviceless authentication
ESPN trusts Avatier Identity Challenge Card for deviceless MFA
Fox News trusts Avatier Identity Challenge Card for deviceless MFA
GSA trusts Avatier Identity Challenge Card for deviceless MFA
Humana trusts Avatier Identity Challenge Card for deviceless authentication
ING trusts Avatier Identity Challenge Card for deviceless MFA
Lockheed Martin trusts Avatier Identity Challenge Card for deviceless MFA
Marriott trusts Avatier Identity Challenge Card for deviceless MFA
MillerCoors trusts Avatier Identity Challenge Card for deviceless MFA
NASA trusts Avatier Identity Challenge Card for deviceless MFA
Nordstrom trusts Avatier Identity Challenge Card for deviceless MFA
Oscar Mayer trusts Avatier Identity Challenge Card for deviceless authentication
Pfizer trusts Avatier Identity Challenge Card for deviceless authentication
Rockwell Collins trusts Avatier Identity Challenge Card for deviceless MFA
SC Johnson trusts Avatier Identity Challenge Card for deviceless authentication
Sprint Canada trusts Avatier Identity Challenge Card for deviceless MFA
Starbucks trusts Avatier Identity Challenge Card for deviceless authentication
Steak 'n Shake trusts Avatier Identity Challenge Card for deviceless MFA
USA Today trusts Avatier Identity Challenge Card for deviceless MFA
Welch's trusts Avatier Identity Challenge Card for deviceless authentication
Vail Resorts trusts Avatier Identity Challenge Card for deviceless MFA
Visa trusts Avatier Identity Challenge Card for deviceless MFA
Volkswagen trusts Avatier Identity Challenge Card for deviceless MFA
Zep trusts Avatier Identity Challenge Card for deviceless MFA
The Device Dependency Problem

Device-Dependent MFA
Can't Protect Workers
Who Don't Have a Device

Modern MFA has a blind spot. It assumes every worker has a managed device — and frontline workers often don't. No enrollment. No MFA. No real protection. That isn't a coverage gap; it's a design flaw that only Deviceless MFA can close.1,2,3

Microsoft IntuneWorkspace ONEJamfKandjiJumpCloudIvantiNone are deviceless

0%

of the global workforce is deskless

No device. No enrollment. No Conditional Access signal. Device-bound MFA can't reach them. Deviceless MFA can.

0

Industries

00%

Device MFA reach

Food Services & Restaurants
95% unprotected
5%
Hospitality & Lodging
95% unprotected
5%
Specialty & General Retail
93% unprotected
7%
Construction & Engineering
92% unprotected
8%
Agriculture & Food Production
90% unprotected
10% device reach
Transportation & Logistics
90% unprotected
10% device reach
Device MFA Reach
Unprotected — No Device

The Identity Challenge Card is Deviceless MFA.

A physical, air-gapped authentication factor — no phone, no laptop, no app, no network. The authenticator isthe card, not the device. That's what makes it deviceless: 100% workforce coverage, including the 70–95% your MDM will never touch.

For CFOs: every unprotected frontline worker is an uninsured breach vector. Deviceless MFA is how the math changes.

Sources

  1. [1] Emergence CapitalThe State of Technology for Deskless Workers (2020)
  2. [2] BCGMaking Work Work Better for Deskless Workers (Dec 2022)
  3. [3] Gartner75% of new mobile initiatives target frontline workers
  4. [4] Fortune2025 Fortune 500 List (June 2025)
Built for the Day Traditional MFA Fails

The Iranian Handala
Stryker Attack Is
Why Deviceless MFA Exists.

When Stryker's device-bound MFA went down during the Handala intrusion, recovery got slower, more expensive, and more dangerous. The Identity Challenge Card is Deviceless MFA— workforce verification restored in one day, without devices, connectivity, or help desk bottlenecks. That's the difference between an incident and a catastrophe.

The Difference

Device-Dependent MFA vs
Deviceless Authentication

Device-Dependent MFA

Identity Challenge Card

Depends on devices
Works without devices
Depends on identity systems
Works without identity systems
Fails during outages
Designed for outages
Takes months to years to deploy
Rapid workforce deployment in 1 day
Push Bombing target
Eliminates Push Fatigue
Depends on MDM (like Intune)
Works without MDM

This is your fallback identity layer.

How It Works

Three Factors. Zero Device Dependency.

Each authentication combines three independent factors — none of which require a phone, an app, or a network connection. That's what makes it Deviceless MFA.

01

Challenge Card Factor

A randomized grid response unique to each card. The system asks for a coordinate — only the person holding the physical card can answer. It's the factor that makes the card deviceless.

02

Private Knowledge Factor

A secure PIN known only to the user. Even if someone finds the card, they cannot authenticate without this second piece.

03

Identity Anchor Factor

An employee ID or account number that binds the challenge to a specific person — closing the loop between card, knowledge, and identity.

Try Deviceless MFA

See Deviceless Authentication. Try It.
Understand It in 60 Seconds.

This is
Deviceless MFA.
Try it.

A simple idea: a physical, air-gapped authenticator that keeps working when everything device-bound fails. No phone. No app. No network. That's Deviceless MFA.

No phone required

No app required

No network required

Works when device MFA fails

Deploys in one day

Zero help-desk bottleneck

Identity Challenge CardCard ID: B7eCB15
#ABCDE
1
INSTALL
POWDER
GARDEN
BRIDGE
MARBLE
SILVER
ROCKET
WINDOW
GUITAR
CASTLE
2
PLANET
ANCHOR
TURTLE
FOREST
BASKET
TEMPLE
VELVET
PIRATE
COTTON
DRAGON
3
CANYON
MAGNET
PUZZLE
ORANGE
VIOLET
BEACON
COPPER
JUNGLE
CARPET
MONKEY
4
HARBOR
KNIGHT
VISION
QUARTZ
JASPER
WILLOW
SUMMIT
STREAM
PARROT
FABRIC
5
MEADOW
COBALT
FABRIC
SPHINX
FALCON
BINARY
ORCHID
PRISM
LANTERN
OXYGEN
Three-Factor Challenge
Challenge Card Factor

Coordinate C2 TOP word

Private Knowledge Factor

Your PIN 1234

Identity Anchor Factor

Employee ID EMP-48291

How Three-Factor Works

· Challenge Card Factor — Find the coordinate (e.g., A1, B3) and enter the TOP or BOTTOM word

· Private Knowledge Factor — Read your 4-digit PIN, then enter it in the PIN field

· Identity Anchor Factor — Your Employee ID is verified automatically

· Both factors required — The word and PIN must both be correct to gain access

· New challenge — Click 'New Game' to randomize a fresh coordinate and PIN

Outcomes by Role

The Business Value of
Deviceless MFA Mapped to Who's Buying

Every persona has different success criteria. See the outcomes that matter to your role — from closing audit gaps to defining a new market category.

Auditors expect 100% MFA coverage — but device-dependent solutions leave 80% of your workforce unprotected. The Identity Challenge Card eliminates every exception. Deviceless MFA is how you get to 100% with no asterisks.

Eliminate the 80% MFA Gap with Deviceless MFA

Most MFA mandates require all users — but device-based solutions exclude factory floors, shared workstations, field staff, and contractors. The Challenge Card closes every exception, giving auditors complete coverage evidence with no asterisks.

NIST 800-63BZero TrustSOC 2 Type II

Resist Push Fatigue & Real-Time Phishing

Air-gapped authentication eliminates push-notification hijacking, SIM-swap, and real-time phishing attacks that defeat SMS and TOTP. The challenge/response is offline and unreplayable — no interception vector exists.

CISA MFA GuidanceEO 14028FedRAMP

Maintain Audit-Ability & Policy Enforcement

Card issuance, expiration, re-enrollment, and revocation are all logged and policy-enforced. Admins set expiry windows; users receive automated reminders. Every access event is traceable — no gaps in the audit trail.

SOXPCI-DSS v4ISO 27001

Ready to close your compliance gaps with Deviceless MFA?

See how the Identity Challenge Card — Deviceless MFA — satisfies auditors and protects every worker in days, not months.

Book a Deviceless MFA Demo
Deviceless MFA— Multilingual & Global

Built for Global Workforces

Challenge cards available in 29 languages for multilingual deployment across global workforces and customer-facing support environments.

Compliance-Ready Deviceless MFA

Deviceless MFA, Trusted in Regulated Environments

The Identity Challenge Card is Deviceless MFA engineered for regulated workloads: zero PII on the card, full lifecycle auditability, and an architecture that satisfies NIST 800-63B, SOC 2, PCI-DSS v4, and ISO 27001 on the first audit pass.

Privacy by Architecture

No PII on the card — nothing to breach

  • Zero personal information stored on the physical card
  • No name, no ID number, no user mapping printed or encoded
  • A lost card cannot be exploited without the separate PIN
  • Nothing to disclose under breach notification requirements
  • Deviceless MFA: privacy by design, not privacy by policy

Full Lifecycle Controls

Every card event is logged and policy-enforced

  • Card issuance, expiration, and revocation are fully auditable
  • Admin-configurable expiry windows with automated reminders
  • Service Desk use auto-expires the card immediately after use
  • Re-enrollment flows enforce policy before issuing replacements
  • Complete audit trail — every access event is traceable

Phishing-Resistant by Design

Air-gapped Deviceless MFA with no interception vector

  • Eliminates push-notification hijacking and SIM-swap attacks
  • Challenge/response is offline and unreplayable
  • No network dependency means no man-in-the-middle attack surface
  • Meets CISA phishing-resistant MFA guidance (EO 14028)
  • Satisfies NIST 800-63B verifier impersonation resistance
Deviceless MFA FAQs

Frequently Asked Questions

Everything you need to evaluate Deviceless MFA — by role, by risk, by question asked in the last procurement review.

Security posture & attack surface

What exactly is Deviceless MFA — and how is the Identity Challenge Card different from every other MFA?

Deviceless MFA is multi-factor authentication that works without a phone, an app, a hardware token, or a network connection. The Identity Challenge Card is the first production implementation: a printed grid of word pairs that a user looks up during login. When Stryker's device-bound MFA went down during the Iranian Handala intrusion, Deviceless MFA is the category that would have kept workforce verification running — one day to deploy, every worker covered, zero device dependency. Every FAQ below explains how it works, how it deploys, and how it satisfies auditors.

Is a printed card actually secure? A lost card means a compromised credential.

The card contains no personal data and no identity information. Without the PIN it is useless. A lost card is less dangerous than a lost phone — you can't SIM-swap paper. The card is revoked in seconds and replaced the same day. Cyber attackers cannot compromise paper. That is an architectural truth, not a tagline.

We already have MFA. Why does our existing solution leave a documented gap?

Authentication that works for 20% of your workforce does not protect your organization — it creates a documented 80% vulnerability. Every MFA exception you've written is a gap an attacker can map. Device-dependent MFA assumes devices, networks, and identity systems are available. During the Stryker attack, none of those assumptions held. Deviceless MFA is how you stop documenting 80% exceptions and start documenting 100% coverage.

How does this meet CMMC, HIPAA, PCI-DSS, and GDPR requirements?

Every major compliance framework requires authentication that works for every worker in every environment. Device-dependent MFA cannot deliver that — your exceptions are documented compliance risk. A governed Identity Challenge Card closes every exemption with immutable audit logs, policy-enforced expiration, and identity-verified re-enrollment. No personal data is processed by the auth mechanism — zero GDPR exposure.

What happens during an active cyberattack when identity systems are down?

That is exactly when this was built for. Nothing runs at authentication time — no server call, no network dependency, no identity provider. The card resolves locally. When everything else fails, the card still works. Your service desk can still verify users. Business operations can continue. That's what Deviceless MFA is built to do.

Can push bombing or replay attacks work against this?

No. There are no push notifications — so push fatigue attacks have no surface. Each coordinate value is one-time — used values are permanently burned and never reused. Replay attacks are structurally impossible. Air-gapped means no network attack surface exists.

See Where Deviceless MFA
Fits in Your Environment

No commitment · 30-min Deviceless MFA walkthrough · same-day response

Talk to the team behind the Identity Challenge Card — the first production Deviceless MFA.