Accessible cybersecurity

If using it costs you your privacy, it isn't accessible

Someone who can't read a CAPTCHA asks for help. Someone who can't type their password dictates it to another person. Every accessibility barrier left unsolved ends up as a security hole.

Data

Our key differentiator

LOCAL Local by default

Whatever can be resolved inside the device is resolved inside the device.

This is not an ideological stance: the less data that leaves, the less surface there is to protect and the less we have to ask people to trust us.

It is also what lets us in where other tools cannot go. In a health centre, a law firm or a public administration, the conversation does not start with price: it starts with what leaves the machine. If the gesture and the context never leave, there is nothing to negotiate.

When something does have to leave the device, we say so explicitly and explain what for. The formal detail will be in the privacy policy.

How we approach it

Two pieces that didn't exist

  • Screen and audio

    Secure mode

    Hidden screen and private audio. It lets the device be used in a waiting room, an open-plan office or on public transport without sensitive information being visible — or audible — to whoever is next to you. For many people, today's alternative is not doing the task until they get home.

  • Human verification

    Gesture-based CAPTCHA

    Visual CAPTCHAs shut out millions of people with visual impairments, and audio alternatives break down with background noise or a screen reader in the mix. Our CAPTCHA verifies that there's a person there from the way they gesture, which is hard to automate and requires seeing nothing.

Open framework

OSCF Handbook Public draft v0.1

The Open Source Cybersecurity Framework is our open framework for accessible cybersecurity. It documents AGVS, the Accessible Gesture Verification Standard, and is published in the open with its source and change history visible.

We didn't write it as decoration. An accessible verification standard is only worth anything if other people can read it, implement it and argue with it — and for that it has to be public before it's finished.

  • Layer 1

    Principles and scope

    What AGVS solves, and what it deliberately leaves out.

  • Layer 2

    Threat model

    Replay of recorded gestures, automation, shoulder surfing and session abuse.

  • Layer 3

    Interaction model

    Rules for making the verification challenge usable multimodally, not just by looking.

  • Layer 4

    Conformance model

    Three levels — A, AA and AAA — so an implementation can show how far it goes.

Read the OSCF Handbook (opens in a new tab) Published openly on GitLab Pages, with the repository and change history available.

Standards

What we're aligned with

WCAG 2.2 level AA
Web content accessibility guidelines. They apply to the product and to this site.
ISO/IEC 27701
Privacy information management.
ISO 27001
Information security management.

We word this precisely, on purpose

AIntegra is not certified against any of these standards yet. The product is designed to meet them and we are working towards certification. When we hold a certificate, we'll publish it with its number and its certification body. Until then, putting it any other way would be selling you something we aren't.

Have a security requirement to meet?

If you're evaluating a public procurement or an internal rollout, tell us what's required of you and we'll tell you exactly where we stand.

Talk to us