FAQs
Search The Question
General
-
How do I contact support?
Please contact us at support@traitware.com.
-
What is island hopping?
Bad actors target large organizations indirectly, gaining access first to smaller, more vulnerable partner company networks to eventually infiltrate the larger company.
Find out more about Island hopping here:
-
How can I login to Windows (offline and online)?
Here is how you can Login to Windows:
-
How do you protect the information sent from the TraitWare mobile device App to the authentication server?
We require certificate pinning between the phone app and the authentication server. [Pinning is the process of associating a host with their expected X509 certificate or public key.]
Once a certificate or public key is known or seen by a host, the certificate or public key is associated or ‘pinned’ to the host.
The integrity of data sent from the phone app to the authentication server is verified with a digital signature for the data packets sent over the encrypted connection. [A digital signature is an authentication mechanism that enables the creator of the message to attach a code that acts as a signature.]
-
What are the two+ factors in Passwordless MFA?
We deliver up to five factors of authentication, with four of them being completely transparent to the user:
- Physical possession of the mobile device that the TraitWare authenticator app is installed on. We use patented behavioral metrics to create a rotating ‘device signature’ that locks out the user if the device is tampered with (through jail-breaking/rooting, malware, etc.)
- FaceID or another user biometric of equivalent security. We only use device-native APIs, ensuring the biometric is an algorithmic representation and never leaves the device.
- A non-replayable, time-based login code (delivered through a QR).
- The physical location of the mobile device. Authentication can be restricted to a geographic boundary and will fail once the user leaves the permitted area.
- A unique ‘Image Pin is chosen by the user as a knowledge factor. Use of a pin is reserved for cases when biometrics are unavailable or must be paired with a second factor for extra security.
-
Does the TraitWare solution require SSO?
We use auth standards of SAML 2.0, OIDC, and OATH along with a Windows agent and a PAM module for integration to applications, Windows endpoints, and for Linux SSH/SFTP. This allows us to either sit in front of an existing IAM (SSO) solution or act as the IDP. We can also go to the service provider directly.
SSO is not required nor is an AD/AAD server. What we do require is for an auth standard to be in place or the ability to install the Windows agent or Linux PAM.
-
Does TraitWare support event-based or time-based MFA?
We use a different methodology that delivers up to 5 factors of authentication per login request, of which 4 are transparent to the user. One of the factors is a rotating key; another is an OTP that can only be used from the authenticator with its device-bound crypto. So we use both an OTP and a rotating key for each event. We are also able to limit access based on geolocation at the time of the authentication event.
-
How secure is the TraitWare authentication system?
To secure each individual’s identity TraitWare utilizes
1) the user’s mobile device equipped with the TraitWare Mobile App, and
2) the cloud-hosted TraitWare Authentication Server.
Traitware’s authentication is incredibly effective against malicious attacks and identity theft by a magnitude greater than conventional username and password systems.
-
Is TraitWare supported on both iOS and Android?
TraitWare is supported on both iOS and Android, Yes.
You can download the TraitWare authentication app with iOS (10.0+) and Android (6.0+).
-
Does my 30-day trial period start when I initially sign up for my TraitWare account, or do I get 30 days for each customer I add?
Your 30-day TraitWare account trial starts when you sign up for your account. Your account customers are all associated with the initial account signup, and therefore will not be given their own 30-day trials.
Users
-
How to add users?
Users can be added manually, imported using CSV, or synced using Microsoft Entra GraphAPI.
To manually add a user:
- Select Create User from the Users page. Mobile Phone is not required
- Select Save Changes
- To Import Users, select the button on the Users page
- Paste users in the appropriate format and select Preview
- Select Submit Users if it looks correct
- For User Sync, you will need information from Microsoft Azure complete this step.
- Once the information is inputted, users will be synced over based on the allowed groups.
- If you are using Azure Graph API, you can choose to sync all users in the Azure AD, or groups.
To add a user in person:
- User Registration can be done in Person.
- Navigate to the User to be added. Select User
- Navigate to the Devices tab
- If there is no device, select Reset Device
- Select QR Code Registration
- Scan Registration QR with user’s device
Find more information and a videos here:
-
What is Face verification and how can it help MFA?
Here is what Face verification is and how it can help MFA:
-
How to enable an alias user (user perspective)?
Here is how you can enable an alias user from the user perspective:
-
How do I add Photoauth?
Here is how you add Photoauth:
- Helpdesk : TraitWare Support (freshdesk.com) (mobile device)
- Helpdesk : TraitWare Support (freshdesk.com) (PC/ external device)
-
How do I login to a Web application?
Here is how you Login to a Web application:
-
How do I add a User account?
Here is how you add a user account:
Admin persona
-
How does Enterprise recovery work?
The TaitWare Console allows Account and Customer Owners (see Owners documentation) to provision Recovery Users and Paper Keys.
Owners may provision recovery users and paper keys for any Accounts or Customers that they own. Anybody who knows this paper key, has access to the recovery email, and is able to provide identity proofing to TraitWare support can utilize this process to provision a new Owner without access to an Owner’s device and device credentials. With this in mind, protect these secrets the same way you would protect a phone that automatically unlocks.
TraitWare strongly suggests provisioning multiple owners for any Account or Customer. This recovery process is intended to only be used as a final protection against Account or Customer access loss, in cases where all owners simultaneously lose access to their devices.
Find out how Enterprise recovery works here:
-
How to create an alias user (admin persona)?
- Navigate to the Applications tab in the TraitWare console. Click on the blue button to add application
- Select Windows 10/11 MFA, a new page will appear
- Fill out the section under Application Name, select Save Changes on the bottom right
- Copy the Client ID and Client Secret
- Enable the Windows 10 application for newly-created alias user
- Ensure that everyone using the alias user is enabled for the same application
- Navigate to the tab in the TraitWare console called Alias Users. Click on the blue button to add an alias user
- Name the mapping and select the alias user. When finished click submit
- Click on the newly created Mapping Name
- To add users for the alias, select Manage Users
- Name the mapping and select the alias user. When finished click submit
- Click on the newly created Mapping Name
- To add users for the alias, select Manage Users
- Select desired users. When finished click Close, the newly added accounts should now be seen on the alias user screen
- Select the Approved Applications tab. To add applications, select Manage Applications
- Select desired applications and when finished click Close
- The application is now shared via the alias user to other users
- Select desired users. When finished click Close, the newly added accounts should now be seen on the alias user screen
- Select the Approved Applications tab. To add applications, select Manage Applications
- Select desired applications and when finished click Close
- The application is now shared via the alias user to other users
Find out more here:
-
How to enable an alias user (admin perspective)?
- In the TraitWare console, navigate to Customer Settings in the bottom left of the page
- Select Enable Alias User
- Add a name for the alias user, there is the option to add a logo if desired. Once completed click Save Changes in the bottom right corner
Find out more here:
-
Requiring 3-factor authentication
- By default, only one type of authentication is required (biometric or PhotoAuth)
- If you desire a higher level of security, 3-Factor Authentication (biometric and PhotoAuth) may be turned on for users
- Note that this is recommended for admin users with higher accesses
- 3-Factor can be applied to new or existing users
- **Randomize Photo Authentication is recommended for highest security measures
-
How to troubleshoot if a user can’t sign in?
- If there is a message that the QR is not valid, please restart the TraitWare application. A session will timeout after 5 minutes of inactivity. If screen timeout is longer than 5 minutes, session will timeout without user knowledge
- QR code not showing on browser – please see list of supported browsers:
- Chrome (recommended)
- Firefox (recommended)
- Safari
- Microsoft Edge
- Failed Sign-In, please check the following:
- Make sure that connection is stable
- Check that account is enabled
- Ensure no change to biometrics or master PIN
- If users opt for PhotoAuth, make sure that the sequence is entered correctly
- If issues continue, please contact the account admin
- If users receive an “Unexpected Error” when using TraitWare, please make sure that the connection is stable. If this error continues, exit out of the TraitWare app and try again
- Biometric or PIN change. Biometric or master PIN change will lock the TraitWare accounts on the device. These accounts will need to be unlocked by an administrator
Find more information here:
-
How to reset to many failed attempts?
A user may get a failed authentication attempt by entering the wrong PhotoAuth sequence, if their device traits have changed too much, or in some cases (particularly with Samsung) on device update.
- Resetting Failed Login attempts will solve issues for a user who has forgotten a PhotoAuth sequence
- Resetting Session Traits will solve issues for a user who has traits which have changed too much (this may sometimes solve issues after a device update)
-
How to create an application?
First create a signing key for your application (SAML apps).
- Click Signing Keys under the Applications menu.
- Select Generate new Key Pair.
- Enter a Display Name.
- Select the lifetime of time you prefer for your key. NOTE: Owners will be notified by email of pending key expirations. The other options are fixed.
- Select Generate Key.
-
How to add a new device?
- If a user loses or upgrades their device, the old device will need to be Deleted before you can Add a New Device
- Note that if they are using a temporary phone, this step will still need to be completed. Only one device can be assigned to a user for security purposes
- Once a new device is added, you will be able to Register the user
Account Registration
-
I got an error message when trying to complete registration. What could this mean?
If you receive an error during registration, there are few steps to complete to make sure that there is not an issue.
- Make sure you are using a valid registration code
- Registration codes typically expire 24 hours after your registration email is sent
- Make sure that your device is on the approved list
- We do not support some older operating systems as they don’t provide the security we require
- Make sure that your session hasn’t timed out
- If you are registering your device and don’t complete it within 5 minutes, it will break the app. This includes choosing your authentication method, and trying to change the current photo set for using PhotoAuth
- Make sure that you have a stable internet connection
- If your wifi or cellular signal are weak, you may not be able to complete the communication to TraitWare.
- Make sure you are using a valid registration code
-
I was denied access when scanning the QR code during account activation. What should I do now?
Please make sure that you have selected ‘QR Scan’ from the options at the bottom menu within your mobile app. If you try to use ‘Login with QR Code’, it will not work.
-
I am activating my TraitWare account, and I have sent an activation email to my email address, but I haven’t received any emails. What should I do?
If you have waited a few minutes, and checked your spam folder, and you still have nothing, select resend email from the same screen as before. If you do not receive an email still, please contact support@traitware.com.
Account Recovery
-
How do I recover my account if I lose or replace my phone?
How do I recover my account if I lose or replace my phone?
If you have lost or replaced your phone and are the only account owner, please contact us at support@traitware.com to request a new activation code. If you have another Account Owner, please ask them to sign in and choose Resend Activation Email under your user row.
Marketing and Sales
-
What is Phishing resistant MFA?
We realize the reluctance to adopt MFA across the enterprise is still there, despite words from experts and leaders. People seem to think they’re not at risk, or that MFA is too difficult. We’re here to tell you that TraitWare is simple (from deployment to login) and cost-effective, not to mention built using the highest industry standards for security.
-
What does login in 3-touches mean?
Here you can find a video on what login in 3-touches is:
-
Comparison between TraitWare and competitors or other login technologies
There are other companies who also promote MFA. However, TraitWare is the only one that has Passwordless MFA.
See how TraitWare works in comparison to other companies here:
-
How to strengthen cybersecurity against Ransomware?
These days you hear about Ransomware attacks often. It is important to be cyber secure against all form of cyberattacks including Ransomware attacks.
Read here for more information about cybersecurity against Ransomware attacks:
-
How to make MFA adoption easy?
Multifactor authentication (MFA) is a must for enterprises to ensure data security in the face of both new attacks and persistent older ones that are constantly being fine-tuned by cybercriminals. It offers multiple layers of security to your login processes through multiple means of authentication.
Find out more on how to adopt MFA:
-
Why should Healthcare invest into MFA?
Multi-factor Authentication is essential in Healthcare. Just this year Change Healthcare was hacked and personal data of many were stolen. This could have been prevented with Passwordless MFA like we have.
Here is some more information about MFA in Healthcare:
-
What is real Passwordless MFA?
In light of the sharp rise in cyber attacks worldwide – from ransomware to phishing scams to man-in-the-middle attacks – we’ve been told by the likes of Microsoft, countless cybersecurity experts, and even the President of the United States, that it’s time to take cybersecurity seriously in every enterprise … that it’s time that we implement Zero Trust Architecture and Multi-Factor Authentication (MFA) to secure our company valuables – and protect our identities.
Read more about real Passwordless MFA:
-
What is account take over (ATO)?
Account takeover is real and potentially crippling. Especially if you run a business of any size, I encourage you to take it seriously. Deploy Passwordless MFA plus Single Sign-On for simpler, more secure access to all your accounts.
Here is some more information about ATO:
-
Why I shouldn’t store passwords in my browser? It’s Free!
No one likes the Password.
Clunky, frustrating, and by now, we all know they’re not particularly secure, as almost daily we hear news of cyberattacks with compromised user credentials as the root cause.
But until they go away, there is a proper way to manage them.
Find the proper way here:
-
MFA and cybersecurity
Today, cyber insurance is difficult for most companies to navigate. Legacy cybersecurity solutions do not often meet today’s criteria.
In order to ensure you’re ready to apply for cyber insurance, you’ll need to be sure you meet the requirements.
All the needed requirements and more information can be found here:
-
How does Zero Trust support MFA?
Multifactor authentication (MFA) is an authentication method that requires from users two (as in 2-factor authentication) or more information that fall under either of these four categories: knowledge (e.g., PIN), possession (token, USB key, etc.), inherence (biometrics—e.g., fingerprint, voice, etc.), and location (determined through GPS tracking). Options to increase the number of factors required to authenticate identity makes multifactor authentication a logical core value for the zero trust model.
-
Is it ‘Passwordless’ or merely a ‘Passwordless experience’?
Real Passwordless MFA is here.
TraitWare® provides Real Passwordless MFA plus Single Sign-On (SSO) for True Zero Trust Access™. Simple Secure Login in Three Touches. TraitWare does what most MFA solutions don’t: It enables MFA right from account creation. MFA is built-in to the technology and verifies user identity without a password, leveraging the biometric reader of a mobile device the user already carries (no expensive hardware or Keys to purchase), as well as opaque behavioral biometrics in real-time. Ultimately, TraitWare ties the USER to the login, providing higher levels of authentication assurance through Real Passwordless MFA™ built with True Zero Trust Architecture.
Read more about Real Passwordless MFA here:
Pricing and Payments
-
What kind of Passwordless MFA Technology Partnerships does TraitWare offer?
It is our goal to help fuel the success of all our partners – to empower them, in the face of growing global security risk, to better serve the needs of their customers – with TraitWare’s Real Passwordless MFA™ for True Zero Trust Access.
A list of partnership types can be found at this link:
-
How do I modify or change my billing or contact information?
Please email us at partners@traitware.com.
-
Are you SOC 2 certified?
Yes. A SOC 2 certification report can be sent when a partner is under NDA with TraitWare.
-
Do you have industry use cases?
Yes, we do have case studies and customer testimonials.
More about that can be found here:
-
What are the retail prices?
Retail pricing for TraitWare is $5 per use, per month. Partners can get a discount on the retail price, dependent on which partner contract you have in place with TraitWare:
- Referral: In this model, for any referral to TraitWare that results in a sale, the partner will receive a one time referral fee of 10% of first year contract value
- Co-Sell: In this model the partner is responsible for bringing the opportunity to TraitWare and handle the account management responsibilities of the client (from initial sale to a closed contract. TraitWare will handle both the technical part of the sales process as well as post sale customer technical support. The partner receives a 20% commission for the life of the contract with the client.
- Resell/MSP: In this final model, the partner is responsible for all aspects of the sales process. This includes Sales, Technical Sales and Level 1 support post sales. The partner receives a 40% commission for the life of the contract with the client.
-
Can I get a volume discount?
Yes. There are options where a volume discount could apply.
For example, volume tiers will be established and the amount of margin the partner receives will increase based on achieving the next plateau. The number of users and amount of the additional discounts are negotiated on a per partner basis, based on the markets served (Geographically and from an Industry perspective).
For more information contact us on support@traitware.com.
-
How does your pricing model work?
Every user begins with a 30-day free trial account of our software. During this period, they are given unlimited access and usage of the service and the ability to cancel the service. After the 30-day trial, the user will choose a pricing plan detailed on this page.
-
What if I need to be issued a refund?
If you have already purchased a yearly subscription, and you are not satisfied with the product, we can issue you a pro-rated refund based on the amount of time after your trial period expired. Contact support@traitware.com to get your refund process started.
-
How long does it take before I receive my refund in my account?
Refunds typically take 5-10 business days to be processed and refunded to your account.