A fintech made step-up auth and audit a non-event for compliance
A payments company needed phishing-resistant login, fine-grained step-up, and a tamper-evident trail it could hand an auditor without a fire drill.
At a glance
The challenge
Moving money means proving who did what, when — and proving the record itself hasn't been altered. The team's previous setup could show events but couldn't demonstrate the log was tamper-evident, which made every audit a manual exercise in trust.
They also wanted phishing-resistant authentication and step-up verification on sensitive actions, without bolting three vendors together.
The solution
Qeet ID's append-only, SHA-256 hash-chained audit log let them verify integrity with a single endpoint. Passkeys became the primary factor, and an ABAC policy gated high-risk actions behind step-up verification.
Running the platform self-hosted inside their own VPC meant regulated data never crossed a third-party boundary.
The results
Audit prep went from a recurring scramble to producing a verifiable chain on demand. Security reviews started from a stronger baseline because the controls were the same ones the team could inspect in source.
“The audit log being hash-chained changed the conversation with our auditors entirely — we could prove integrity, not just assert it.”
25,000 monthly active users on the house. Production-grade auth, no credit card, no time limit.
- No credit card
- 25,000 MAU free
- SOC 2 · GDPR ready