Enterprise
Authentication for teams and regulated environments.
NexKey is built so that authenticator lifecycle — enrollment, oversight and revocation — can be managed centrally without weakening the on-device security model.
Managed authentication capabilities
Each capability below is marked with its current status. Only items marked Available have shipped.
- Managed authenticators Planned
- Device policy Planned
- Central revocation Planned
- Security audit events Planned
- Trusted devices Available
- Recovery policies Planned
- Enterprise enrollment Planned
Trusted devices, today
Explicit device enrollment and revocation already ship in NexKey. A revoked device stops receiving synchronized data.
Built for oversight
The trusted-device model and encrypted sync are designed so that central policy and audit can be layered on without moving secrets off the device.
Trust model
Central oversight, local secrets.
Management operates on device enrollment and policy — not on the authenticator secrets themselves, which stay in platform secure storage on each device.
-
iPhone Secrets live in the Secure Enclave–backed Keychain.
-
Encrypt locally Vault is encrypted with a key that never leaves the device.
-
Encrypted Vault Backend stores ciphertext. It has no key to read it.
-
Trusted Mac Only devices you approved hold a decryption key.
-
Decrypt locally Plaintext exists only in memory on the trusted device.
Future capabilities
What we are building next.
- TOTP and HOTP Available
- Encrypted sync Available
- Trusted devices Available
- Passkeys Planned
- Push approval Planned
- Transaction approval Coming later
- Enterprise device policy Coming later
Talk to us about a deployment
Tell us about your environment — device fleet, compliance obligations and the authenticator lifecycle you need — and we will tell you honestly what NexKey supports today.