Authsignal: Building the Infrastructure of Digital Trust

Justin Soong | Authsignal | Building the Infrastructure of Digital Trust | CIO Times Magazine

You know how we usually don’t notice all the infrastructure that keeps our digital world running until something actually goes wrong? It’s like the wiring behind a light switch or the security checks happening behind the scenes during an online purchase. We only really pay attention when the power cuts out, or someone tries to drain an account.

For the past twenty years, we’ve treated digital identity the exact same way. You’d type in a username and password, maybe get a quick code texted to your phone, and that was it. It worked well enough for a while, but honestly? It’s running out of steam. That old approach is pretty much on its way out, and that’s exactly where Authsignal comes in.

Authsignal Founded by Justin Soong, the company is taking a fresh look at things. Instead of treating identity as just another login screen, they see it as the interwoven fabric of the digital economy. It’s the drop-in foundation that lets people, businesses, and even AI agents securely interact and do business with each other, even if they’ve never worked together before. And honestly, it’s the kind of shift we really need as everything keeps moving forward.

From Login to Continuous Trust

For two decades, identity has functioned as a single checkpoint. Prove who a person is once, and the system trusts them until something forces a reset. Soong expects that era to end within the next decade, predicting that identity will stop being a login and become “a continuous, portable proof of trust” that travels with a person rather than resetting at every new service.

Authsignal sees governments as a key force accelerating this transition. Every EU member state has to issue a citizen digital wallet, mobile driver’s licenses are live across roughly twenty US states, and the UK has committed to a national digital ID scheme. Once verifiable cryptographic credentials sit in millions of pockets, Authsignal’s position is that businesses need to look beyond whether someone has logged in, and ask whether they can trust who they are dealing with, wherever and however they show up.

The implication for enterprises is uncomfortable but clarifying. Soong puts it plainly: “Trust becomes infrastructure.” It cannot be bolted on after a breach or a compliance deadline. Authsignal’s view of who wins the next decade centers on businesses that treat verifying their customer as a core capability they orchestrate deliberately, across the entire customer journey, including web, mobile, the call center, and in person, rather than a feature inherited from whichever identity system they happened to stand up years ago.

Retiring the Friction Myth

The cybersecurity industry has long operated on an assumption Soong considers one of its most expensive myths: that stronger security inevitably means more friction. That belief, in his view, gave the industry permission to ship friction and call it protection, while the friction quietly cost businesses their customers.

Authsignal’s reframe treats authentication as a conversion decision as much as a security one. Every step-up challenge added has a measurable cost in drop-off, and everyone removed has a cost in risk. Historically, security owned the risk and product owned the funnel, with little shared view between the two. Authsignal’s approach is to let both sides see the same numbers and tune them deliberately.

Soong believes that passkeys are the clearest proof that the old trade-off was never a law of nature. They are phishing-resistant and faster than typing a password, stronger and smoother at once. When Authsignal helps a business to roll out passkeys, the client does not just get more secure, it recovers conversion and cuts support tickets. Soong sums up the underlying logic this way: “You challenge hard when the risk is real and get out of the way when it isn’t. Invisible for the ninety-nine, immovable for the one.”

Authsignal also encourages product and security leaders to think beyond authentication: once a business can actually trust the person, or the AI agent, on the other end, new customer experiences become possible. Soong’s advice is to build for a digital-identity-first paradigm the way the industry once learned to build mobile-first, starting from the assumption that identity is established and designing the experience forward from there.

Anticipating the Next Attack

Artificial intelligence has industrialized fraud, an uncomfortable truth Soong explored in a February 2024 Forbes Technology Council piece on generative AI’s risks to digital trust. Deepfake voice cloning is up several hundred percent year over year, in his account, and a convincing synthetic identity is now cheap to produce at scale.

As he puts it, “If your defense is a static rule written eighteen months ago, you’re bringing a fixed lock to a fight with an attacker who rewrites the key every week.” Once generative AI can convincingly fake a face or a voice, verifying someone once and trusting them forever stops working. Trust, in his view, has to be re-established at the level of each interaction, with cryptography and biometrics confirming that an action is both authentic and actually authorized by a human.

Authsignal does not try to be the fraud engine that predicts every threat. That is a different layer with its own specialists. Instead, it gives the people closest to the problem a real-time drop-in orchestration layer they can adapt without waiting on an engineering sprint. Its no-code rules engine ingests risk signals from multiple sources, including device reputation, behavior, transaction velocity, and third-party fraud tools, then makes a live decision to allow, challenge, step up, or block.

Authsignal’s direction is to shorten the loop between a new attack pattern emerging and a defense going live, increasingly using AI on the defensive side to surface anomalies and suggest rules so a fraud or product team can respond in hours, not quarters. In the company’s view, the winners will not be the ones with the cleverest model, but the ones that can adapt their defenses at the speed the threat is moving, something most enterprises cannot do because their authentication is welded into systems only engineers can touch.

From Cost Center to Strategic Asset

In Soong’s account, authentication becomes a boardroom issue the moment a single failure could wipe out decades of brand trust or trigger a regulatory penalty measured in millions. When the UK made banks reimburse victims of authorized push payment fraud, it changed bank economics overnight. Preventing fraud became cheaper than paying for it. That, in his framing, is no longer an IT line item, it is a conversation the board has to own.

Soong’s advice to business leaders is to stop treating authentication and digital identity more broadly, as a cost center and start treating it as a strategic capability, the way a company would treat its payments stack or its data platform.

He argues that three questions belong in the boardroom rather than an engineering backlog: what customer friction costs in lost conversion and retention, what the exposure looks like if the current method is downgraded by a regulator, and whether the teams who own customer experience and fraud can actually change how the business authenticates or are hostage to whoever controls the identity system.

That last question, in his words, is the tell. In most enterprises, the people accountable for the business outcome have no lever to pull. In Authsignal’s model, making identity a true enterprise capability means giving product, fraud, and compliance teams greater control, rather than leaving it solely in the hands of engineering.

That same logic extends to how the company treats the data authentication process. Every authentication event is a signal about risk, behavior, and intent, and Authsignal’s assessment is that most organizations throw that signal away or lock it inside a system nobody outside engineering can query. In most enterprises, device data, transaction history, and fraud flags sit in separate places, unjointed at the moment a decision has to be made.

Bringing those disparate signals together in real time, so a rule can act on them, is a large part of what Authsignal does. Once joined, the value extends well beyond stopping a bad login. It becomes governance a company can evidence to a regulator, a conversion instrument that shows the direct impact of a security decision on completion rates, and an early-warning system that surfaces fraud patterns before they scale. Soong puts it simply, “Authentication data isn’t exhaust. Treated properly, it’s one of the highest-quality, highest-intent datasets a consumer business owns.”

The Structural Bet on Digital Credentials

When asked which development will most fundamentally reshape identity infrastructure, Soong points to digital credentials rather than any single technology. The shift, in his framing, is from a world where the business stores and manages the customer’s identity to one where the customer carries a cryptographically signed credential and presents it on demand.

Passkeys are the clearest proof that this model works at scale. They are cryptographic, bound to the device, and phishing-resistant by design. As Soong puts it, “You can’t phish what the user never types.” With Google, Microsoft, and Amazon defaulting new accounts to passkeys, consumer behavior has already moved. That, to him, is a genuine change to the security model, not a cosmetic improvement to the old one.

But Soong is deliberate about placing passkeys within a broader shift rather than treating them as the whole story. Governments are now issuing the next wave of digital credentials: mobile driver’s licenses are live in more than twenty US states, the EU mandates digital identity wallets for every member state by the end of 2026, and Apple Wallet and Google Wallet already hold government-issued credentials in multiple jurisdictions.

What makes this structural rather than incremental, in Soong’s view, is that the credential model itself is changing. A mobile driver’s licence is not a scan of a plastic card. It is a cryptographically signed, verifiable credential the holder controls, and the model is built so that a business verifying one attribute, such as whether someone is over eighteen, can be designed to confirm just that without exposing the rest of the document. The privacy architecture lives in the credential, not bolted on afterward by the business.

Soong is careful to distinguish between the credential and the hard part. “The credential being standardized was never the challenge,” he says. The challenge is what happens when a business needs to accept digital credentials from multiple wallets, across different standards, alongside passkeys, biometrics, and traditional methods, without rebuilding its identity stack for each one. In his assessment, the businesses that will lead this transition are the ones that treat digital credential acceptance as an orchestration problem, not an integration project to be repeated for every wallet and every jurisdiction.

That orchestration challenge is what drew Authsignal to build its Digital Credential Verification capability, applying the same drop-in principle the company used with passkeys. A single integration accepts credentials from Apple Wallet, Google Wallet, and government wallets built on recognized standards. Biometric holder verification confirms that the person presenting the credential is the person it was issued to.

Soong sees these layers as cumulative rather than competing. Passkeys fix how a person authenticates. Government-issued verifiable credentials fix how a person proves who they are. Together with biometric verification confirming the human behind both, they form the infrastructure for a trust model that is fundamentally different from the username-and-password era. “Passkeys were the first structural shift,” he says. “Digital credentials are the next. The organizations building for both are the ones designing for the decade ahead, not the quarter.”

Regulation as a Starting Gun

Regulation, in Soong’s view, has never been the enemy of innovation, at least not in a category built on trust. Regulation is the single biggest demand driver Authsignal has. Almost every consumer-facing financial institution outside a couple of regions now faces a hard deadline within the next couple of years to move off SMS one-time codes toward phishing-resistant authentication. The US has downgraded SMS in federal guidance. The UAE has banned it outright. India, the Philippines, Malaysia, Singapore, and Australia are all moving in the same direction, and Europe is tightening its rules while shifting fraud liability onto providers.

Soong’s responds, “That’s not a constraint. That’s a starting gun.” Each deadline forces a business to evaluate something better, converting a vague sense that it should modernize someday into a dated line item with a compliance owner attached.

Where governance becomes real differentiation is in how fast a business can respond to it. A regulation lands, a window opens, and the business that can deploy compliant authentication in weeks, rather than turning it into a year-long engineering project, wins the moment. That is the whole thesis behind how Authsignal is built: meeting the deadline without it becoming a rebuild.

Companies that treat compliance as a race to the minimum keep scrambling from deadline to deadline, while the ones that build the capability to adapt quickly turn each new rule into an advantage over slower competitors. As he sums it up, “Same regulation, opposite outcome. The difference is architecture.”

Designing for a Moving Target

The distinction Soong draws is between organizations that buy security products and organizations that design for trust. Plenty of companies, in his assessment, have a full stack of security tools and still leak customers, because the tools were bolted on to satisfy an audit rather than built into how the customer actually experiences the business.

Cultivating trust, in Authsignal’s philosophy, is a design discipline rather than a purchasing decision, and it shows up in small moments: whether signing in is fast and feels safe, whether a risky-looking session gets challenged in a way that feels protective rather than punitive, whether a support agent contacted for help actually knows the customer rather than interrogating them with security questions a fraudster could answer from social media.

The organizations that get this right, in the company’s view, treat trust as something they orchestrate deliberately across every channel a customer reaches them through, rather than a checkbox ticked once a year. The tell is consistency. A business that has truly invested in trust feels the same whether a customer is on the app, on the website, or on the phone.

That same logic shapes how Authsignal thinks about resilience. Static security assumes the threat holds still, and Soong argues it never does. Against AI-driven fraud that iterates weekly, a static architecture is not just less effective, it is a liability with a countdown on it.

Adaptive authentication flips the default: instead of treating every user the same, it reads the context of each interaction, including device, behavior, transaction, and surrounding risk signals, then calibrates in real time. A trusted customer doing something ordinary sails through, while the same account behaving strangely, from a new device, at an odd hour, moving money in an unusual pattern, gets challenged hard.

But adaptive intelligence only works, in Soong’s words, if the people who understand the threat can actually change the response, which he sees as the part the industry underweights. The resilient organization is the one where a fraud analyst who spots a new pattern on Monday has a new rule live by Tuesday. In his words, “Resilience isn’t a smarter static wall. It’s a shorter loop between seeing a threat and adapting to it, and that loop has to be operable by the business, not gated behind engineering.”

Built to Cooperate

Enterprise technology’s shift from isolated products to platforms and ecosystems is real, and it shaped Authsignal’s own place in the stack in a deliberately contrarian way. According to Soong, a lot of vendors responded to the shift by trying to become the all-in-one platform that does everything. Authsignal went the other direction.

The company positions itself as a drop-in authentication layer that sits on top of whatever identity system a business already runs, whether that is Auth0, Cognito, Okta, Ping, or Keycloak, adding modern capabilities like passkeys, adaptive step-up, and omnichannel verification without ripping anything out.

That reflects a deliberate bet about how ecosystems actually work, in Soong’s framing: enterprises do not want to stake the business on a single monolithic platform that owns their entire identity stack. They want best-in-class capabilities they can compose alongside what they already have. The winning ecosystems, in his view, are collaborative rather than walled gardens.

Authsignal companies posture, Soong says, is to be “an outstanding participant in the ecosystem rather than a wannabe owner of it.” The company integrates with identity providers, fraud tools, verification partners, and biometric providers. That collaboration, in his words, will matter even more as identity extends to autonomous agents.

As AI assistants start booking travel and managing subscriptions on people’s behalf, the identity layer has to recognize and authorize those agents too, and no single vendor is going to own that world end to end. Soong expects it to be orchestrated across specialists who cooperate, which is why Authsignal chose depth over trying to be everything.

What Endures?

The honest test Soong applies to any new development is whether it fixes a root cause or simply decorates a symptom. Everything that only decorates a symptom, in his framing, is a cycle to be embarrassed about in three years.

The question he says he asks of every shiny new thing is the same one: “Does this remove a fundamental weakness, or does it just add a feature?” Passwords being a shared secret is a fundamental weakness. Passkeys remove it. That, in his opinion, is the difference between a structural shift and a trend, and by that measure he counts a few things as clearly structural.

Passkeys are first, because they kill the shared secret, which he considers a permanent change to how humans authenticate rather than a passing preference.

The second is the regulatory retirement of SMS one-time codes. Once governments start banning a method outright, in his view, there is no cycle back. SMS as a security control is finished, and the whole industry is being forced onto something better.

The third is sovereign digital identity, meaning government wallets, verifiable credentials, and mobile driver’s licenses. That infrastructure is being laid now, and once hundreds of millions of people carry a verifiable credential, high-assurance verification becomes an everyday expectation rather than a special case.

The fourth, still early but one Soong is convinced is structural, is agentic identity: authenticating and authorizing the AI agents that will increasingly act on people’s behalf. Non-human identities, in his assessment, are projected to outnumber human ones many times over, and systems built entirely around human login rhythms were not designed for that.

A Legacy Measured in Silence

Authsignal compan’s mission, in Soong’s words, is “to power the global digital trust economy,” and he says he means that plainly rather than as a slogan. The world, in his assessment, is moving off decades-old trust infrastructure, and someone has to build the layer that lets the transition happen without every business rebuilding itself from scratch.

Done well, Authsignal is work makes it dramatically easier for any consumer business to verify and trust its customers everywhere they show up, without a rip-and-replace project that takes a year and puts the whole platform at risk.

The legacy Soong wants is not a category award. It is a company that helped move an entire industry off insecure, decades-old methods and onto something better for real people: fewer accounts taken over, fewer customers locked out, less fraud, less friction. Most of that work, by design, is invisible. Soong says that when authentication is done right, nobody notices it. The customer logs in and gets on with their life, and the fraud that would have happened simply does not happen. As he puts it, “There’s no headline for the breach that never occurred.”

He defines success accordingly, in a way suited to an industry where the best outcomes go unseen: not by the noise Authsignal makes, but by the trust it quietly makes possible, measured in the millions of everyday interactions that work exactly as they should, without anyone having to think about it.

A digital world that is a little safer and a lot less annoying, achieved by strengthening what businesses already have rather than forcing them to start over, is the legacy Soong says he would be proud of.

Also Read :- CIO Times Magazine For More Information

Releated Post