WinMagic Extends Identity Assurance Beyond Passkey Login With Live Key and LIT

Pattern of various antique keys and keyholes arranged on a bright yellow background, representing the concept of security, access, or unlocking solutions.

Passkeys have addressed the authentication problem at login, but they leave a gap that security teams know well: what happens to the session after the user gets in. Toronto-based WinMagic is targeting that gap with Live Key and Live Identity in Transaction (LIT), launched March 9.

The two products work together as a continuous identity assurance layer. Live Key feeds real-time endpoint signals into the identity system, including login status, screen lock state, encryption posture, and overall device health. LIT uses those signals to evaluate whether the verified identity established at login still holds during a transaction. If endpoint conditions degrade or something changes, trust can be revoked automatically, without requiring the user to re-authenticate.

WinMagic CEO Thi Nguyen-Huu described the problem the company is solving: bearer tokens and long-lived sessions remain a significant attack surface even when the initial login was protected by a passkey or strong authenticator. A compromised endpoint left open after a successful login can be exploited without triggering any re-authentication event. “Endpoint intelligence now makes it possible to uphold verified presence continuously without repeated interaction,” Nguyen-Huu said.

The products are aimed at banks, enterprises, and other organizations that need to secure sessions and high-risk transactions without adding friction at every step. Payment approvals, privileged actions, and help desk resets are the specific scenarios WinMagic highlights, all moments where the identity verified at login needs to be confirmed as still valid rather than assumed.

The launch lands as passkey adoption continues to broaden. SK Telecom’s recent addition to the FIDO Alliance board reflects how widely passkeys are now being adopted across enterprise and carrier ecosystems, and the FIDO Alliance’s updated metadata service rules point to growing pressure on the trust layer that passkeys depend on. WinMagic’s framing treats passkeys as a solved problem and focuses on the post-login surface that remains exposed.

The broader shift WinMagic is betting on is that enterprises are moving past password replacement and asking harder questions about verified presence throughout a session. Live Key and LIT are positioned as an answer to those questions without adding repeated authentication prompts or disrupting workflows.

Sources: PR Newswire

– Mobile ID World Editorial Team