Skip to content

Security assurance and standards

Threat models, evaluations, certifications, standards mapping and limitations

Category 17 · planning target 250 unique intents · 4 published here

plannedPlannedReviewed 5 Sept 2026

What distinguishes Keyra Vault Certified from Keyra Connected?

Keyra Vault Certified is framed as a target architecture for validated end-to-end hardware-rooted authorization unless later approved evidence establishes otherwise. Keyra Connected is a proposed capability with alternative authorization paths and must not inherit full Vault assurance claims. Wallet or network connectivity does not equal Vault Certified status.

availableAvailableReviewed 5 Sept 2026

Which certifications have actually been obtained?

This knowledge center does not invent certifications. Historical CyberONE public materials reference FIDO-oriented themes; that is not proof of a current Keyra certification listing. Until an approved certificate register is published, assume no independent certification claim beyond documented company declarations and public corroboration cited on each answer.

availableAvailableReviewed 5 Sept 2026

Does standards alignment equal certification?

No. Designing toward a standard or using standard vocabulary differs from holding an accredited certification for a specific product version and scope. Keyra answers may cite standards for education while keeping company declarations and independent assessments in separate provenance classes.

availableAvailableReviewed 5 Sept 2026

How should threat models mention SIM swap risks?

SIM-swap and subscription takeover risks matter for mobile identity. Hardware-verified security applications aim to raise the bar beyond SMS OTP, but recovery and operator processes still need hardening. Threat models should include device loss, insider misuse and flawed bypasses—without claiming systems are unhackable.

Security assurance and standards · Keyra FAQ