
Authentication built the session.
We build the act.
Yuthent is an Execution Authority Infrastructure company. We produce the primitive the rest of the identity stack does not: proof that a specific human authorized a specific action, at the moment it fired.
The observation that became the company.

Mohamad Khalil Yossif
Founder & CEO
Yuthent started from a real problem I hit building a workforce product. Customers refused to give up on-site biometric check-ins. Not because they loved biometrics, but because it was the only control that reliably proved the right human was present. Passwords, codes, passkeys and sessions could all be shared, borrowed or taken over. The press was the only act that stayed tied to the person.
That observation generalized. Every industry facing social engineering, insider abuse, session hijacking or agent delegation fights the same gap, and every existing stack answers it with a session token. Yuthent answers with the press itself.
“A valid session is not proof of approval. A signed action is.”
Concrete. Operating. Shipping today.
Android and iOS SDKs, native
The full P/S/E/A surface. Hardware-bound keys in StrongBox, TEE and Secure Enclave. A trust engine across five signal categories. Offline-first signing with a durable queue.
The control plane
A tenant-facing portal: device forensics, enrollment, trust policy, anomaly triage, the action ledger, analytics, usage and entitlements, webhooks, access control.
The backend that enforces the contract
A hash-chained per-actor ledger, daily anchors, RFC 3161 timestamping. Per-risk-level monotonic counters. Server-side attestation verification with action-bound nonces. An external-decision callback for integrator fraud systems.
Link-enrollment grant flows
In-person and video-remote link enrollment. Time-boxed, scoped, signed grants. The primitives under patient consent, supervised onboarding and field-operator workflows.
Why it is safe to build on.
The category is specified in the open.
Yuthent authors and publishes draft-yossif-psea-02, the Internet-Draft that specifies it, and the approval-integrity requirement merged into OWASP AISVS 1.0. The draft is an individual submission: not adopted by an IETF working group, and not IETF consensus. The repository is public.
A proprietary primitive, patent-pending.
The core authorization method and the device-bound execution-proof architecture are under active prosecution at the USPTO.
Selected.
By SafeNology (Takwin Ventures and S.T-Impact) and by Hasoub Labs, Cohort 4.
Built, not promised.
Native iOS and Android SDKs, the control plane, and the backend that enforces the contract. A product to deploy, not a roadmap to wait on.
Work with us.
Tell us the flow you want to protect. A first deployment ships a working integration on it, with cryptographic evidence auditable on day one. First call within five business days.