Trust Center

Security FAQ

Straight answers to the questions we hear most often about social engineering, phishing, stolen email accounts, and how Photon Light is designed to stop them.

What makes Photon Light different from a password manager?

A password manager still relies on a master password, a device, and often email-based recovery. If the master password is coerced or the email inbox is taken over, the vault follows. Photon Light removes the password entirely: authentication is bound to a physical hardware device and a photonic exchange, so there is no secret string for an attacker to steal, reset, or socially engineer.

If my email is stolen, can attackers access my Photon Light account?

No. Access is not tied to your inbox. Even if an attacker controls your email, they cannot trigger a password reset — because there is no password — and they cannot receive a one-time code or recovery link that unlocks the account. The only thing that can authenticate you is the physical device registered to your identity.

How does Photon Light stop social-engineering phone calls?

Social engineering works by convincing a human to reveal or type a secret. Photon Light users have no password, PIN, or one-time code to read out. A support scammer can ask for anything they want; there is simply nothing useful the user can provide over the phone.

Can a phishing site steal my Photon Light credentials?

There are no credentials to type into a fake page. Authentication happens through a light exchange between the registered device and the legitimate service. A cloned website cannot perform that exchange, so it cannot harvest anything of value.

What if someone intercepts my phone number and receives SMS codes?

Photon Light does not use SMS, email, or app-based one-time codes. SIM swaps, number porting attacks, and intercepted text messages are therefore irrelevant: there is no code path for them to exploit.

Where is the cryptographic key stored?

Private key material is generated inside the hardware device and never leaves it in readable form. There are no recovery phrases, screenshots, or backup files sitting in cloud storage or a mailbox for an attacker to find.

How do you detect an account-takeover attempt in progress?

Every authentication event is verified continuously against device posture, session context, and behavioral signals. If a session deviates from expected patterns — unusual location, device mismatch, or anomalous timing — the platform isolates it and revokes trust automatically rather than waiting for the user to notice.

Does Photon Light protect against insider threats?

Yes. Because authentication is hardware-bound and non-repudiable, an insider cannot simply look up, copy, or share a password. Administrative actions require the same hardware-bound proof of presence, and audit logs record who performed what and with which registered device.

Is Photon Light post-quantum secure?

The protocol uses NIST-standardized post-quantum key establishment and digital signatures — ML-KEM and ML-DSA — alongside classical primitives during the migration period. This protects today's sessions against tomorrow's quantum decryption as well as current harvest-now-decrypt-later threats.

Still have questions?

Our executive team can walk through your threat model, compliance requirements, and how Photon Light fits into your existing identity architecture.