The rise of AI-powered deepfakes and sophisticated social engineering has broken trust in traditional credential-based authentication for remote access. OpenVPN and iVALT are addressing this critical vulnerability through a strategic partnership. They are integrating iVALT's Human-Bound PKI™ identity directly into OpenVPN's Zero Trust Network Access (ZTNA) solutions, enabling one-click, passwordless login that cryptographically verifies the real human behind every access request.
OpenVPN and iVALT partner to integrate human-bound PKI identity into ZTNA.
The solution enables one-click, passwordless VPN login via a mobile app.
It cryptographically ties access to a user's device and biometrics, creating an unspoofable identity.
The integration is designed to stop social engineering and AI deepfake impersonation attacks.
It eliminates passwords, tokens, and manual certificate management, reducing operational overhead.
The partnership strengthens zero trust with user location and time-based context for access decisions.
Traditional remote access remains vulnerable to stolen credentials and impersonation, a threat magnified by AI deepfakes. This partnership hardens OpenVPN's Zero Trust posture by anchoring access to a verified human identity. “OpenVPN has long set the standard for secure connectivity,” said Rohit Kalbag of OpenVPN. “By integrating iVALT’s Human-Bound PKI identity, we are setting a new standard—one that eliminates the biggest vulnerabilities in remote access... while also future-proofing against threats brought on by AI.”
The solution replaces passwords with iVALT’s mobile-centric identity, which combines secure-element keypairs, device binding, and biometrics. Users authenticate instantly through the iVALT mobile app. Each login is cryptographically bound to the individual, incorporating contextual factors like time and geographic boundaries. This creates a robust defense layer that verifies the true human behind any access or privilege escalation request, blocking deepfake voices and impersonation attempts.
The integration delivers tangible security and operational gains. It removes credential-based vulnerabilities and strengthens least-privilege access with identity and location context. For users, it means frictionless, one-click access. For IT teams, it eliminates the burden of password resets, SMS codes, and hardware token management. The added assurance layer is particularly critical for highly-regulated industries, providing an "AI-ready identity architecture" that ensures only validated humans can trigger actions across networks and AI systems.
This partnership marks a significant step toward a more resilient security model. By moving beyond what a user knows (passwords) or has (tokens) to who they are in a cryptographically provable way, it addresses the core weakness exploited in modern attacks. As iVALT CEO Baldev Krishan noted, “AI deepfakes have broken trust in traditional authentication.” Together, the companies provide a practical path to restore that trust, ensuring secure remote access in an era of AI-enabled threats.
About OpenVPN
OpenVPN's network security platforms provide secure remote access through both self-hosted VPN and cloud-delivered VPN solutions for business with the core tenets of Zero Trust Network Access (ZTNA), creating peace of mind for organizations with remote and hybrid employees. Built on the high-performance, enterprise-trusted open-source OpenVPN protocol, OpenVPN’s solutions for business, Access Server and CloudConnexa®, help teams securely access private company resources on SaaS platforms, the web, and via cloud environments (AWS, Azure, Google Cloud, etc.). With over 90 million downloads and nearly 20,000 business customers, OpenVPN products are trusted for their security, speed, and simplicity.
About iVALT, Inc.
iVALT provides real-time unassailable identity for people and endpoints. With 5-factors, including 1-click mobile biometrics identity and simultaneous PKI mobile identity, along with GPS location and time, iVALT verifies identity and context instantly across enterprise, financial, healthcare, and government environments. Its patented OnDemand ID™ technology integrates seamlessly with all existing authentication, access management, and security systems to deliver trusted human, AI agent and IOT identities for all use cases.