The challenge
Credential-stuffing attacks were driving account takeovers, and password resets were the largest support cost.
Our approach
- 01
Implemented passkeys (FIDO2/WebAuthn) with biometric fallback.
- 02
Built adaptive risk scoring on device, network and behaviour signals.
- 03
Pentested every release and closed findings before go-live.
The outcome
Drop in fraudulent logins: 99.9% · Password-reset tickets: −70% · Critical findings at launch: 0. The Aegis Security Solutions team now owns the full codebase and documentation, with Promettis on hand for ongoing improvements.