Syberkey CAM⬡ PQ AI CAM

Banking, protected by Syberkey CAM

Continuous access enforcement on every transaction — not just at login.

Bind
Verify
Enforce
CPE
Start Demo →
Scroll to learn more
What is it?

Continuous Access Management

Traditional authentication checks identity once at login. CAM verifies every action with real-time AI risk scoring, device context, and biometric session binding.

Traditional Auth
Login once → full session access
Login → session token issued
Token valid for hours/days
Every action trusted by default
No risk scoring per action
Session hijack = full account access
Syberkey CAM
Every action verified in real-time
Login → bind session with biometric
Every action runs verify + enforce
AI risk engine scores context (0–1)
High risk → step-up challenge
Execution token consumed on enforce
CPE middleware architecture
BrowserBFF (Next.js)CPE VerifyCPE EnforceProtected Handler
Advanced Tier

PQ AI CAM — The Quantum-Ready Tier

When quantum-ready protection is required, PQ AI CAM extends classical CAM with PostQuantum cryptography — available when enabled on the tenant.

🤖

AI Risk Scoring

Every action scored 0–1 by the AI risk engine. High scores trigger step-up challenges before execution.

PostQuantum Signatures

ML-DSA-65 on evidence bundles, permission artifacts, and hybrid proofs — available when PQ AI CAM is enabled.

🔐

Hybrid Token

Classical JWT combined with a detached PQ signature. Available in PQ AI CAM deployments.

PostQuantum deployment stages
1
Classical CAM
HMAC + AI risk scoring
v1 (this demo)
2
PQ Evidence
ML-DSA-65 signed evidence bundles
3
PQ Artifacts
Permission artifacts with PQ signature
4
Hybrid Token
Classical JWT + detached PQ proof
5
Full Hybrid
All channels PQ-hardened
6
Full PQ Resilient
Quantum-native end-to-end
Under the hood

How CPE Protects XYZ Bank

Four stages, firing on every banking action — transparent to the user, visible in the demo.

🤝
Step 1
Handshake

The app registers the user session with cpe-service. A session token is issued — no biometric yet.

🔗
Step 2
Bind

The user's biometric context (face / device) is locked to the session token. From here, every action carries proof of identity.

🧠
Step 3
Verify

Before each action, CPE runs AI risk scoring on device, location, and behaviour. An execution token is issued — valid for seconds.

Step 4
Enforce

The execution token is consumed — single-use. The action is allowed or denied. Audit record written. Strip updates.

Demo coverage

What the Demo Showcases

💸

Wire Transfers

Create, release to processing, and settle wires. Every step CPE-verified with AI risk scoring.

CustomerTellerAdvisor
🏦

Account Management

View checking and savings balances. Admins and tellers can open new accounts.

All roles
📋

Compliance Review

Update compliance status (teller) and add audit notes (advisor). Role-gated and CPE-enforced.

TellerAdvisorAdmin
🚨

Step-up Challenges

High-risk actions trigger biometric re-verify. CPE challenge modal — live in the demo.

All roles
📊

Real Audit Trail

Every CPE decision logged: action ID, risk score, assurance level, execution token expiry.

Visible in strip

PQ AI CAM

Badge shows configured assurance level. v1: classical CAM. Future: hybrid and full PQ.

All roles

See Syberkey CAM in action

Walking guide included — directs you step-by-step and shows CPE firing live.

Demo users: customer@maildrop.cc · teller@maildrop.cc · advisor@maildrop.cc · admin@maildrop.cc

Start XYZ Bank Demo →
cpe-bank-demo.syberkey.com·Powered by Syberkey CAM·v1 classical assurance