Relock
AitM Protection

End Adversary-in-the-Middle attacks
instantly, directly in the SSO

Three stacked application windows with an AitM label, illustrating Relock AitM Protection

Arm your SSO with AitM protection

Overview

How Relock AitM Protection works

Relock offers the first server-side solution that stops the Adversary-in-the-Middle attacks and requires no action from the users. There is no browser extension, no extra software, and no adoption needed.

Relock prevents login attempts when there is a malicious proxy between the user and the SSO / customer authentication. It uses a challenge-based mechanism that forces the AitM phishing kit to reveal itself, pushed directly to the browser. Any adversary intercepting the login is immediately terminated.

See the flow diagram below to take an attacker's perspective.

Pick attacker's actions and follow the flow
Relock scans fingerprint

Attacker's response - fingerprint declaration

Relock sends a browser attestation challenge

Attacker's response - challenge execution

Outcome