Relock Witness

Fight back AI-enabled phishing
directly from the login

The problem

Phishing has outgrown conventional defenses

AI is amplifying the capabilities of attackers and the scale of phishing attacks, making organizations of every size a target.

Sophisticated attacks no longer require sophisticated attackers

AI models allow any attacker to use capabilities that were accessible before only to nation state-level groups.

Anthropic Threat Intelligence, Sep ‘26

All phishing is now customized spear phishing

EvilTokens PhaaS attack targeted 12,000 accounts across 10,000 organizations, each with a custom AI-generated email lure, personalized to the targeted user.

Microsoft Threat Intelligence, Sep ‘26

Conventional defenses do not offer effective protection

Almost all modern phishing kits offer AI-enabled user device spoofing and risk analysis bot detection to bypass defensive mechanisms.

ANY.RUN H1 2026 Cyber Risk Report
Relock solution

Protection that works without user action

The first AI-powered phishing counterattack that kills AitM / MitM directly in the login page. Added to your IdP admin portal in less than 30 minutes – fully transparent to the user.

Overview

How Relock Witness protects every authentication flow

Relock Witness is the first AI-powered countermeasure that terminates the AitM / MitM phishing attacks, with 100% deterministic precision.

At each user authentication the Witness server injects a challenge directly into the login flow. This counterattack inevitably reveals any malicious phishing kit sitting between the user and the legitimate page and kills the connection.

The user sees nothing. If they click on a phishing link, their login attempt on the fake page will be terminated before they introduce their password or any other credentials.

Pick attacker's actions and follow the flow
Relock scans fingerprint

Attacker's response - fingerprint declaration

Relock sends a browser attestation challenge

Attacker's response - challenge execution

Outcome

Relock Witness

Stops phishing before credentials are exposed

Relock Witness counterattack approach The user's browser connects through an attacker to the login page. Relock Witness terminates the attack at the login. Defensive approaches such as passkeys, hardware keys, whitelisting, browser extensions and AI risk analysis prevent theft of credentials or alert the user. No user adoption is needed. User’s Browser DEFENSIVE APPROACHES Passkeys Hardware keys PREVENT THEFT OF CREDENTIALS Whitelisting Browser extensions AI risk analysis ALERT THE USER Attacker COUNTERATTACK APPROACH TERMINATE THE ATTACK WITNESS No user adoption is needed. Unlike user-side defenses, such as passkeys or browser extensions, Witness requires no user action, making the rollout possible in minutes.
Technology difference

AI-powered, polymorphic challenge

Polymorphic browser attestation

Witness generates a unique challenge that can only be correctly executed by the device attempting to log in.Even an attacker that can modify the entire information flow between the page and the user is forced to either fail or reveal the presence of the malicious phishing kit.

Counteroffensive AI model

A proprietary AI model that uses offensive methods against attacks to prevent bypass. Witness is always evolving and changing live, so any reconnaissance is useless to mount an attack.

Tried and hardened by experts

Our red team lab keeps the model behind the challenge up to speed on the latest threat developments and our own security research into the frontier of AI-enabled phishing.

IAM-native and server-side

Built to be used by IAM admins, directly with major Identity Providers such as Okta, Auth0, or PingID. No application or infra changes required. No user education needed.