TECHNOLOGY
Security by Design
Secure Authentication
Some two-factor solutions rely on shared secrets to generate token numbers, which, if attackers steal, they can use the information to compromise an organization. Duo’s two-factor solution is designed with security in mind.
We use asymmetric cryptography, keeping only the public key on our servers and storing private keys on your users’ devices in a tamper-proof secure element. Duo never stores your passwords - meaning your logins stay safe.
Designed for People
We know the most effective security solution is one your users actually use. Our solution only requires your users to carry one device - their smartphone, with the Duo Mobile app installed on it. Logging in via push notification is fast and easy.
We strongly recommend using Duo Push as your second factor, a more secure method than SMS passcodes that can protect against man-in-the-middle (MITM) attacks.
High-Availability Architecture
Duo has maintained uptime of greater than 99.99% for more than four years, with a hard service level guarantee backed by SLA. Duo’s servers are hosted across independent PCI DSS, ISO 27001-certified, and SSAE 16-audited service providers with strong physical security.
We provide a high-availability service split across multiple geographic regions, providers and power grids for seamless failover, and our multiple offsite backups of customer data are encrypted.