
Passwordless, Phishing-Resistant Authentication for Workforce and Frontline Access
Founded in 2019 in Oshawa, Ontario, BlokSec builds passwordless authentication for organizations trying to remove credentials from the login path entirely. The company was started by identity and security practitioners frustrated with the cost enterprises absorb from password resets and credential theft, and it sells to mid-market and enterprise IT teams covering knowledge workers, frontline staff, contractors and vendors across North America, Europe and Asia-Pacific. Leadership includes chief executive and technology officer Mike Gillan, with Ketan Kapadia as chairman and co-founder advisor.
BlokKey enrolls a user by QR scan, binding a hardware-protected key to their corporate identity; the application then sends a signed, location-aware challenge the user approves with Face ID, Touch ID or a device PIN, with private keys held in the iOS Secure Enclave or Android TPM so nothing reusable crosses the wire. Federation runs over SAML, WS-Fed and OpenID Connect. BlokBadge issues NFC or QR credentials for shared-workstation environments, and BlokSafe vaults legacy passwords, injecting them into sessions without displaying them.
What distinguishes the lineup is coverage of the awkward edges of a passwordless migration rather than the clean case: frontline workers without phones, contractors on shared terminals, and legacy applications that still demand a stored password. Security claims are anchored to recognised baselines, including FIDO2 alignment, NIST AAL3 guidance, TLS 1.3, FIPS-validated crypto modules and NIST 800-171 for badge deployments, with immutable audit logs streamed to a SIEM. Integrations span Microsoft 365, Google Workspace, AWS, GitHub, CyberArk and Delinea. It remains a small Canadian challenger in a category dominated by the major identity providers.



