VC-IA-001 / 7 MIN / 09 SEP 2026

Identity, devices and sessions

How VENTEX Connect separates sign-in, trusted devices, passkeys, session revocation and security events.

State: controlled production release · independent security assurance pending
MaturityCurrent product state
Review basisRepository-aligned
Reviewed2026-09-09
01

A device is not a session

A device represents the longer-lived security context of a browser or endpoint. A session is the revocable access associated with that device.

One session can therefore be ended, or a complete device and all its sessions removed, without signing out every other endpoint.

02

Sign-in and security confirmation

Accounts with a registered security key receive no session after the password step alone. The WebAuthn confirmation completes authentication.

Passkeys reduce phishing risk, but do not prove that an endpoint is malware-free or physically controlled by the intended person.

  • WebAuthn as an additional possession proof
  • Device context remains bound to sign-in
  • Removed devices remain revoked
  • Failed attempts become security events
03

Revocation and recovery

Users can review active sessions, end individual sessions, verify devices and remove devices. Administrators can revoke every session belonging to an account when required.

Device revocation, panic mode and the duress path remove related push subscriptions. On the next eligible sign-in path, the client removes account-scoped local security state including history, ratchet state, outbox, prekeys and device identity.

Local cleanup cannot physically erase an endpoint that remains offline or compromised. If deletion is blocked by an open browser context, the interface reports the condition explicitly instead of entering a reload loop.

04

Public claim boundary

Browser device identity is not hardware attestation. Device verification confirms a controlled relationship between authorised endpoints, not operating-system integrity.

Signing keys remain non-exportable. Exchange keys are preferably persisted as non-exportable CryptoKey objects; iOS/WebKit uses a documented JWK fallback when reliable CryptoKey persistence is unavailable.