HiSign for teams

Five seconds before the money moves.

A cloned voice sounds like your CFO. Before a payment is released or an MFA is reset, both people read their two words and check that the other device still holds the secret they exchanged in person.

Two phones running HiSign side by side. One lists sample contacts by name and role. The other shows a check in progress: the phrase to read aloud, the phrase to expect back, and the seconds left before both rotate.
Illustrative screens with sample contacts.

Where the check goes

The moments worth five seconds.

HiSign is a line in a procedure you already have, not a system to deploy. These are the calls teams put it in front of.

  • New or changed bank details
  • Payment and payee approvals taken by phone
  • MFA resets, password resets, and device enrollment
  • Refund and credit-limit overrides
  • Access and role changes
  • On-call escalation and after-hours instructions
  • Callbacks with named outside counterparties you have met in person

It also needs no coverage to work, which matters to a different kind of team. That is further down, under Comms that are watched, jammed, or out of range.

The risk

The attacker calls the desk.

Attackers do not need to break in if they can call in. They phone the desk with a voice you recognize and ask for the thing they want. The four calls below are composites written to show the shape of it, not reports of real events.

The changed payee

An email asks for a supplier’s bank details to be updated before the evening payment run. Minutes later the phone rings, and the voice is the Controller’s, saying he has already approved it.

The fake employee

“Hey, it’s Sam from the night shift. I got a new phone and I’m locked out. Can you reset my MFA real quick?” It sounds like Sam. It is not Sam.

The fake supervisor

“This is Dana. I need you to override the refund limit on this account, customer is escalating.” A cloned voice plus urgency is how limits get bypassed.

The fake IT desk

“IT here. We’re migrating accounts tonight, I need you to read me the code we just sent you.” Both directions of the helpdesk call can be spoofed. HiSign gives both sides a phrase pair to check.

What the check is

No signal. No server. Nothing to phish.

Both phones derive the same phrase pair from a secret they already hold. The keys and the clock live on the device, so there is nothing to reach for when you speak.

Exchanged in person

The secret is created device to device by NFC tap or QR scan, with both people in the same room. Nothing leaves the room, and there is no HiSign server holding it afterwards.

Fresh every 60 seconds

A new phrase pair every minute. Anything an attacker overhears is dead before the call is.

Rides on the call you are already on

Two spoken words are the whole check. Desk phone, cell, softphone, two-way radio, satphone, or face to face.

Off-grid teams

Comms that are watched, jammed, or out of range.

Some teams work where the radio is watched, jammed, or simply out of range, and where the wrong instruction gets someone hurt. The check needs no coverage, because both phrases come from the devices.

Maritime & offshore

There is no cell coverage offshore. Crews pair with the captain and with shore operations before they sail. After that a VHF or satphone check takes two words, before anyone acts on a divert or a payment instruction.

Field crews & reporters

Reporters and field staff pair before they split up. After that a satphone check takes two words, and there is no roster or codebook on anyone to find.

This only covers people who paired. Crews from different agencies meeting for the first time at an incident have no phrase pair to compare, so HiSign says nothing at all about a call between them.

Rollout

Set up in one team meeting.

For a team of 10 to 20 people, setup happens in a single huddle. Here is the whole rollout.

  1. Everyone installs

    Each person downloads HiSign on iPhone or Android and creates their identity card. Two minutes, no account, no signup.

  2. Pair at the huddle

    At one team meeting, everyone pairs with everyone by scanning QR codes or tapping phones. This in-person step is what gives every pair a secret no attacker was there to receive.

  3. Set the rule

    Write one line into your procedures: MFA resets, refund overrides, access changes, and payment instructions require a HiSign check first. No exceptions, even for the boss.

  4. Check in five seconds

    On any sensitive call, both people open the app and say their two words. Match means proceed. No match means hang up and report it.

  • Customer support and success desks
  • IT helpdesks and MFA reset queues
  • Call centers handling account changes
  • Finance and AP teams that approve payments by phone
  • On-call rotations and escalation chains
  • Managers, associates, and trusted outside vendors

Tell us what you’re protecting.

We take questions about pilots, rollouts, and off-grid use. If today’s app does not cover your roster, we would rather say so in the first email than at a pilot review.