H&F Supports Ideem’s Passkeys+ Expansion Through Hyperstacks’ Digital Banking Platform in the Philippines
- 4 days ago
- 5 min read
Manila, Philippines
H&F is supporting Ideem’s market development in the Philippines as Passkeys+ is integrated into Hyperstacks composable digital banking platform, giving BSP-regulated institutions a more direct route to device-bound, phishing-resistant authentication.
H&F is supporting Ideem’s expansion in the Philippines as the company brings its Passkeys+ authentication technology into the country’s digital banking ecosystem through Hyperstacks.
The collaboration connects Ideem’s device-bound passkey capability with Hyperstacks composable digital banking platform, creating a clearer route for banks, electronic-money issuers and other BSP-regulated financial institutions to introduce phishing-resistant authentication across their digital services.
The development comes as Philippine institutions review the role of SMS one-time passwords in their customer journeys. OTPs have been a familiar way to add a second factor of authentication, but the method is increasingly exposed to phishing, social-engineering attacks, SMS interception and account-takeover fraud. At the same time, banks are under pressure to strengthen their controls without asking customers to accept a more difficult sign-in experience or undertake a large-scale rebuild of the services they already use.
BSP Circular 1213 has added further momentum. The circular reinforces expectations around stronger authentication, automated fraud monitoring and real-time responses to suspicious activity, bringing the shift away from methods that can be phished or intercepted higher up the agenda for regulated institutions.
![]() |
For H&F, the opportunity is a clear example of how market development in financial services depends on more than the quality of the technology itself. Product capability, regulatory timing, local infrastructure and a practical implementation model all have to come together before a solution can move from interest to adoption. Ideem’s Passkeys+ is built on device-bound FIDO authentication for regulated financial environments. Instead of relying on a password or an SMS code, it uses a cryptographic credential protected on the customer’s device. Customers can approve access with familiar device controls, such as biometric authentication or a local PIN, while the institution receives cryptographic proof that the request is legitimate.
This removes the shared secret that makes OTPs vulnerable. A customer does not need to enter a reusable password or disclose a temporary code, leaving less for an attacker to steal, intercept or persuade them to share. The credential is associated with the legitimate digital service, reducing the risk that it can be replayed on a fraudulent website designed to imitate a bank.
Ideem also binds the credential to a trusted device through its Zero-Trust Secure Module. This allows an institution to establish not only that the correct credential was used, but that it came from the expected device.
That distinction is important for banks. Consumer passkeys can be designed to synchronise across devices for convenience, but regulated financial institutions may require more explicit control over credential migration, device replacement, high-risk actions and the evidence available for audit and risk management. Ideem’s approach is designed to preserve the convenience of passkeys while meeting those more demanding requirements.
Hyperstacks provides the local infrastructure layer that makes the proposition more immediately actionable. Its platform enables digital banking channels for banks, electronic-money issuers and other regulated institutions, while connecting them to domestic payment rails including InstaPay and PESONet. By integrating Passkeys+ into this environment, Hyperstacks makes stronger authentication available through infrastructure that institutions already use to deliver digital banking services. Rather than treating passkeys as an isolated, custom technology project, banks using the platform can consider them as an extension of their existing digital stack.
This can reduce duplicated integration work, shorten the path to implementation and lower the organisational burden of introducing a new security control. It also gives institutions a practical way to respond to the growing need for phishing-resistant authentication without disrupting the customer experience that customers already trust.The integration does not remove the need for careful deployment. Banks will still need to define how customers enrol, recover access, replace devices and manage exceptions. They will need to account for customers with older devices, limited connectivity or particular accessibility needs. Fraud, compliance, customer-service and technology teams will all need to be involved in the design of the new journey.
What changes is the starting point. Institutions do not have to approach stronger authentication as a complete redesign of their mobile and web services. They can assess a device-bound passkey model through a platform that is already connected to the operational realities of Philippine banking. Authentication has traditionally been treated as a necessary security checkpoint between a customer and the service they want to use. In digital banking, it is increasingly part of the product experience itself.
Friction Points | User experience Tax |
OTP delay | Can interrupt an urgent transfer |
Failed login | Prevent a customer from accessing essential account information |
Confusing recovery process | can undermine confidence at the precise moment when reassurance matters most. |
TOTP | difficult navigation, search and time on task |
These points of friction influence both security and whether customers continue to use a digital service.
Passkeys provide an opportunity to make the security step feel simpler while increasing the strength of the control behind it. Customers can authenticate with the familiar action of unlocking a trusted device rather than remembering a password or waiting for a message. For institutions, the same shift can bring stronger device assurance, lower exposure to phishing and a clearer evidential basis for managing authentication risk.
That matters in a market where digital services can extend financial access to people for whom a branch visit requires substantial time or travel. Reliability is not simply a convenience measure. It is part of whether digital banking delivers on its promise of accessible financial services. H&F’s role is to help bring these elements together in a form that fits the market. That means aligning Ideem’s technology with Philippine regulatory priorities, establishing the right implementation and distribution relationships, and ensuring the commercial proposition reflects the practical needs of financial institutions and their customers.
This is not expansion through presence alone. It is expansion through fit: a security capability that addresses a real risk, a local infrastructure provider with an established place in the market, and a route to deployment designed around how institutions actually operate.
For Philippine banks, the immediate value is a more direct pathway to phishing-resistant, device-bound authentication across mobile and web. It offers an alternative to the risks and friction associated with SMS OTPs, while allowing institutions to build on the digital banking infrastructure they already run.
For customers, the goal is straightforward: a faster, simpler and more reliable way to prove that an access request or transaction is genuinely their own.
The move beyond OTPs will not occur at the same pace across every institution. Yet the direction is clear. Authentication is moving away from shared secrets and towards cryptographic trust; away from isolated credentials and towards verified devices; and away from cumbersome security steps and towards experiences designed to be both safer and easier to use.
With Ideem’s Passkeys+ integrated into Hyperstacks’ platform, H&F sees a credible path for Philippine institutions to begin that transition from a stronger position.




