How TAA SECO works

Protect trust before the attack. Reduce exploitation after compromise.

A cyberattack does not necessarily end when the compromised system is restored. Stolen customer, employee, partner or user data can later be used for impersonation, social engineering and fraudulent instructions. TAA SECO is designed to add a further trust layer before an incident and after information has already been exposed.

Before & after compromise

The protection objective continues after data has been stolen.

TAA SECO complements existing cybersecurity by protecting the trust relationships that attackers may try to exploit around identities, communications, transactions and authorized interactions.

BEFORE

Prevent · Authenticate · Discourage

Reduce opportunities for fraudulent exploitation by strengthening transaction security, communication authenticity, identity context and trust checks before a sensitive action.

AFTER

Reduce exploitation · Verify · Protect

When real information has already been copied or disclosed, reinforce checks so possession of that information alone is not treated as sufficient proof of legitimacy.

BEFORE & AFTER

Restore and preserve trust

An organization may introduce the protection layer before an incident or after a compromise, when confidence in identities, communications and counterparties needs to be rebuilt.

Core principle

Stolen data should not automatically become proof of legitimacy.

An attacker may know a customer’s name, telephone number, address, bank, employer or other real details. Those facts can make a false story more convincing, but they do not prove that the caller, sender, website, representative or transaction destination is legitimate.

TAA SECO is designed to introduce additional references and trust checks around the identity, communication, recipient or context the user believes to be authentic.

Beyond strong authentication

A user can be correctly authenticated and still be manipulated into a fraudulent action.

Strong authentication primarily answers: is this really the user performing the operation? That protection is essential, but a legitimate user may still authorize a fraud if they have been deceived about who they are dealing with or what they are authorizing.

Within the combined TAA-TPV framework, SECO can add a separate verification reference around the identity, recipient or context the user believes is legitimate. TAA adds a further concern for situations where the legitimate user may be under pressure or coercion.

The architecture in practice

Four public components, distinct roles.

See the canonical technology architecture →
TAA

Transaction security & anti-coercion

The first invention adds protection around sensitive transactions, communications and situations involving manipulation or coercion.

TPV

Controlled trust & pseudonymization

The second invention supports trust decisions when dealing with unknown or not personally known counterparties and can provide controlled identity-status context.

SECO

Public security-identification code

SECO is a public security reference derived from the TAA framework and intended to help compare an apparent identity or destination with a separate trusted reference.

AOM

Affiliation & mission verification

AOM uses the TAA/SECO infrastructure to support verification of organizational affiliation and, where applicable, the authenticity or status of a claimed mission or authorization.

What is SECO?

A public security reference separate from the identifier you already see.

SECO — Secure External Code is a public security-identification code derived from the TAA framework. Depending on the service, it may be associated with a telephone number, email address, website, application, digital account, financial identifier, business, company, institution, product, service or another compatible element.

The objective is not to replace existing identifiers. It is to give users another reference to compare before deciding whether the visible identity or destination is consistent with trusted information.

For organizations

A controlled path from declaration to verification.

The precise verification criteria depend on the identity or service concerned and on the applicable deployment framework.

01Declaration
The partner identifies the elements it wishes to protect, such as its name, website, telephone number, email address, application or another compatible identifier.
02Security reference
Compatible elements can be associated with a SECO security reference presented through approved public-facing channels.
03Verification
Declared information is assessed under criteria appropriate to the service. Depending on deployment, the public interface may present a verification status or other trust signal.

Physical interactions

AOM can extend trust beyond the screen.

Not every impersonation attempt happens online. A person may appear as a technician, employee, institutional representative, delivery person or other supposedly authorized agent while using real information to make the story credible.

AOM is designed to add a verification layer around organizational affiliation and, where the deployment supports it, the existence, validity, expiry or revocation of a mission or authorization.

Reducing the burden on users

Technology should support vigilance at the moment trust is tested.

Advice such as “do not click,” “verify the number,” “call us before acting” or “be cautious with unexpected visitors” remains important. But people may need to decide under stress, urgency or fear. TAA SECO is intended to add system-level indications and controls rather than leaving the entire decision to human judgment alone.

A layer of protection, not an absolute promise

No serious security system can guarantee that every cyberattack or fraud attempt will fail.

TAA SECO is intended to complement — rather than replace — banking controls, telecommunications security, identity systems, strong authentication, cybersecurity measures and appropriate human verification. Its objective is to reduce the exploitability of compromised information and strengthen trust decisions around identities, communications, transactions and missions.

Production use remains subject to technical feasibility, institutional integration, governance, privacy and applicable regulation. Protected implementation details remain outside the public disclosure layer.

Legal & public disclosure

Already experienced a compromise?

Protection can also begin after the incident.

An organization may evaluate TAA SECO after a breach or data exposure to strengthen subsequent protection of clients, employees, partners or users against impersonation and social-engineering attempts.

Discuss a post-compromise protection context →