Location-aware risk assessment can help an app recognize routine mobile activity and reserve extra login steps for suspicious situations. It is best understood as a contextual signal in adaptive authentication—not as proof of identity, a replacement for strong authenticators, or a formal NIST assurance level.
What is zero-factor authentication?
In an October 4, 2021 BetaNews Q&A, André Ferraz, then CEO of Incognia, described zero-factor authentication (0FA) as a passive, mobile-native approach that evaluates location, network, and device data in the background. The idea is to assess the context of an activity without asking the user to complete an authentication action every time.
Incognia’s current product page describes 0FA as rule-based evaluation of network, location, and device signals within a continuous adaptive risk assessment. In practice, that makes it a way to inform an app’s decision about whether to allow an activity with little friction or request another authentication step.
The term is a vendor label, not a separate authentication assurance level defined by NIST. Location and device signals can add context, but they do not by themselves demonstrate that the person holding a phone is its legitimate owner.
#1 Best Overall
How does location technology enable a 0FA approach?
Ferraz’s interview described a “trusted location” as somewhere in a person’s routine, such as home, an office, or a favorite restaurant. Incognia says its approach can combine GPS with Wi-Fi, Bluetooth, cellular, motion, and device signals, then compare the observed environment and behavior with past patterns.
This is a risk-scoring concept: several signals can make a login appear more or less consistent with expected use. The company’s product page also describes device intelligence and suspicious-device watchlists. The vendor describes combining signals to detect anomalies; GPS alone can be spoofed, and the approach should not be treated as impossible to evade.
Rank #2
A location mismatch is not proof of fraud. A legitimate customer may travel, move home, use a different network, or have location services unavailable. Conversely, a familiar place does not establish that the current user is authorized. Location is useful as one input to a decision, not as a stand-alone identity credential.
What could change for users and organizations?
Used carefully, contextual risk assessment may reduce unnecessary prompts for routine, lower-risk activity and reserve step-up checks for behavior that looks unusual. The practical benefit depends on how an organization sets its rules, what signals its app can collect, and what it does when signals are missing or ambiguous.
Free tools Windows power users keep installed
One-click scans. No signup required.
Incognia reports that 90% of logins and 95% of sensitive transactions occur from trusted locations, and that its location-enabled fraud rate is below 1 in 100,000,000. Its page also cites a willbank case study reporting 93% frictionless authentication, a 90% reduction in fraud losses, and a 0.0013% false-positive rate. These are vendor-reported figures; the cited material does not establish enough about study design, population, geography, time period, or independent replication to treat them as general industry benchmarks.
Those claims illustrate the intended trade-off, not a guarantee for another app or population. Organizations should judge the system against their own threat model and measure both fraud outcomes and legitimate-user friction.
Rank #4
Does 0FA meet the same standard as multifactor authentication?
No. NIST SP 800-63B Revision 4 defines Authentication Assurance Levels for remote authentication to government information systems. At AAL2, an application must prove two distinct factors and offer a phishing-resistant option. AAL3 requires a phishing-resistant authenticator with a non-exportable authentication key and two distinct factors. Passive recognition of a place or device is not, by itself, the two-factor proof described by those requirements.
NIST identifies a dedicated security key as one example of hardware that can protect an authentication key from host software. A security key supplies cryptographic evidence in a way that location-based risk signals do not. Depending on the service and its requirements, an organization might use contextual signals to decide when to prompt for a stronger authenticator rather than treating those signals as a substitute.
Are 0FA and zero trust the same?
No. 0FA refers to a passive authentication or risk-scoring method; zero trust is an architectural approach to protecting resources. NIST SP 800-207 says zero trust grants no implicit trust based solely on an asset’s physical or network location or ownership. Being at home or on a corporate network should therefore not, by itself, make a login trustworthy.
The two ideas can coexist: an organization may use location as one contextual signal within a zero-trust system, while still requiring authorization decisions based on the protected resource and other relevant evidence.
What should organizations weigh before using location signals?
- Friction versus assurance: Decide which actions can proceed with low friction and which require a phishing-resistant authenticator or another step-up check.
- Travel and recovery: Provide a safe route for legitimate users whose normal location changes or whose phone cannot supply location signals. A mismatch should trigger review or another check, not an automatic conclusion of fraud.
- Spoofing and device compromise: Treat location as a risk input, not a guarantee. Assess how the system responds to spoofed signals, compromised devices, or missing telemetry.
- Privacy and consent: Explain what location and device data the app collects and why, and establish deployment-specific consent, retention, and sharing practices. The 2021 interview mentions opting in, but the available sources do not establish those practices for every deployment.
- Evidence for performance: Validate vendor claims with the organization’s own population, threat model, baselines, and measurement period before relying on them operationally.
For readers, there is no accessory that turns an ordinary personal login into Incognia-style 0FA: the described capability is an enterprise and mobile-app service using phone signals. A FIDO or other hardware security key is a distinct option for phishing-resistant authentication where a service supports it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

