Where Things Live
PTERI keeps keys, biometrics and signing on the user device, while Kakr infrastructure handles verification only.
Authentication Flow
The canonical PTERI login sequence — challenge, biometric approval, signature, and server-side verification with no shared secret.
Key Custody
Private keys live in the Secure Enclave or a hardware Keystore, biometrics gate key usage locally, and Kakr never receives them.