How it works in a data room
When a user registers a passkey, their phone or laptop creates a private key that stays on the device and a public key that the data room stores. At login, the room sends a challenge, the device signs it after the user unlocks it with biometrics or a PIN, and the room checks the signature. No reusable secret crosses the network, and the key is bound to the real website address, so a lookalike phishing page cannot collect anything useful. Passkeys follow open standards published by the FIDO Alliance and can sync across a user’s devices or stay on a single hardware key.
Why it matters in a deal
Phished passwords remain a leading cause of account takeover, and deal participants are attractive targets because their inboxes and rooms hold price-sensitive information. Codes sent by text message help, but they can still be relayed by a convincing fake login page. Passkeys remove that path. For external bidders who will not join the seller’s single sign-on, passkey support is one of the strongest login options a room can offer.
Example
A fintech target worries that bidders’ junior staff will be phished during a busy auction. The seller’s adviser chooses a room that supports passkeys and asks every bidder group to register one before access is granted. Two weeks later, a phishing email imitating the room’s login page circulates, and it captures nothing usable. The financial services and fintech guide covers sector expectations.