WinMagic products
Passwordless Authentication and Encryption Products
WinMagic makes two data-security products. MagicEndpoint is passwordless authentication: people log in to their device once, and MagicEndpoint keeps verifying them to the applications you define, with no further user action. SecureDoc is full-disk encryption for Windows, macOS and Linux, with passwordless pre-boot authentication on Windows and Linux. Used together, they protect your data in layers, from the moment a device powers on to your online accounts.
Frictionless security to achieve your data-protection goals.
WinMagic at a glance
WinMagic is a Canadian data-security company founded in 1997 by Thi Nguyen-Huu, who is still its CEO (WinMagic).
WinMagic's two products are MagicEndpoint, for passwordless authentication, and SecureDoc, for endpoint encryption.
WinMagic's cryptographic modules for Windows and for macOS/Linux are FIPS 140-3 validated, NIST CMVP certificates #5204 and #5214, both active since March 2026.
Three FIDO Eazy authenticators, including a TPM-based one and a phone-based one, are FIDO2 certified by the FIDO Alliance (WinMagic certifications).
SecureDoc 9.x holds OPSWAT Platinum certification for disk encryption (WinMagic certifications).
More than 97% of identity attacks are password spray or brute force attacks, according to the Microsoft Digital Defense Report 2025. Passwordless authentication removes the password those attacks guess.
Why settle for less?
Why choose WinMagic for data security?
WinMagic gives you strong data security without slowing people down. Have high data security standards? We do too. With WinMagic solutions, you don't have to compromise.
Discover data security software that protects your business while staying out of the way of productivity. From the user experience to security compliance and IT management, we've got you covered.
Frictionless authentication
No passwords or MFA prompts after one device login.
Standards-based security technology
FIDO2 protocols, TPM-bound device keys and FIPS 140-3 validated cryptography.
Layered defense model against data security breaches
Authentication and encryption controls stacked so that where one fails, the next one holds.
Which WinMagic product do I need?
Choose MagicEndpoint if your problem is passwords and MFA. Choose SecureDoc if your problem is protecting the data on your devices. Most organizations use both.
If you're struggling with…
→ MagicEndpoint
- Password or MFA fatigue
- Forgotten passwords
- Lost or compromised passwords
- User credential theft or compromise
- IT costs for password resets
If you're struggling with…
→ SecureDoc
- Keeping your data at rest safe
- Easily securing your endpoint devices
- Mitigating risks in your workplace
- Managing your security solutions (centralized management)
MagicEndpoint Passwordless Authentication
What is MagicEndpoint?
MagicEndpoint is WinMagic's passwordless, always-on authentication solution, with no user action after one device login.
It verifies the user and the device cryptographically, at the endpoint, then keeps verifying them to the applications you define without asking the user to do anything again.
Simple in every way except data security. Built on more than 25 years of WinMagic experience in endpoint security, MagicEndpoint is:
Move beyond MFA to effortless, no-user-action user authentication.
SecureDoc Endpoint Encryption
What is SecureDoc?
SecureDoc is WinMagic's all-in-one full-disk encryption suite.
It encrypts the data on laptops, desktops, servers and removable media, and checks who the user is before the operating system even starts, so a lost or stolen device gives away nothing. With WinMagic's SecureDoc, you can trust your information will be encrypted at all times.
Used in sectors where exposed data is not an option, including government, healthcare and national defense.
MagicEndpoint vs SecureDoc: what's the difference?
MagicEndpoint controls who can get into your accounts and applications. SecureDoc protects the data stored on your devices. They cover different layers, and they are built to work together.
| Feature | MagicEndpoint | SecureDoc |
|---|---|---|
| Product type | Passwordless authentication | Full-disk encryption suite |
| What it protects | Access to online accounts and applications | Data at rest on devices and removable media |
| Main problems solved | MFA fatigue, password resets, phishing, credential theft | Lost or stolen devices, data exposure, compliance |
| Where the user is verified | At the device, then continuously for the applications you define | Before the operating system loads (pre-boot, on Windows and Linux), then at Windows login |
| Key technology | Live Key (hardware-bound, TPM), compliant policies, continuous verification | FIPS 140-3 validated encryption, pre-boot authentication |
| Works with | Microsoft Entra ID, Okta and other identity providers | Windows, macOS, Linux, self-encrypting drives, BitLocker |
| Management | MagicEndpoint identity provider | SecureDoc Enterprise Server |
| Product page | MagicEndpoint passwordless authentication | SecureDoc endpoint encryption |
We don't do "good enough"
How does WinMagic's layered security work?
WinMagic protects your data with four layers, so that where one fails, the other will prevail.
The stakes are too high. With cyberattacks growing more sophisticated by the day, data security solutions must stay ahead with better and more secure technology. This urgency is why WinMagic believes in layers.
-
1
Your data. At the center, protected by every layer that follows.
-
2
Endpoint encryption. Everything on the disk stays encrypted until the user is verified. SecureDoc
-
3
Passwordless pre-boot authentication. On Windows and Linux, the user is verified before the operating system loads, so no one else gets past power-on. SecureDoc
-
4
Windows login with MFA. Multi-factor authentication at Windows login. Passwordless by default; organizations that prefer to keep a password can. MagicEndpoint SecureDoc
-
5
Live Key and continuous verification. After the endpoint login, the Live Key, a hardware-bound key that is present only while the verified user is, together with compliant policies, authenticates the user to the applications you define with no user action. The user, the device and its signals, such as the disk being encrypted, are re-verified throughout the session. MagicEndpoint
Which MFA options does WinMagic offer for cyber insurance?
WinMagic data security solutions offer MFA at three points (online applications, Windows login and pre-boot) to support your cyber insurance requirements.
Phishing-resistant MFA
MFA that can't be defeated by tricking someone into entering credentials on a fake page, the type of MFA CISA urges all organizations to implement.
MFA for Windows login
Multi-factor authentication at the Windows logon screen itself, for every user on every managed PC.
Pre-boot authentication
On Windows and Linux, the user is verified before the operating system loads, which keeps an encrypted disk locked to everyone else.
Discover WinMagic innovation
How does WinMagic's technology work?
In this video, WinMagic explains how its products verify the user and the device, and why the endpoint is the best place to do it. It covers:
- How we achieve continuous verification
- How we use FIDO2 protocols to verify the user + device
- Why the endpoint is the best choice for protecting your online accounts
- What's next for the cybersecurity industry
Latest WinMagic research and articles
All WinMagic articles →- AI made the careful attack cheap. Authentication has to change.
- AI Cyberattacks. The Industry Gives Warning. WinMagic Gives the Fix.
- When “no user action” is good design, and when it is not
- YellowKey: A New BitLocker Attack That Shouldn’t Surprise Anyone
- Why FIPS Matters Differently When the Endpoint Is the Authenticator
- Why Endpoint Encryption Is the Missing Foundation of Zero Trust
FAQ
Frequently asked questions
What products does WinMagic offer?
WinMagic offers two products: MagicEndpoint, a passwordless authentication solution, and SecureDoc, a full-disk encryption suite. MagicEndpoint controls access to online accounts and applications; SecureDoc protects the data stored on laptops, desktops, servers and removable media.
What is the difference between MagicEndpoint and SecureDoc?
MagicEndpoint is passwordless authentication: it verifies the user and device at login and then continuously for the applications you define. SecureDoc is endpoint encryption: it encrypts the disk and verifies the user before the operating system loads. MagicEndpoint protects access; SecureDoc protects stored data. They are designed to be used together.
Is MagicEndpoint phishing-resistant?
Yes. After the one device login, MagicEndpoint authenticates with the Live Key, a hardware-bound key that never leaves the device. There is no password or one-time code for the user to type into a fake page and no prompt to approve, which leaves a phisher nothing to steal.
What is passwordless pre-boot authentication?
Passwordless pre-boot authentication verifies the user before the operating system loads, without a typed password. SecureDoc offers it on Windows and Linux, where it keeps the encrypted disk locked until the right person is verified, so a lost or stolen device reveals nothing.
Which operating systems does SecureDoc support?
SecureDoc supports Windows, macOS and Linux, as well as self-encrypting drives, and it can centrally manage Microsoft BitLocker. Pre-boot authentication is available on Windows and Linux. All of it is managed from SecureDoc Enterprise Server.
Is WinMagic's encryption FIPS validated?
Yes. The WinMagic Cryptographic Module for Windows (NIST CMVP certificate #5204) and the WinMagic Cryptographic Module for macOS/Linux (certificate #5214) are FIPS 140-3 validated, both active since March 2026. Earlier SecureDoc and MagicEndpoint releases are covered by FIPS 140-2 certificates #4190 and #4192.
Does MagicEndpoint work with Microsoft Entra ID and Okta?
Yes. MagicEndpoint works as a standalone identity provider, or delegated alongside your existing identity provider, such as Microsoft Entra ID or Okta, over SAML, OIDC and WS-Federation. If you keep your identity provider, MagicEndpoint adds passwordless, continuous verification in front of it.
Can WinMagic help meet cyber insurance MFA requirements?
Yes. WinMagic offers MFA at three points: phishing-resistant MFA for online applications, MFA at Windows login, and pre-boot authentication before the operating system loads (Windows and Linux). Together with SecureDoc encryption, these cover the MFA and encryption controls cyber insurers commonly ask for.
What is zero-trust continuous verification?
Zero-trust continuous verification means the user and device are re-verified throughout a session rather than trusted after a single login. This follows NIST SP 800-207, under which no trust is implicit and trust is re-evaluated continually while access goes on. MagicEndpoint does this cryptographically in the background, with no action from the user.
Who founded WinMagic?
WinMagic was founded in 1997 by Thi Nguyen-Huu, who remains its CEO. The company is based in Canada and builds passwordless authentication and endpoint encryption software for businesses and governments.
Take a simpler approach to data security
Schedule a demo or talk with one of our security experts to learn how WinMagic can help you achieve stronger security without adding friction for your users.
Sources
- WinMagic: About us; Certifications and validations.
- NIST Cryptographic Module Validation Program: Certificate #5204, WinMagic Cryptographic Module for Windows (FIPS 140-3, validated 23 March 2026); Certificate #5214, WinMagic Cryptographic Module for macOS/Linux (FIPS 140-3, validated 27 March 2026).
- Microsoft, Microsoft Digital Defense Report 2025, October 2025.
- NIST, SP 800-207: Zero Trust Architecture, August 2020.
- CISA, Implementing Phishing-Resistant MFA, fact sheet, October 2022.
- FIDO Alliance, FIDO2.
Checked 8 October 2026.