How Stealth Mode WorksIdentification, authorisation and discreet protection working together.

Stealth Mode operates within Double PIN Technology. The system first establishes who the user is, then separately authorises the sensitive action. When a configured duress signal is used, Stealth Mode silently applies a safer policy without visibly revealing the protective response.

Policy engine active
PIN 1 identifiesWho is requesting access?
PIN 2 authorisesMay this sensitive action proceed?
Policy determines the outcomeNormal processing or discreet protection

Double PIN does not confirm the same thing twice.

Its two PINs perform different security functions. This separation prevents a successful login from automatically granting unrestricted authority over every sensitive action.

PIN 1 identifies the user

PIN 1 establishes which user or account is interacting with the system. It answers the identity question, but it does not automatically authorise a protected transaction or change.

PIN 2 authorises the action

PIN 2 is dynamic, time-bound and connected to the sensitive workflow. It grants limited authority for the intended action rather than becoming a permanent second password.

Important distinction: PIN 1 and PIN 2 are not duplicate confirmations. One establishes identity; the other grants temporary authority.

From a sensitive request to a policy-controlled outcome.

The exact user interface may vary between banking, payments, applications, documents and other integrations, but the underlying security sequence remains consistent.

A sensitive action begins

The user starts a protected operation such as a payment, withdrawal, account change, document access request or privilege elevation.

Request

The user is identified

PIN 1 identifies the user or account. In an integrated flow, another trusted system such as 3D Secure may perform this identification step.

Identity

PIN 2 is requested

A dynamic and time-bound PIN 2 is supplied for the specific sensitive action. Its usefulness expires after the configured validity period.

Authority

The signal is evaluated

The policy engine determines whether the user entered the normal authorisation or activated a configured Stealth Mode signal.

Decision

The policy is applied

The system either processes the authorised action or silently applies the configured protective outcome while maintaining a believable user experience.

Outcome

The same interface can produce very different security outcomes.

The visible workflow can remain familiar while the policy engine decides whether normal authority or discreet protection should apply.

Normal path

Valid authorisation

  • The requested action is within the allowed policy.
  • PIN 2 is valid for the intended action and time window.
  • The system processes the operation normally.
  • PIN 2 expires or becomes unusable after the configured conditions are met.
Stealth path

Protective authorisation signal

  • A configured Stealth Mode trigger is detected.
  • The system silently changes privileges, information, limits or processing.
  • The observer is not visibly informed that protection has been activated.
  • A safe, believable message or limited experience may be presented.

Three ways Stealth Mode can be triggered.

Implementations can support one or more activation methods depending on the product, risk model and configured security policy.

1

Preset policy

The user proactively activates Stealth Mode or a restrictive security state within the application before a risky situation occurs.

2

Reverse PIN entry

Entering PIN 1 or PIN 2 in reverse order can act as a covert distress signal while appearing to be an ordinary credential entry.

3

Dedicated Stealth PIN

A separate configured PIN activates the protective sequence while the interface continues to present a plausible response.

Stealth Mode changes what is possible without announcing why.

The result is controlled by policy. Different products can combine several responses according to the action, user, channel and assessed risk.

Reduce limits

Lower transaction, withdrawal or transfer limits without exposing that a protective state is active.

Change privileges

Temporarily remove elevated permissions or place the account into a restricted operating profile.

Hide information

Display limited balances, records, documents, beneficiaries or other sensitive information.

Block sensitive actions

Prevent selected operations while allowing the rest of the interface to appear available.

Allow no processing

Accept the apparent request without completing the sensitive operation behind the interface.

Return a safe message

Present a believable explanation such as temporary unavailability or an applicable limit.

Independent or integrated with an existing identity layer.

Double PIN Technology can provide both identification and authorisation, or it can complement another trusted identification system.

Independent Double PIN flow

PIN 1 performs user identification. PIN 2 then authorises the sensitive action. Stealth Mode remains available through the configured activation methods.

PIN 1IdentificationPIN 2Authorisation

Integrated identification flow

Another trusted layer, such as 3D Secure, identifies the cardholder. Double PIN Technology then uses PIN 2 to authorise the sensitive action.

3D SecureIdentificationPIN 2Authorisation
The principle

Valid credentials should not automatically mean unrestricted control.

Stealth Mode strengthens Double PIN Technology by recognising that a legitimate user may be authenticated but no longer acting freely. The system can therefore protect the user without creating an obvious confrontation.