We’re excited to announce the launch of Authsignal’s new UK data region. UK organisations can now store customer data and run authentication workloads in the UK, supported by local infrastructure, data centres and API endpoints at uk.api.authsignal.com.
It is an important step for our UK customers, giving organisations access to Authsignal’s full authentication platform with UK-based data residency and infrastructure. The timing also matters, with passkeys, digital credentials, risk-based authentication and evolving regulation pushing UK businesses to rethink how authentication works across the customer journey.
Helping UK teams adapt as authentication regulation evolves
For highly regulated organisations, the new region also provides a stronger local foundation for changing how and when customers are challenged as requirements evolve.
The direction of UK payments regulation reinforces the need for that flexibility. In its 2025 priorities for payment firms, the FCA said the government had committed to revoking the payments authentication elements of the existing Strong Customer Authentication framework, with the FCA developing a replacement approach focused on outcomes, innovation, fraud reduction and customer experience.
That direction became more tangible in March 2026, when the FCA removed fixed regulatory contactless limits and introduced an exemption that allows payment service providers to apply a more risk-based approach, subject to the relevant requirements.
Authsignal’s adaptive MFA and rules engine give teams control over authentication policy without requiring them to rebuild the underlying customer journey each time requirements or risk models change.
Supporting authentication across every customer channel
Local UK infrastructure also strengthens how Authsignal can support authentication across web, mobile, contact centre and in-person interactions. That becomes increasingly valuable as authentication spreads across more of the customer journey.
Customers move between devices and channels. They recover accounts, contact service teams, make sensitive changes and perform higher-risk actions. The security requirements may change, but the authentication policy should remain consistent.
Passkeys are part of that shift. In April 2026, the National Cyber Security Centre began recommending passkeys wherever services support them, based on its assessment of FIDO2 credentials against common credential attacks.
Passkeys strengthen routine sign-in, but they do not remove the need for recovery paths, adaptive authentication or support across assisted channels. Authsignal allows teams to apply the right authentication method based on the interaction and risk, without rebuilding security separately for each channel.
Supporting UK businesses as digital verification moves into implementation
UK teams can now bring digital credential verification into customer journeys while keeping authentication workloads and customer data in the UK. That matters as the UK’s digital verification ecosystem moves into implementation.
The certification scheme aligned to version 1.0 of the UK Digital Verification Services Trust Framework went live in September 2026, while the GOV.UK Wallet sandbox is now available to registered providers certified against the framework.
For UK businesses, this creates a more immediate need to think about how verified credentials and attributes will fit into existing customer journeys. A credential might support onboarding, account recovery or a higher-risk interaction, but the business still needs to determine what that verified information should allow the customer to do next.
Authsignal can bring digital credential verification into the same authentication layer as passkeys, adaptive MFA and other methods, allowing verified information to inform the next step rather than creating another disconnected flow.
Giving UK businesses a foundation for what comes next
For UK organisations, the combination of local data residency and the full Authsignal platform creates a stronger foundation for what comes next. That includes passkeys, adaptive MFA, digital credential verification, Number Verify, biometrics, push authentication and OTP, all orchestrated through a single authentication layer.
The timing matters because the UK authentication landscape is moving quickly. Digital verification is entering implementation, passkeys have clear NCSC backing, regulation is evolving and customers increasingly expect security to follow them across channels.
UK teams should be asking the questions now. Can authentication policy follow a customer across channels? Can new methods be introduced without rebuilding the journey around them? Can risk, authentication and verified credentials inform the same decision?
The goal is not to predict which authentication method comes next, it’s to build an architecture that can adapt when it does.
If you’re a UK organisation looking to take advantage of Authsignal’s new UK data region, talk to our team about how we can support your authentication strategy locally.
_2026-09-22_23-49-16%20(1).png)