Cosigner Authentication – Proof Help Center
Cosigner authentication in Proof is an automatic security feature for co-located signers sharing a device, requiring existing users to verify their identity via an emailed PIN while new users proceed without one, and restricting users with advanced security (MFA or SSO) to complete transactions only on separate devices.
The short answer: Cosigner authentication is an additional security layer that verifies the identity of co-located signers when multiple signers share a single device to complete a transaction. It is automatically enabled for all organizations that use co-located signing.
How it works
Co-located signers have different experiences depending on whether they already have a Proof account:
- 1.New user
- Proceeds with the transaction as usual — no PIN required.
- 2.Existing Proof user
- Receives a personal identification number (PIN) at the email address associated with their Proof account.
- Provides the PIN to verify identity.
- Proceeds to the transaction on the shared device.
- 3.Existing user with advanced security (e.g., multi-factor authentication or single sign-on)
- Cannot complete the transaction on a shared device.
- Must use a separate device to maintain the integrity of their advanced security settings.
If a signer doesn't receive the PIN, they can verify the email address is correct, check their spam folder, or select the link to resend the code.
Summary Checklist
- Automatically enabled for all orgs using co-located signing — no setup required.
- Existing users receive a PIN by email. New users proceed without a PIN.
- Users with MFA or SSO must use a separate device — they cannot complete on a shared device.
Still unsure? Contact Proof Support for help.
Related
SaaS Security Has an Identity Problem
The article argues that SaaS security's traditional focus on authentication methods like passwords and MFA fails to address the critical need for verifying the actual user identity behind actions within SaaS products—such as who changed billing or promoted admins—highlighting that rapid product-led growth and widespread SaaS adoption have exacerbated identity-related risks like fake signups and credential theft, which impact security, product operation, and business growth.
23 NYCRR Part 500 Is a Regulatory Shift from Authentication to Attribution
The updated 23 NYCRR Part 500 regulation by NYDFS, completed in November 2025, mandates stronger multi-factor authentication and governance for financial institutions, signaling a shift from traditional authentication methods based on secrets to a more robust architectural approach that addresses the industrialized and sophisticated nature of modern credential theft and systemic cyber risk.
How Financial Institutions Can Keep Customers Safe with Authentication
The article emphasizes that financial institutions must implement strong, layered, and biometric-based authentication methods—moving toward passwordless solutions and combining identity verification with fraud intelligence platforms like Proof—to effectively combat rising threats such as account takeover, credential stuffing, and SIM-swapping, thereby protecting customer assets, maintaining trust, and ensuring regulatory compliance.
How To Protect Your Business From Digital Identity Fraud
Digital identity fraud poses a significant and growing threat to businesses, involving complex tactics like phishing and synthetic identity theft that exploit multiple digital channels to steal sensitive information, resulting in substantial financial losses, and necessitating a layered defense strategy including multi-factor authentication, identity verification, proactive monitoring, and regular audits to effectively protect against and respond to such attacks.
Deepfakes and Real Estate Fraud
The article discusses how AI-generated deepfakes, created using technologies like Generative Adversarial Networks, have become a significant threat to the real estate industry by enabling fraudsters to impersonate property owners and authorize fraudulent transactions, highlighting the industry's vulnerability due to high-value deals and outdated verification methods, and emphasizing the need for advanced, layered security solutions like biometric analysis and live supervised verification to effectively detect and prevent such sophisticated scams.
Turning Account Recovery Into a Seven-Figure Business
In 2023, the threat group Scattered Spider used social engineering tactics like impersonating IT staff and voice phishing to infiltrate major casino operators MGM Resorts and Caesars Entertainment, causing hundreds of millions in damages, and since then, similar groups Cordial Spider and Snarky Spider have adopted this identity-focused attack playbook—targeting various industries through phone-based phishing to steal credentials and MFA tokens in real time, enabling rapid data exfiltration and extortion demands reaching seven figures.