One rules engine applied consistently across app, web and assisted channels, with passkeys for frequent travellers.
Loyalty balances are liquid and attractive, and travel customers move between app, web, kiosk and contact centre within a single journey. Inconsistent verification across those channels is where abuse concentrates — an attacker who cannot get past passkey-protected app login may still succeed by calling the contact centre and relying on weaker, ad hoc verification there.
At the same time, frequent travellers expect fast, low-friction access on their own devices across every booking and redemption, which makes uniform, heavy-handed verification an equally poor answer to the same problem.
The same rules engine and verification standard applies whether a member is redeeming points in the app, on the web, at a kiosk or through a contact centre agent, closing the gap that abuse typically concentrates around when channels are governed inconsistently.
Members who travel and log in often can move to passkey-based authentication on their own devices, reducing friction on repeat access while remaining phishing-resistant, without requiring the whole membership base to adopt passkeys at once.
Points redemption, transfers and contact-detail changes each carry their own risk profile and can be assigned a step-up requirement independent of ordinary login, so casual account browsing and itinerary checks stay frictionless.
Call Connect extends the same challenge used in the app or web portal into the contact centre, so an agent handling a redemption or account change over the phone applies an equivalent standard rather than a separate, weaker process.
A unified event record across channels gives fraud and loyalty teams visibility into a member's authentication history regardless of which channel they used, supporting investigation when a redemption or change is later disputed.
A single policy set governs app, web, kiosk and contact centre rather than separate rules per channel.
Phishing-resistant authentication for frequent travellers on their own registered devices.
Extends digital-channel verification standards into agent-assisted interactions.
Redemption, transfer and contact-detail changes can each carry an independent verification requirement.
A consistent challenge history across channels supports dispute handling and fraud investigation.
A member's contact details are changed, and shortly afterwards a large points balance is redeemed from a device the account has never used before. If the redemption were attempted through the app, the rules engine would flag the combination of a recent contact-detail change and an unrecognised device, and require a step-up challenge before the redemption proceeds. Because the same rule set governs the contact centre, an attacker who instead calls in and asks an agent to process the redemption manually faces the same requirement — the agent triggers the challenge through Call Connect rather than approving the request on the strength of a conversation alone, closing the gap that channel-by-channel policies would otherwise leave open.
CyberLane helps loyalty and travel operators identify where channel-by-channel inconsistency in verification is creating exposure, and designs a single rules framework that can be applied across app, web, kiosk and contact centre. We support requirements definition, Call Connect workflow design for agent-assisted interactions, and the business case for a phased rollout, before planning a proof of concept and overseeing implementation with Authsignal or a qualified partner.
CyberLane is independent and works on the decision rather than the deployment. Product-specific delivery is coordinated with the vendor or a qualified implementation partner.
Capability descriptions are based on the vendor's published materials; CyberLane's wording is independently written.
We start with an independent conversation about where your exposure actually sits, before any technology decision is made.