How GovTech Singapore makes security invisible within Singpass

Resilience goes beyond securing Singpass’ own systems, but also ensuring that it catches abuse happening downstream and the broader ecosystem services, says Senior Director of Singpass at GovTech Singapore, Winston Teo.

Senior Director of Singpass at GovTech Singapore, Winston Teo. Image: GovTech Singapore

More than five million Singapore residents get through the services they need with a few taps on the Singpass app. 

 

Behind that ease of accessing services is what the Senior Director of Singpass at GovTech Singapore, Winston Teo, calls a “trust infrastructure,” covering identity, authorisation, consent, signing, fraud detection, data sharing, and the platform capabilities that public agencies and businesses rely on. 

 

Is it a tension to keep it secure and resilient on one hand, while ensuring the app remains simple enough for everyone to use? 

 

Speaking to GovInsider, Teo shares how simplicity and security are not necessarily opposite ends of the spectrum. 

 

“When risks emerge, it is easy, and sometimes necessary, to bolt on another security step.  

 

“But if that becomes our default response, we risk creating a system that people avoid because it is too cumbersome to use,” he explains. 

 

Instead of applying a blanket security intervention across everything, the Singpass team first assess the risk and level of assurance needed, then decide on the intervention appropriate to that risk. 

 

“The best solutions are often the ones where security and simplicity reinforce each other,” he says, adding that he will share more about how Singpass continues to evolve as a trust infrastructure at GovTech Singapore’s upcoming STACK conference.  

Earning trust at every level 

 

Teo emphasises that the government has to keep earning the citizen’s trust in the Singpass system, and not assume that trust is in place just because Singpass is a government system. 

 

He explains what it means to earn trust at several levels.  

 
Prior to launching Singpass passkeys, the Singpass team engaged with citizens to gather feedback on passkeys that is designed to protect against phishing scams. Image: GovTech Singapore

At the individual level, residents want to be able to access Singpass when they need it, and to know their identity and data are protected and shared only with their consent.  

 

As residents use their Singpass information to make real-world decisions, they need to trust that the right level of verification has been carried out in the system and that the information provided is accurate, he explains. 

 

At the ecosystem level, Teo’s team makes it difficult for scammers or fraudsters to abuse Singpass accounts.  

 

“Trust is not a feature that we ship once and move on from,” he explains, highlighting that the team continues to learn from real-world feedback through every interaction and iterate on the product. 

Resilience is an ecosystem play 

 

Resilience goes beyond securing Singpass’ own systems, but also ensuring that it catches abuse happening downstream and the broader ecosystem services that rely on Singpass. 

 

On securing Singpass’ systems, Teo says: “we need strong infrastructure, good recovery, reliable audit trails, and solid security foundations.” 

 

He cautions that a trusted identity can still be used in an untrustworthy transaction. 

 

A resident may log in genuinely because a scammer has tricked them. Or a Singpass account may look normal to one service, but becomes suspicious once activity across several services is tracked. 

 

“Our security boundary therefore cannot end with the conclusion that "Singpass authenticated the user successfully,” he stresses. 

 

While authentication establishes who completed the action, it does not establish that the transaction is trustworthy. 

 

This is where he talks about ecosystem trust, which is spotting patterns and sharing appropriate signals across the services that rely on Singpass, and working with public agencies, businesses and law enforcement partners to stop abuse.  

 

According to him, the challenge is doing this while respecting clear boundaries around privacy and the use of data. 

 

“Singpass’ resilience depends both on the strength of Singpass itself and the health of the ecosystem built around it,” he says. 

How AI makes security invisible 

 

“A lot of the protection happens without the user ever seeing it,” says Teo, highlighting the role of data science and machine learning in securing Singpass accounts. 

 

The technologies allow his team to look for patterns across devices, accounts and transactions “that would be very difficult for an individual user to recognise.” 

 

The signals are then surfaced to Singpass’ Trust & Safety team, so that they can investigate further and decide on the appropriate response. 

 

The use of data also extends to understanding where Singpass users struggle with when transacting. 

 

“If we see the same users repeatedly failing at a particular point or contacting our helpdesk for the same reason, we fix the underlying experience rather than expect users to keep working around it,” he says. 

 

The recent implementation of passkeys is another example of how GovTech Singapore balances security and simplicity. 

 

Teo describes passwords as "inconvenient and susceptible to phishing".  

 

Rather than adding more protection around them, passkeys move Singpass towards a mechanism that tackles the risk while making the experience easier for users.  

 

 

He adds that users do not necessarily need to understand GovTech Singapore’s risk engines, cryptography or technical jargon. 

 

“The system should do as much of that work as possible,” he explains, sharing that the only exceptions are when the user must approve an important transaction, share personal data or provide additional assurance.  

 

Then, Singpass should be clear about what is happening and why, he says. 

 

His test is to ask the question: “does the user actually need to do something here?” 

 

If not, the complexity stays behind the scenes. If so, the action and its purpose should be clear, with "a recovery path if something goes wrong". 

 

Security, usability and recovery are considered together in the product design, rather than with one or more bolted on after. 

Measuring the security-simplicity balance 

 

Security controls shouldn't be judged only by the risk they stop. They also need to be judged by their cost to legitimate users, says Teo. 

 

While security teams worry about allowing something malicious through, product teams worry about stopping someone legitimate, he says. 

 

He shares an example when the scam landscape shifts, his team sometimes tightens controls around higher-risk transactions, and some legitimate users are inevitably caught by them.  

 

While an extra layer of biometric security, such as face verification, may be justified by the risk it tackles, it can be frustrating for a user trying to complete an urgent government transaction, he notes. 

 

“A good system has to care deeply about both [security and simplicity],” he notes. 

 

On measuring the security-simplicity balance, Teo says there is no single metric, and the important thing is to look at the whole journey where “legitimate users should be able to get things done easily, while suspicious activity becomes harder to carry out and easier for us to detect and contain.” 

 

On what Teo is most proud of among the things users never see, he points to the team rather than a capability.  

 

“Most users may never see the people behind Singpass, but their commitment is a big part of what makes Singpass what it is today.” 

 

STACK Conference 2026

 

Catch Winston at STACK Conference 2026, where he will share more on how Singpass uses data and AI to strengthen trust, security, and resilience while keeping digital experiences simple and seamless. 

 

Early-bird prices are available until 14 Oct, sign up here now!