The login proves who arrived. SpiAlert proves who stayed.
Every authentication system trusts a session from login to logout. SpiAlert closes the post-authentication trust gap by verifying, second by second, that the authorized human remains present throughout the session.
Authentication ends at the door. The risk lives inside the room.
Identity providers confirm a user at login and then trust the session. That leaves a window, from the moment of login to logout, where no system verifies that the same human is still there.
The credential gap
Stolen or phished credentials let an attacker inherit a live session. Once past login, they look exactly like the authorized user for the rest of the day.
The walk-away gap
A workstation left unattended stays trusted until a policy timeout. In shared clinical, branch, or trading environments, the session can belong to the wrong person in seconds.
The remote and BYOD gap
On remote and personal devices, the authenticated machine is no longer under the authenticated person's control. Device trust is not human trust.
Once the door opens, nothing checks who's still in the room.
However access is gained, a stolen credential, a hijacked session, or lateral movement once inside, no identity architecture rechecks the human once the door is open. Two independent research organizations, using different methods, keep finding the same shape of problem.
Credential abuse, tracked across the full breach chain, sits at the top of all breach patterns, more than any single vector measured.
Verizon, 2026 Data Breach Investigations ReportIdentity weaknesses were exploited in the large majority of incidents investigated last year, Unit 42's broadest measure of identity's role in a breach.
Palo Alto Networks Unit 42, 2026 Global Incident Response ReportIdentity-based techniques drove initial access in most investigated breaches, ahead of phishing and vulnerability exploitation alone.
Palo Alto Networks Unit 42, 2026 Global Incident Response ReportThese figures come from separate reports with different methodologies and measure different things, initial access, cumulative involvement across a breach, and credential-specific abuse. They are not additive and should not be summed. Each is cited to its own source.
Auto-enroll. Verify continuously. Let access follow presence.
SpiAlert overlays your existing identity stack. No rip and replace, no new hardware.
No enrollment step for your users
SpiAlert builds each user's presence baseline automatically from their first authenticated access, or from an existing directory or badging record. There is nothing for the user to set up, no proximity readers, and no special hardware. It is hardware-agnostic and works with standard webcams.
Confirm the human across every access point
After that first authentication, SpiAlert verifies the same human second by second across corporate access: on-device sessions, physical entry, and remote connections. Only irreversible mathematical descriptors are sent for matching, never raw video.
Access follows the person
A sovereign server issues a presence attestation that your identity provider and applications can check. The moment the trusted person is no longer present, access is denied and the screen is protected immediately, then revealed the instant they return.
One console for presence, risk, and events.
- Presence and events in one place. Every presence confirmation, absence, and anomaly is captured against the standard event taxonomy and surfaced to your team.
- Risk over time. Track presence-driven risk by user, device, and time window, and export to your existing SOC or SIEM.
- Built for the security operator. Device and user management, groups, roles, and audit views, designed for the people who run identity day to day.
Continuous human presence solves a problem nothing else in your stack was built to solve.
SpiAlert works alongside the tools you already run, and it is the piece most zero trust models assume exists but do not actually provide: continuous verification of physical human presence, not continuous evaluation of device signals or behavior. Here is precisely where it fits.
| Dimension | Legacy identity and MFA | SpiAlert |
|---|---|---|
| When it checks | Once, at login | Continuously, second by second |
| What it trusts | The device or the token | The verified physical human |
| If credentials are stolen | Attacker inherits the session | They are useless without the trusted human. Access is denied. |
| User experience | Repeated prompts and timeouts | Passive background verification |
| Response posture | Reactive, after the event | Proactive: the screen is protected the moment the person steps away, and revealed when they return |
Your login system answers one question. It was never built to answer the second.
Your identity provider confirms who logged in. That is its job, and it does it well. But it was never built to keep checking if that same person is still the one at the keyboard, no login system was. SpiAlert adds that missing piece using the security standards your systems already speak, without taking control away from your identity provider.
Your login checks identity once. SpiAlert keeps checking for a trusted human for as long as the session lasts.
SpiAlert closes a gap every login system shares: none of them recheck who is still there once you are in. Your identity provider can check with SpiAlert the same way it already checks for extra verification, right after login, before a sensitive action, or continuously for as long as the session runs.
Checked for as long as the session lasts
Your identity provider checks with SpiAlert the same way it already checks for extra verification, and gets a simple answer: is the trusted human still at the device where this session started? It can check right after login, before a sensitive action, or when an AI agent is about to act outside its approved scope, confirming it is still the same person who launched it.
Passive, so it never interrupts the person
Verification runs in the background, second by second. There are no codes, no push notifications, and no prompts. The person keeps working while their presence is confirmed, so security never costs anyone productive time.
Bound to the device the session started on
Presence stays tied to the device and session where the login began. If the trusted person steps away, or the session is being driven from somewhere else, presence cannot be confirmed, and your identity provider can deny, step up, or revoke access.
Cross-platform coverage. SpiAlert runs as a lightweight, operating-system-independent agent on managed desktops and servers, and as a zero-footprint browser module on unmanaged and personal devices. One presence standard, whatever the endpoint.
What SpiAlert is not.
The fastest way to understand a new category is to place it against what you already know.
SpiAlert does not add codes or push notifications. It verifies presence passively in the background, so it can reduce the login friction your team already resents.
Liveness fires once, at enrollment or login. SpiAlert verifies continuously, throughout the session, second by second.
Network access controls decide whether the connection is allowed. SpiAlert checks something else entirely: whether the trusted human is actually there.
Enterprise browsers control what an application can reach. SpiAlert attests who is actually sitting at the keyboard.
A biometric unlock built into a device vouches for itself, once, on that device only. SpiAlert verification is independent of the device you connect from. It runs against a sovereign server, so the same standard applies on a managed laptop, a shared workstation, or a device you have never used before, and it keeps checking after that first moment instead of stopping there.
Your identity provider is built to answer who logged in, and it does that well. No identity protocol, including your IDP, was ever built to answer whether that person is still the one driving the session. SpiAlert supplies that missing layer through standard OIDC and SAML calls. Your IDP keeps every access decision.
Verify the person without storing their face.
Privacy is built into the architecture, not bolted on. This is how SpiAlert is designed to support your data-protection obligations.
No raw video
Only mathematical facial descriptors are sent for matching. Images and video never leave the device.
Volatile-first matching
Biometric matching runs in server memory. No vectors or images are written to persistent storage.
Irreversible templates
Descriptors are one-way. They cannot be reversed into a face or a usable image.
Sovereign server
Governance and administrative control stay with your enterprise, wherever it is hosted.
Built for the environments where trust in every session matters most.
The post-authentication gap shows up differently in every regulated environment. Start with yours.
Healthcare & Telemedicine
Shared clinical workstations, ePHI access, remote care.
Explore →IndustryFinancial Services
Trading floors, branch terminals, high-value transactions.
Explore →IndustryInsurance
Remote adjusters, claims handling, seasonal staff.
Explore →IndustryGovernment & Citizen Services
Contractor access, citizen identity, appointment integrity.
Explore →IndustryContact Centers & BPO
Agent presence, clean-desk enforcement, outsourced sites.
Explore →IndustryPharmaceutical & Life Sciences
GxP workstations, lab access, IP protection.
Explore →IndustryLegal
Client confidentiality, shared matter workstations.
Explore →IndustryCritical Infrastructure & OT
Operator presence at industrial and OT endpoints.
Explore →IndustryTransportation & Logistics
Dispatch consoles, fleet devices, shipment data.
Explore →IndustryManufacturing & R&D
CAD workstations, shop-floor kiosks, trade-secret protection.
Explore →IndustryBusiness Process Outsourcing
Outsourced seats, client proof-of-presence, PCI workflows.
Explore →See presence verification on a live session.
We will walk through the post-authentication gap in your environment and show how SpiAlert holds presence without adding friction for your people. We are also glad to discuss current pilots and references under NDA.