Know who's still in control.

Login proves who entered. Before a sensitive action executes, GrayPass checks whether the expected person is still in control and returns a decision your application can enforce.

EvidenceAssurancePolicyDecision + proof
Backed by:
with angels from:

Works with your identity provider, passkeys, MFA, device signals, and transaction context.

See your behavior take shape.

Move, scroll, and type. GrayPass turns the timing of your interaction into a temporary visual trace.

What is a Brainprint?

A Brainprint is a privacy-preserving, tenant-scoped model of how an enrolled person interacts with software.

Keystroke timing. Pointer movement. Scrolling rhythm.

It models operational style without capturing raw text content.

Brainprint is the source GrayPass uses to assess continuity before important actions.

Login was earlier. The action is now.

  1. 9:41 AM. Passkey accepted. Authentication establishes who entered.
  2. 2h 38m later. Still signed in. The session remains valid while the evidence behind it ages.
  3. 12:19 PM. Any requested action. The consequential action arrives inside a valid session.
  4. Before execution. Verify again. GrayPass checks current control and returns a decision to enforce.

Login was earlier. The action is now.

Session entryTime passesAction requestedCurrent control checked

9:41 AM

Passkey accepted

Authentication establishes who entered.

Keep your stack. Add fresh assurance.

Your existing controls establish identity and context. GrayPass combines them with Brainprint continuity, applies your policy, and returns one decision for one exact action. Your application enforces it.

Existing controls

Proprietary continuity signal

GrayPass

Typed assurance. Your policy. One exact action.

Decision your application enforces

AllowVerify againHoldDeny
Action-bound proof

Select an input to see what it contributes.

Still in control? GrayPass asks that before every consequential action.

GrayPass weighs the evidence against your policy and returns one of four decisions: allow, verify again, hold, or deny. Your application enforces the result.

  • Proposed action

    Approve a recurring payout

    A scheduled transfer would go to a verified destination.

    GrayPass returns

    Allow
  • Proposed action

    Change a payout account

    Future payouts would move to a new destination.

    GrayPass returns

    Verify again
  • Proposed action

    Create a production credential

    A new key would gain production access.

    GrayPass returns

    Hold
  • Proposed action

    Increase an agent's authority

    An automated actor would act with more power.

    GrayPass returns

    Deny

The boundary, the policy model, and the decision contract stay the same.

Less data by design.

  1. Local signals

    Interaction timing is observed in the browser. Typed content is never read.

  2. Derived features

    Signals are reduced to timing features before anything leaves the device.

  3. Tenant-scoped assurance

    Brainprints stay inside each customer's environment and can be revoked or deleted at any time.

Human authority can extend to agents.

An agent acts under a mandate: the bounded authority a person granted it. Before each agent action executes, GrayPass checks that it still falls within that grant.

Choose where the agent's action falls.

Human principal

Mandate: what the person granted

Agent
Proposed action

GrayPass authorization

Result

Allow

The action is covered by the person's authority and executes with proof.

Protect the action that matters most.

Start with one consequential workflow and evaluate GrayPass before changing production behavior.