Know who's still in control.

Login proves who entered. Before a sensitive action executes, GrayPass checks whether the expected person is still in control and returns a decision your application can enforce.

Backed byY Combinator

with angels from

Every interaction has a rhythm.

Step 01

Follow the movement.

Pointer movement and click timing describe how someone moves through software, including changes in speed, curves, and pauses.

Step 02

Read the timing.

The gaps between keystrokes and the time each key stays pressed form one interaction rhythm. This illustrates timing, not the meaning of the words.

Step 03

Trace the pace.

Scrolling leaves a pattern of bursts, pauses, and changes in direction. Brainprint models that operational style.

Keep your stack.Add fresh assurance.

Keep your identity controls

Your identity provider, passkeys, and MFA establish who entered. GrayPass works with that foundation.

Bring context to the action

Device, session, and transaction context describe where the request comes from and what it would change.

Add Brainprint continuity

Interaction timing helps assess whether the expected person is still in control, without capturing typed content.

Apply your policy

GrayPass weighs the available evidence against your rules for the requested action.

Bind proof to one action

Action-bound proof ties authorization to the exact action your application is about to execute.

Enforce the decision

Your application enforces the result: allow, verify again, hold, or deny.

Hover or focus an illustration to play it. Move away to pause.
  • Allow.
  • Verify again.
  • Hold.
  • Deny.

Protect the action that matters most.

Request Evaluation

Before you integrate

Frequently Asked Questions

What does GrayPass check?

GrayPass checks whether the expected person is still in control before a sensitive action executes. It brings identity, device, session, and Brainprint evidence to your policy and returns a decision your application can enforce.

Does GrayPass replace our login stack?

You keep your identity provider, passkeys, and MFA. They establish who entered. You add GrayPass at the point where your application needs fresh assurance before an important action.

What is a Brainprint?

A Brainprint is a privacy-preserving, tenant-scoped representation of how you interact with software. It relates an enrolled person's interaction patterns to later evidence from typing, pointer movement and clicks, or scrolling. It contributes continuity evidence; it does not establish identity, intent, or permission on its own.

Does GrayPass capture what people type?

Interaction evidence describes timing and movement, not the words or their meaning. The browser derives features before sending evidence. Available modalities vary by session; not every session needs typing, pointer, and scrolling evidence. Brainprints stay scoped to the customer and can be deleted when the customer deletes the subject.

What happens when the evidence is uncertain?

Your policy determines the result: allow, verify again, hold, or deny. Missing or stale evidence can require fresh approval or a review. Your application enforces the decision before executing the action.

Where do we integrate GrayPass?

Your server requests authorization before executing a protected action, such as changing a payout account. For an allowed action in enforce mode, GrayPass returns short-lived signed proof bound to that action and your application.

How do we start an evaluation?

Use Request Evaluation to tell us about your company, the action you want to protect, and your current stack. Start with one workflow so you can assess GrayPass before changing production behavior.