Know who's still in control.
Login proves who entered. Before a sensitive action executes, GrayPass checks whether the expected person is still in control and returns a decision your application can enforce.
Works with your identity provider, passkeys, MFA, device signals, and transaction context.
See your behavior take shape.
Move, scroll, and type. GrayPass turns the timing of your interaction into a temporary visual trace.
What is a Brainprint?
A Brainprint is a privacy-preserving, tenant-scoped model of how an enrolled person interacts with software.
Keystroke timing. Pointer movement. Scrolling rhythm.
It models operational style without capturing raw text content.
Brainprint is the source GrayPass uses to assess continuity before important actions.
Login was earlier. The action is now.
- 9:41 AM. Passkey accepted. Authentication establishes who entered.
- 2h 38m later. Still signed in. The session remains valid while the evidence behind it ages.
- 12:19 PM. Any requested action. The consequential action arrives inside a valid session.
- Before execution. Verify again. GrayPass checks current control and returns a decision to enforce.
Login was earlier. The action is now.
9:41 AM
Passkey accepted
Authentication establishes who entered.
Keep your stack. Add fresh assurance.
Your existing controls establish identity and context. GrayPass combines them with Brainprint continuity, applies your policy, and returns one decision for one exact action. Your application enforces it.
Existing controls
Proprietary continuity signal
GrayPass
Typed assurance. Your policy. One exact action.
Decision your application enforces
Select an input to see what it contributes.
Still in control? GrayPass asks that before every consequential action.
GrayPass weighs the evidence against your policy and returns one of four decisions: allow, verify again, hold, or deny. Your application enforces the result.
Proposed action
Approve a recurring payout
A scheduled transfer would go to a verified destination.
GrayPass returns
AllowProposed action
Change a payout account
Future payouts would move to a new destination.
GrayPass returns
Verify againProposed action
Create a production credential
A new key would gain production access.
GrayPass returns
HoldProposed action
Increase an agent's authority
An automated actor would act with more power.
GrayPass returns
Deny
The boundary, the policy model, and the decision contract stay the same.
Research on human control in digital systems.
Technical reports on continuity, agency, and attention.
All researchBehavior changes across time and context.
The Shape of Identity
Execution is observable. Authorization requires provenance.
The Chain of Intent
In progress
More research coming soon.
Less data by design.
Local signals
Interaction timing is observed in the browser. Typed content is never read.
Derived features
Signals are reduced to timing features before anything leaves the device.
Tenant-scoped assurance
Brainprints stay inside each customer's environment and can be revoked or deleted at any time.
Human authority can extend to agents.
An agent acts under a mandate: the bounded authority a person granted it. Before each agent action executes, GrayPass checks that it still falls within that grant.
Choose where the agent's action falls.
Mandate: what the person granted
GrayPass authorization
Result
The action is covered by the person's authority and executes with proof.
Protect the action that matters most.
Start with one consequential workflow and evaluate GrayPass before changing production behavior.