Why we started GrayPass.
The question after login
GrayPass started with a question: who is in control when an important action happens? Login establishes who entered a session. A payout change or a new credential may happen hours later, when that original check says little about the person acting now.
We built GrayPass to check current control at that moment and bind the result to the action. That is the starting point for the company: give applications fresh evidence before they let a consequential action proceed.
Human authority comes first
People should retain authority over the actions taken through their accounts, including work they delegate to an agent. Applications need a way to check that authority where the action happens.
We build around the identity systems teams already use. Brainprint continuity adds behavioral evidence to their policy, alongside identity and action context. The application makes that policy effective by enforcing the returned decision.
The evidence has limits. Behavior can change, a device can be compromised, and a familiar interaction does not prove permission. We want those limits to remain visible in how the system reports its evidence and in the claims we make about it.
Research shapes the work
Our studies examine how behavior changes over time and what interaction traces can tell us about human and agent activity. We use that work to test the assumptions behind GrayPass and to define the evidence a decision needs.
The reports include their methods and limitations. Their benchmark results describe the research setting; they are not measurements of product performance.
Talk to the founders
Have a question about GrayPass or the work behind it? Write to us directly.