Human Factor Authentication

The login proves who arrived. SpiAlert proves who stayed.

Every authentication system trusts a session from login to logout. SpiAlert closes the post-authentication trust gap by verifying, second by second, that the authorized human remains present throughout the session.

Continuous presence, not point-in-time login Independent of the device you connect from Hardware-agnostic, standard webcams Cross-platform agents, OS-independent Sovereign server, your data stays yours
The problem

Authentication ends at the door. The risk lives inside the room.

Identity providers confirm a user at login and then trust the session. That leaves a window, from the moment of login to logout, where no system verifies that the same human is still there.

The credential gap

Stolen or phished credentials let an attacker inherit a live session. Once past login, they look exactly like the authorized user for the rest of the day.

The walk-away gap

A workstation left unattended stays trusted until a policy timeout. In shared clinical, branch, or trading environments, the session can belong to the wrong person in seconds.

The remote and BYOD gap

On remote and personal devices, the authenticated machine is no longer under the authenticated person's control. Device trust is not human trust.

Why it matters

Once the door opens, nothing checks who's still in the room.

However access is gained, a stolen credential, a hijacked session, or lateral movement once inside, no identity architecture rechecks the human once the door is open. Two independent research organizations, using different methods, keep finding the same shape of problem.

39%

Credential abuse, tracked across the full breach chain, sits at the top of all breach patterns, more than any single vector measured.

Verizon, 2026 Data Breach Investigations Report
89%

Identity weaknesses were exploited in the large majority of incidents investigated last year, Unit 42's broadest measure of identity's role in a breach.

Palo Alto Networks Unit 42, 2026 Global Incident Response Report
65%

Identity-based techniques drove initial access in most investigated breaches, ahead of phishing and vulnerability exploitation alone.

Palo Alto Networks Unit 42, 2026 Global Incident Response Report

These figures come from separate reports with different methodologies and measure different things, initial access, cumulative involvement across a breach, and credential-specific abuse. They are not additive and should not be summed. Each is cited to its own source.

How it works

Auto-enroll. Verify continuously. Let access follow presence.

SpiAlert overlays your existing identity stack. No rip and replace, no new hardware.

01 / Auto-enroll

No enrollment step for your users

SpiAlert builds each user's presence baseline automatically from their first authenticated access, or from an existing directory or badging record. There is nothing for the user to set up, no proximity readers, and no special hardware. It is hardware-agnostic and works with standard webcams.

02 / Verify

Confirm the human across every access point

After that first authentication, SpiAlert verifies the same human second by second across corporate access: on-device sessions, physical entry, and remote connections. Only irreversible mathematical descriptors are sent for matching, never raw video.

03 / Attest

Access follows the person

A sovereign server issues a presence attestation that your identity provider and applications can check. The moment the trusted person is no longer present, access is denied and the screen is protected immediately, then revealed the instant they return.

The platform

One console for presence, risk, and events.

  • Presence and events in one place. Every presence confirmation, absence, and anomaly is captured against the standard event taxonomy and surfaced to your team.
  • Risk over time. Track presence-driven risk by user, device, and time window, and export to your existing SOC or SIEM.
  • Built for the security operator. Device and user management, groups, roles, and audit views, designed for the people who run identity day to day.
app.spialert.com
SpiAlert dashboard showing presence events, risk over time, and most risky users
Why we are different

Continuous human presence solves a problem nothing else in your stack was built to solve.

SpiAlert works alongside the tools you already run, and it is the piece most zero trust models assume exists but do not actually provide: continuous verification of physical human presence, not continuous evaluation of device signals or behavior. Here is precisely where it fits.

DimensionLegacy identity and MFASpiAlert
When it checksOnce, at loginContinuously, second by second
What it trustsThe device or the tokenThe verified physical human
If credentials are stolenAttacker inherits the sessionThey are useless without the trusted human. Access is denied.
User experienceRepeated prompts and timeoutsPassive background verification
Response postureReactive, after the eventProactive: the screen is protected the moment the person steps away, and revealed when they return
The missing layer

Your login system answers one question. It was never built to answer the second.

Your identity provider confirms who logged in. That is its job, and it does it well. But it was never built to keep checking if that same person is still the one at the keyboard, no login system was. SpiAlert adds that missing piece using the security standards your systems already speak, without taking control away from your identity provider.

Okta  via OIDC / SAMLMicrosoft Entra  via OIDC / SAMLAny OIDC or SAML IDP  standards-basedYour SOC / SIEM  push and pull API
Trusted presence as a signal

Your login checks identity once. SpiAlert keeps checking for a trusted human for as long as the session lasts.

SpiAlert closes a gap every login system shares: none of them recheck who is still there once you are in. Your identity provider can check with SpiAlert the same way it already checks for extra verification, right after login, before a sensitive action, or continuously for as long as the session runs.

Checked for as long as the session lasts

Your identity provider checks with SpiAlert the same way it already checks for extra verification, and gets a simple answer: is the trusted human still at the device where this session started? It can check right after login, before a sensitive action, or when an AI agent is about to act outside its approved scope, confirming it is still the same person who launched it.

Passive, so it never interrupts the person

Verification runs in the background, second by second. There are no codes, no push notifications, and no prompts. The person keeps working while their presence is confirmed, so security never costs anyone productive time.

Bound to the device the session started on

Presence stays tied to the device and session where the login began. If the trusted person steps away, or the session is being driven from somewhere else, presence cannot be confirmed, and your identity provider can deny, step up, or revoke access.

Cross-platform coverage. SpiAlert runs as a lightweight, operating-system-independent agent on managed desktops and servers, and as a zero-footprint browser module on unmanaged and personal devices. One presence standard, whatever the endpoint.

Category clarity

What SpiAlert is not.

The fastest way to understand a new category is to place it against what you already know.

Not another MFA prompt

SpiAlert does not add codes or push notifications. It verifies presence passively in the background, so it can reduce the login friction your team already resents.

Not liveness detection

Liveness fires once, at enrollment or login. SpiAlert verifies continuously, throughout the session, second by second.

Not ZTNA

Network access controls decide whether the connection is allowed. SpiAlert checks something else entirely: whether the trusted human is actually there.

Not an enterprise browser

Enterprise browsers control what an application can reach. SpiAlert attests who is actually sitting at the keyboard.

Not a device-side check

A biometric unlock built into a device vouches for itself, once, on that device only. SpiAlert verification is independent of the device you connect from. It runs against a sovereign server, so the same standard applies on a managed laptop, a shared workstation, or a device you have never used before, and it keeps checking after that first moment instead of stopping there.

Not a replacement for your IDP

Your identity provider is built to answer who logged in, and it does that well. No identity protocol, including your IDP, was ever built to answer whether that person is still the one driving the session. SpiAlert supplies that missing layer through standard OIDC and SAML calls. Your IDP keeps every access decision.

Privacy by architecture

Verify the person without storing their face.

Privacy is built into the architecture, not bolted on. This is how SpiAlert is designed to support your data-protection obligations.

No raw video

Only mathematical facial descriptors are sent for matching. Images and video never leave the device.

Volatile-first matching

Biometric matching runs in server memory. No vectors or images are written to persistent storage.

Irreversible templates

Descriptors are one-way. They cannot be reversed into a face or a usable image.

Sovereign server

Governance and administrative control stay with your enterprise, wherever it is hosted.

Request a demo

See presence verification on a live session.

We will walk through the post-authentication gap in your environment and show how SpiAlert holds presence without adding friction for your people. We are also glad to discuss current pilots and references under NDA.

info@spialert.com   |   908 770 1552

Thanks. Your email client should open with the details ready to send. If it does not, write to info@spialert.com and we will follow up within one business day.
Please enter your name.
Please enter a valid work email.
Please enter your organization.

Submitting composes an email to our team. To be wired to your CRM or form endpoint before launch.

Newsroom

New From Newsroom