Always-on verification

Lose the laptop. Keep control.

A password is a moment, not a perimeter. Every request is checked again — so a machine walking out of the building walks out with nothing.

A lock that checks once is a lock left open.

  • Tata
  • Siemens
  • HDB Financial Services
  • Aditya Birla Group
  • Asian Paints
  • Mphasis
  • Landmark Group
  • NHPC
  • Pidilite
  • Axis Max Life
  • Haldiram's
  • Allcargo Logistics
  • Mirae Asset Sharekhan
  • Jana Small Finance Bank
  • DTDC
  • Bajaj General Insurance
  • Samsonite
  • Cafe Coffee Day

What is always-on verification?

Always-on verification

A lock that checks once is a lock left open.

Always-on verification re-decides access on every request instead of trusting a decision taken at login. Identity, device, posture, policy and context are all read again — and when they stop adding up, the session ends where it is.

  • The session is not the credentialA password proves a secret was known, once. Every request after that is a fresh question: is this still the same person, on the same approved machine, in a situation that still makes sense?
  • Five signals, scored liveDevice health, location and geo-velocity, behaviour, network and posture, session age and idle time. Each is measured on the request in front of it, not sampled once and cached.
  • Out of scope means out of reachApplications, databases and sites a person has no rights to are not merely refused — they never resolve. There is no login page to attack and no error to work around.
  • Silent unless the risk changesRe-verification is not re-prompting. A step-up challenge appears when something genuinely moves — a new device, an impossible journey — and never as a ritual on a timer.
How always-on verification worksSophia signs in09:41 · password and MFA, onceHAPPENS ONCEEVERY REQUEST AFTER THATGET erp-core.acme.internalDevice healthLocation & velocityBehaviourNetwork & postureSession age & idleAllowedone verdict · 8 msAnd again, on the very next requestSignals holdThe session carries on.Nobody is re-prompted,and nothing is noticed.Signals turnThe session ends whereit is — mid-request, andthe signal is named.
5signals per request
1verdict per request
0sessions left to expire

Five signals.

Scored every request.

None of these is a one-time check.
Each signal is measured live on every request and folded into a single score. When the picture stops adding up, access stops with it — whatever device the request came from, and however long ago the password was typed.

endpointDevice healthDisk encryption, patch level, antivirus and firewall — re-checked continuously, not just at login.
geographyLocation & geo-velocityWhere the session is, and whether it just crossed a continent in the time it takes to refill a coffee.
patternBehaviourHow this person normally moves and works. A sudden break in that pattern raises the score.
networkNetwork & postureTrusted network or hostile one, and whether the machine still meets the policy it was let in under.
timeSession age & idleLong-lived and idle sessions are re-verified or quietly retired before they turn into someone's way in.
watch it decide_

Take the laptop. Open anything you like.

The machine is unlocked, signed in and in the wrong hands. Double-click the apps — the agent opens and tells you it is watching, the codebase and the database refuse, and in the browser only what the policy allows ever resolves.

Protected by InstaSafeWORKSTATION-07 · reported stolen 10:02
Double-click an appTap an app twiceSee what a stolen laptop still cannot reach

Check-once security asks who you are. Always-on asks whether you still are.

One-time vs always-on

Same login. Very different after it.

Both models let the same person in on the same morning. Everything that separates them happens in the hours afterwards.

line by line _ two ways to hold a session
  • Identity is checkedOn every requestOnce, at the front gate
  • Trust after loginRe-earned each timeAssumed for the whole session
  • Stolen unlocked laptopOut-of-scope apps never resolveSees whatever the session could
  • Context turns unsafeSession ends mid-requestRuns until it expires
  • Blast radiusOne requestOne session, and all of it
  • What the user doesNothing — it is silentRe-prompted to feel secure
  • Step-up challengeOnly when risk changesOn a timer, or never
  • Why a request failedNamed signal, in the logSession expired
marks the 5 rows where the architectures differ, not the wording
ONE SESSION · 09:41 → 10:02TIMERESOURCE REQUESTEDVERDICT09:41:12erp-core.acme.internaltunnel open · 8 msALLOWED09:52:40reports-db.acme.internaltunnel open · 6 msALLOWED09:58:03billing-portal.acme.cotunnel open · 9 msALLOWED10:01:55erp-core.acme.internaltunnel open · 7 msALLOWEDDECISIONS TAKEN1,284 · one per request10:02:14erp-core.acme.internaldevice reported stolenDENIED10:02:41codebase.acme.internalsession already closedDENIEDSession closed10:02:14 · mid-requestNothing was revoked by hand.The next request simply failed.SCORED ON EVERY REQUESTDevice healthLocation & velocityBehaviourNetwork & postureSession age & idle
Always-on outcomes

The login ends.The checkingdoes not.

One session, re-decided on every request it makes — which is what turns a stolen machine, a drifting device and a quiet resignation into the same non-event.

A stolen laptop stops being a key

Unlocked and signed in, it still has to pass the next check — and it does not.

Sessions that close themselves

Access ends the moment the signals turn, without waiting for anyone to notice.

Nothing extra for the user

No re-prompt ritual. A challenge appears only when the risk actually moves.

FAQ

Always-on verification, answered.

Tap a question — or open them all and read straight through.

Talk to us

//Ready when you are//

Ditch the VPN. Keep your apps invisible.

Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.

Regulated, air-gapped, or on-premise? See deployment options