Post-Authentication Action-Level Verification and Proven Intent Binding
Provides a post-authentication session-trust layer that continuously verifies and enforces whether each action, command, or prompt is executed by an authorized person by cryptographically binding it down to the command execution level to physical human input from an approved device to establish Proven Intent; sits between MFA and the first keystroke to confirm physical human presence rather than automated scripts or stolen credentials, extends Zero Trust from connection to action across privileged remote sessions, OT plant pathways, third-party access, and AI agent actions, enforces IGA policies at the action level, and delivers session-layer visibility, verification, and enforcement across all governed pathways from login to logout.
02
Deterministic Real-Time Blocking and Proven Intent Enforcement
Enforces deterministic, fail-closed blocking in CONTROL mode in real time for any unattested interaction, action, command, or prompt lacking Proven Intent—including across supported interactive protocols such as RDP and SSH sessions—stopping unauthorized inputs to sensitive resources before downstream detection tools react while allowing legitimate human work to proceed; applies connection control where supported, mitigates lateral movement from compromised credentials, and provides cryptographic evidence as a deterministic binary signal rather than relying on risk scores or probabilistic behavioral estimates.
03
Multi-Protocol Remote Access and Tool Support
Provides visibility, monitoring, and Proven Intent verification for actions across supported interactive and non-interactive protocols and remote access tools—including Windows Remote Desktop Protocol (RDP), Linux Secure Shell (SSH), VNC, NinjaOne, TeamViewer, Splashtop, GoToMyPC, PowerShell Remoting, WinRM, SMB (PsExec), WMI, Telnet, and FTP—including connections originating from unknown or unmanaged clients.
04
Flexible Terminator Host and Jump Host Gateway Deployment
Enables installing and running the terminator process directly on remote destination host machines or on jump hosts serving as gateways in front of destination host machine clusters depending on network infrastructure, enforcing identity and bringing non-interactive remote execution protocols (PowerShell Remoting, WinRM, PsExec/SMB, and WMI) under governance at the jump host segmentation chokepoint without requiring agents on every downstream server.
05
Lightweight Privileged Session Control
Provides a lightweight alternative path for privileged remote session control when full PAM credential lifecycle management is not required, serving as a complementary solution to existing PAM deployments.
Your plan caps how many capabilities are shown — upgrade to see the full list