You are the password.

Spend three minutes inside the demo. We'll capture your typing, mouse, scroll, focus, and (optionally) gaze rhythm, build a live brainprint, and let you watch GrayPass verify and authorize you in real time as you work.

Nothing to steal, nothing to phish, nothing to remember.

1Setup
2Enroll
3Work
4Authorize

Pick your signals

Four signals work with no permissions and carry the identity decision. Eye tracking is optional and needs your camera; on a webcam it corroborates the others rather than deciding on its own.

Keystroke, pointer, scroll, focus Always on. 54 features summarized on your device in disjoint ~5s windows - these carry the decision.
Eye tracking optional Asks for camera; frames never leave your device. A liveness and engagement corroborator, weaker for identity on a webcam.
Data collection notice always on By starting the demo, anonymized behavior summaries from your session - the same timing statistics the live engine scores (typing and pointer rhythm on desktop; typing rhythm, touch-stroke and motion summaries on phones) - are collected to train and improve the model, when this deployment has donations enabled. What is never collected: the words or keys you type, camera frames, raw cursor coordinates, or your screen contents. Pseudonymized before storage, purged after 365 days. Full details: privacy policy.

Demo runs against the real GrayPass backend. A test key is issued automatically.

enrollment follow the prompt below

Loading…

step 1

brainprint forming

0%
--
collecting samples

keystroke0
pointer0
scroll0
focus0
gaze off--
monitoring live backend type in the editor and move your mouse, then watch live trust climb
🔒 inbox.example.com verified
1

Open another tab - no password, no MFA

GrayPass mints a signed token when your live trust is high enough.

Watch the new tab open instantly - or watch step-up kick in if the engine finds you suspicious.

2

The real test: hand it over

Give the device to someone else - watch the live engine notice.

Nothing simulated. Pass this device to someone else and have them type or browse naturally. Every frame is compared to your enrolled brainprint by the live engine - watch it notice the switch.

3

Simulated attacks

No second person around? Replay recorded attacker telemetry.

These replay recorded attacker telemetry - scripted bot, stolen-session, and RDP payloads - through the same live engine. Clearly simulated; the hand-off test above is the real thing.

live trust

0 frames
--
warming

keystroke0
pointer0
scroll0
focus0
gaze off--

0.33% equal-error-rate on a 300-user held-out benchmark. Raw keystrokes, pointer paths, and video never leave this device.

activity

Cross-device

Take your brainprint to your phone

You just proved who you are on this laptop. Tandem hands that verified identity to your phone with one QR scan, then keeps you authenticated as you move between apps - stepping up to Face ID only when the risk actually calls for it.

Try the Tandem demo
GrayPass for Business

Run this on your own app

Everything you just experienced - silent enrollment, continuous scoring, block & MFA handoff - drops into your product with one <script> tag. Buy a session pack, paste the snippet, and you're live. $0.70 / session, never expires.

Deploy GrayPass