Pulse

An AffirmedID product

CONTINUOUS AUTHENTICATION & AUTHORIZATION

Your IdP Secures Login. Pulse Secures the Session.

Your IdP authenticates identity and authorizes access. Pulse CA2 a.k.a. Pulse CA extends that protection throughout the authenticated session, from login to logout.

Pulse CA + REFLEX

Extending that Protection to AI Workloads

IdPs perfected authentication, then threat vectors shifted to the sessions that follow. Pulse CA delivers zero-friction, continuous full session security while Reflex endpoint security extends it to protect AI agents and agentic workloads too.

Pulse CA with Reflex add-on extends Cisco, Okta, Microsoft, AWS, Ping Identity and others—raising their security bar to include AI sessions. No rip-and-replace, no modifications—Pulse CA and Reflex exist along side providing security heretofore unaddressed but now must haves.

Monitor, Detect, Prevent, and Report

Pulse CA Framework

An Add-on Extension to IdP/IAM Frameworks

You don't replace Entra, Duo, Okta, Ping, Google or other. You add a continuous assurance layer to the identity infrastructure you've already built—and extend that assurance to endpoints, processes, and process trees tracing accountability to the founding user.

Benefits

Pulse CA does not replace the organization's investment in user identity. It extends the value of that investment from “knowing the user is authenticated” to “the organization continuously knowing the authenticated user remains present and actively engaged throughout the session.” Retain the existing IdP/IAM investment while adding a continuous-monitoring and reporting layer alongside it.

There's More

Reflex, Pulse CA’s endpoint security service, extends user identity investments in several ways: ● Easily installs as a background service on endpoints the user frequents; ● Enhances presence and engagement detection by making it an active process performed regularly throughout the session; ● Suspending identity linage processes on detecting user absence and resuming them on their return, ● Includes a fulltime Policy Enforcement Point service, and ● Suspending or ending autonomous process’s having no linage to the user’s founding process.

Installation & Configuration

Pulse CA’s core benefits are realized with no impact on existing infrastructure. User’s install the required Pulse Auth app on their cell phones, a process completed in minutes with no help desk impacts. An intuitive admin dashboard facilitates organization configuration needs. With that finished, continuous monitoring is up and running.

Installing Reflex

Pulse Reflex is a separately installed optional service used where elevated endpoint security is needed. Installation by an experienced admin technician with remote access. Backup support is provided if needed and installation services can be provided where remote access is permissable. Installation of Reflex has no impact to either IdP/IAM framework or Pulse CA core components.

Transparency

Pulse CA operations including those of its Reflex endpoint security agent, are transparent with exception that: ● with Pules SIEM logging enabled, its logs will appear alongside others in the organization’s SIEM dashboard; and ● users may experience clearly marked notification of step-up authentication requests from time to time.

AI Threat Prevention

Pulse Reflex closes a critical gap exposed by IdP and IAM frameworks: every task runs as a process, and every process is tracible to a human. Pulse CA is unique in its focus on policing the process irrespective of its task, be it agentic AI or an agentic service performing critical tasks. Of equal importance, when things are not quite right, Pulse CA steps in and suspends or terminates the process, under policy directions. In place of monitor → detect → report some IdP/IAMs may provide, Pulse CA provides monitor → detect → intervene → report. There is no counter to immediate intervention.

Pulse, as an Add-on

Continuous Authentication and Identity Assurance

What's included?'

Pulse Cloud API

Add-on for any IdP or IAM service

  • Secured service endpoints,
    • WebSocket Secure (WSS) protocol with
    • cryptographic DPoP verification.
  • Federated user accounting & FIDO2 authentication,
  • Centralized CA trust metrics collection and distribution, and
  • Per session Policy Decision Point (PDP).
  • Federated SIEM log recording services
  • Orchestrates trust score collection and distribution
  • Delivers trust score metrics and PDP decisions over real time notification channels to Connect and Reflex clients

Reflex

Background endpoint security services

  • Active user presence and engagement monitoring,
  • AI agent detection and monitoring,
  • Exceptions promote user process suspension w/step-up or termination, and
  • Per process and process tree monitoring, for AI processes too
  • Rogue & orphan process detection and elimination in real time
  • WSS notifications, real time trust metrics receiver
  • AuthZEN evaluators enables AI governance

Auth Mobile App

A continuous trust engine

  • Device-bound FIDO2 and PIN/behavior recognition,
  • Binds user identity to the registered device,
  • Possession, behavior, proximity, and 3D location,
  • Continuously maintains identity/session awareness,
  • WSS/FCM connectivity, trust metrics streamed to cloud/PDP, and
  • Secure account registration and federated device transfer

Connect

OpenID Connect and OAuth 2.1

  • Standards compliant PKCE and DPoP support,
  • FIDO2-based, Auth or Passkey, user / policy choice
  • Orchestrates continuous authentication sessions,
  • Policy Enforcement Point (PEP)
  • AuthZEN endpoints provide AI governance where Reflex is not used
  • WSS notifications, real time trust metrics receiver
  • Headless step-up authentication
  • SAML 2 available for those who need it

Is Pulse CA Add-on right for you?

Don’t guess. Evaluate.

Introducing Pulse IQ (Identity Quotient)

Pulse IQ: in depth identity security analysis, generated in seconds

Pulse IQ is a free tool that builds a ready-to-use analysis prompt for any conversational AI. Enter the identity product you want to evaluate and its website address, tick a few options, and tap Copy Prompt. Paste the prompt into the AI of your choice and you get a full analysis of that product. You can also compare products side by side.

For anyone with security responsibilities, the most useful part is the gap list. A full analysis includes specific recommendations for what would need to be addressed to reach a 100% score.

The analysis uses three rule sets, each focused on the identity pillar. Rules are drawn from published standards (NIST SP 800-207 Zero Trust and CMMC) where they exist. Where standards haven’t yet caught up, as with agentic AI, the rules draw on industry RFP requirements and qualified expert recommendations. The rule sets are published, so you can see exactly what’s being measured.

Example output

Below are results for a widely used identity framework that advertises full-session and agentic AI coverage, as scored by five different AI agents. As you’d expect, no two agents agree exactly, but their results fall in the same range, which suggests broad agreement. Running a Full Analysis shows where they differ and pinpoints where attention is needed.

Pulse IQ results are AI-generated assessments based on publicly available documentation. They are indicative, not a certification, and should be followed by hands-on evaluation or experience.

As of October 8, 2026 at 7:06 AM EDT

Point of Reference Claude ChatGPT Gemini Perplexity Copilot
Identity AI Agent Rules 32% 59% 82% 36% 73%
ZTA Rules 67% 75% 100% 58% 92%
CMMC Rules 67% 67% 100% 67% 92%
Grand Total 50% 65% 88% 50% 83%

Same framework with Pulse CA + Reflex add-on extension.

Point of Reference Claude ChatGPT Gemini Perplexity Copilot
Identity AI Agent Rules 86% 86% 100% 92% 98%
ZTA Rules 92% 83% 100% 83% 100%
CMMC Rules 91 100% 100% 75% 100%
Grand Total 89% 84% 74% 99% 100%

Managed Service Providers

No heavy lift, no changes to current infrastructure!

A Low-Energy Revenue Enhancer for MSPs

Secure What Your Clients Already Have

Add protection for client sessions and agentic AI—without replacing, modifying, or disrupting their existing IdP or IAM infrastructure.

What Current IdP or IAM Framework Provides

What Pulse CA with Reflex Extension Adds

How the MSP Business Benefits

Strong authentication at session entry verifies the user when access is initiated, but assurance can diminish after authentication as the session continues.

Continuous identity & session assurance Pulse CA continuously evaluates identity, presence, behavior, proximity and other policy signals throughout the session, while Reflex extends assurance to the endpoint/user-device relationship.

No need to replace or modify the existing IdP or IAM infrastructure. Minimal impact on the existing staff or the help desk.

Identity and access control for human users and established applications Primarily establishes who is authenticated and what that identity is permitted to access.

Continuous authorization context for H2M and M2M Pulse CA + Reflex provides an additional assurance layer for human-to-machine and machine-to-machine/agentic activity, helping the MSP extend its existing IAM investment into continuously evaluated sessions.

The move from “authenticated” to “continuously trusted addressing the clients pressing need for session and AI agent security in the H2M space. Opens the door to new revenue stream extending that same level of trust to the M2M space.

A mature IAM service the MSP already knows how to deploy and manage Valuable recurring service, but increasingly difficult to differentiate as major IdPs converge on similar authentication and access capabilities.

A differentiated security extension and new MSP revenue opportunity Add Pulse CA + Reflex to existing IdP/IAM deployments rather than replacing them. The MSP can turn its existing identity practice into a continuous-session and agentic-AI security offering, creating an additional line-card service with incremental revenue.

Turning an existing IAM competency differentiated line card with increased revenue with no new staff and minimal impact to existing staff and the help desk is a good thing.

Provides initial authorization to begin a sessions. But the session it authorized, agentic AI or otherwise, is left to fend for itself in an environment rife with all manner of cyberattack vectors.

Adds session and agentic AI security without impacting the current IdP or IAM infrastructure.

Benefit from a new revenue stream with very little impact to existing operations.


Keep the identity platform you already sell. Add the continuous assurance it doesn't provide.

Built as One. Not Bolted Together.

Most CA solutions force you to integrate multiple vendors—authentication here, monitoring there, enforcement somewhere else. We architected Pulse CA as a single, elegant framework where every component was designed to work together from day one.

Pulse CA component anatomy Four-panel diagram showing the individual capabilities of each Pulse CA component: Cloud API Service (center), Auth mobile app, OIDC Provider Service, and Reflex endpoint service. Cloud API Service Central hub · Secure database · RP federation Central to all Pulse CA components Hosts secure identity & session database RP federation services Continuous monitoring services Sponsors Policy Decision Point services Auth App Mobile authenticator Identity authenticator Identity assertion provider FIDO2 device assertion provider Source of monitoring metrics Step-up authentication provider Adjunct identity assertion service Android · iOS Reflex Endpoint service & AI agent trust broker Local AuthZEN broker for AI agents Access device identity provider Active BLE proximity service PEP extension provider service AuthZEN client service Windows · macOS · Linux OIDC Provider Identity federation service OIDC and OAuth 2.0 service provider Continuous auth & identity authz AuthZEN evaluation services Policy Enforcement Point Dispatcher of PDP decisions Component capabilities · see the flow diagram below for how they connect
Pulse CA complete framework diagram Five-component diagram showing OIDC Client, OIDC/SAML Provider with PEP (center hub), Auth Device, PDP with AuthZEN, and Reflex endpoint service, with labeled data flows between them. Correlation ID links all activity OIDC / SAML Provider + AuthZEN PEP Orchestrates · enforces · notifies Manages session state Push notifications to RPs OIDC Client Your application Auth Device User's phone Streams trust metrics PDP + AuthZEN Continuous trust analysis Policy decisions Reflex Endpoint & AI agent trust broker FIDO2-DA · BLE proximity Local AuthZEN client Optional · Windows · macOS · Linux Login request Session token Auth ceremony Trust metrics Policy decisions Device assertion AuthZEN eval BLE proximity Dashed border = optional component · Dashed arrows = data streams

No Integration Headaches

It's already integrated. The OIDC provider, Auth device, and PDP were built to work together—no duct-taping vendor APIs or hoping they'll talk to each other.

No Gaps in Coverage

The OIDC provider orchestrates authentication, knows session state, and controls logout. CA monitoring starts exactly when it should and stops when the session ends—no blind spots.

Instant Enforcement

PDP trust decisions flow directly to the OIDC provider managing your session. No separate enforcement layer. No hoping policies get applied. Immediate action.

Single Pane of Glass

Correlation IDs link every event from authentication through monitoring to enforcement. Complete audit trail. One cohesive system—not three vendors pointing fingers at each other.

Pulse CA Framework

As the IdP Provider Service

Five integrated parts working as one elegant system

1. Access Device

The OIDC client application (a.k.a. laptop, desktop, tablet, machine, robot, et.al) integrates seamlessly with Pulse CA. An OIDC session started by the application or AI agent, links to Pulse Connect OIDC provider that supports user login using either Auth or cell phone, OS Passkey, or FIDO2 key.

2. Pulse API Services

Pulse Cloud API platform orchestrates all Pulse components. It securely maintains the registration database for Auth, OIDC, SAML, and Reflex, provides Relying Party federation, streamlined FIDO2 upgrade/recovery, and federates FIDO2 Client functionality with bi-directional authentication on behalf of Relying Parties. Its integrated Policy Decision Point (PDP) enables Continuous Authentication and Identity Authorization through real-time, risk-based access decisions.

3. OIDC Provider

The session orchestration hub; manages authentication ceremonies, maintains session state, receives real-time PDP policy-based decisions a.k.a. Policy Enforcement Point (PEP). Exposes AuthZEN endpoint. Connects with Pulse API over HTTPS/WSS, with WSS channel traffic additionally protected by an ML-KEM-derived AES-256-GCM session key. Optional SAML provider is avilable.

4. Auth Device (User's Phone)

As primary or adjunct to Passkey authenticator, implements user recognition via behavioral patterns and PIN. Dual assertions, identity and device-bound FIDO2, delivered to federated FIDO Client over secure networks. Provides for easy and secure FIDO2 upgrades, same or different phone types. Captures and streams trust metrics (Identity, Proximity, Location, Device Health) to the PDP throughout monitored sessions. Provides BLE advertising secure token on Reflex request to do so.

5. Reflex (Endpoint Background Service & AI Agent Trust Broker)

Optional addition completes the Pulse CA security loop framework. Operates as a persistent, per-user background service on the access device, extending continuous authentication and identity assurance to that device and to every AI agent running on it. Establishes a cryptographically secure device identity, registers with FIDO2-DA (device assertion without user interaction), and actively verifies the physical proximity of the user's Auth device over BLE. For agentic AI, Reflex is the local trust broker: it answers AuthZEN requests from endpoint agents over loopback HTTP, so an agent's authorization check never has to leave the machine. Connects with Pulse API over HTTPS/WSS, same as described above. Incorporates policy enforcement (PEP).


Cryptographic Accountability

The Pulse API enforces cryptographic accountability by requiring attestation at registration and identity assertion at every access. FIDO2 user access relies on either the Auth app or a Passkey on the user's mobile device, while device identity attestation and assertion across all endpoints use the same FIDO2 algorithm—referred to as FIDO2-DA—operating without a user gesture requirement. Wherever supported, hardware security elements handle private key and certificate storage, keeping credentials out of the reach of software-only attacks.

When Pulse CA is deployed as an add-on, primary authentication continues to be governed by the existing IdP/IAM, Pulse CA doesn't replace it. Instead, the user's mobile Auth app runs a continuous, silent identity-assurance layer alongside the primary login. In both foreground and background, it streams trust-score signals to the Pulse API, acting as a heartbeat for ongoing presence verification. If the signal indicates the user has stepped away (or trust score drops below policy threshold), all active AI agents are immediately paused; they resume once the user re-authenticates via step-up.

Policy governs non-human identities (NHI) by mapping headless processes to an accountable user assignment following enforced cryptographic accountability. Following user notification, a Pulse Auth step-up FIDO2-based authentication of the assigned user occurs. On failure for any reason including lack of policy guidance, the process, AI agent or otherwise, is terminated.

Anchoring Agentic AI to a Human Root of Trust

The same continuous trust signal that protects a human session extends to every agent—and every sub-agent—that session authorizes.

ClientMaster: Human Presence as the Root of Trust

Every agentic session inherits its authority from the ClientMaster, the live OIDC session of the human who launched it. Agents share its session identity and cannot outlive it. If the ClientMaster session ends—logout, a trust threshold breach, device compromise, a proximity violation—every subordinate agent is notified and terminated immediately, no matter how many hours or sub-agents removed from the original login.

AgenticID: Cryptographic Identity Per Agent

Each agent instance, including every sub-agent it spawns, receives its own AgenticID: a SHA-256/SHA-512 hash encoding its role and scope, its parent agent, the ClientMaster it descends from, and a time-bounded validity window. Tamper with an agent's context or parentage and the hash no longer matches—expired or forged agents are cryptographically self-evident, not just flagged after the fact.

Merkle-Anchored Audit Lineage

Reflex registers every AgenticID in a Merkle tree, the same integrity structure used to secure cryptocurrency ledgers. Any action, by any agent, at any depth in the tree, is traceable back through its parent agents to the ClientMaster and the authenticated human—and any descendant of a given agent can be found by traversing the tree from that point.

From Pre-Auth to Logout: Complete Session Coverage

The Complete Framework in Action

1. Pre-Authentication Setup

Following Auth app installation, registration of it and the device along with verified email address, and phone number completes the installation.

2. Behavior Recognition

Behavior recognition (how, where, when, and frequency of use) is a learning process that begins with first PIN entry. Over time its accuracy improves to the point PIN use may becomes optional in some cases.

3. Choice of Authenticators

An authentication event triggers at login with application link to Connect OIDC or SAML session service. There is a first use option, use SFA Passkey or MFA Auth, as the default method. Both use phishing resistant FIDO2. A session ID is created for accounting and tracking purposes.

4. Continuous Monitoring Begins

The session begins and Auth app, even when Passkey is used, begins streaming trust metrics to the cloud Pulse API: behavior-based identity recognition, BLE proximity, device possession by human, GPS-based location including elevation and Device health tracking; all monitored until logout.

5. Real-Time Analysis & Enforcement

Throughout the session, Pulse’s Policy Detection Point (PDP) analyzes trust scores feeding results to OIDC or SAML Policy Enforcement Point (PEP) for enforcement. High trust: Session continues. Medium trust: Step-up required. Low trust: Session terminated. Normal logout: CA monitoring ends gracefully.

6. Reflex Option

Reflex installed on the access device completes the security circle. Both Auth FIDO2 and Reflex DPoP merge at Pulse API. Token traversal from Reflex to Pulse API on to Auth and over BLE to back to Reflex where it’s verified. A closed loop security model on like Googles CaBLE but distinguished by its whole session application. If AI agents are running on the device, Reflex brokers their AuthZEN checks locally and terminates them the instant the human's ClientMaster session degrades.

The Attacks That Slip Through Traditional Auth

Mid-Session Credential Theft

Traditional Auth: ✗ User logged in at 9 AM. Credentials stolen at 11 AM. System has no idea.

Pulse CA: ✓ Behavioral anomaly detected immediately. Session terminated. Threat neutralized.

Unexpected Location Change

Traditional Auth: ✗ User authenticated from Boston. Now accessing from Romania. Still trusted. Or same building, wrong floor, 2D geofencing can't tell.

Pulse CA: ✓ 3D location monitoring (latitude, longitude, and barometric altitude) detects both impossible travel and floor-level displacement. Location violations trigger immediate step-up or session termination.

Device Compromise

Traditional Auth: ✗ Phone jailbroken mid-session. Full access continues.

Pulse CA: ✓ Device health monitoring detects compromise. Access revoked instantly.

Orphaned AI Agent

Traditional Auth: ✗ Human launches an agent, then logs off, sleeps, or has credentials revoked. Agent and its sub-agents keep working on a token issued at launch, unaware anything changed.

Pulse CA: ✓ Every agent inherits authority from the human's live ClientMaster session. The moment that session degrades, every descendant agent is notified and terminated—automatically, at any depth.

See Continuous Authentication & Identity Assurance in Action

Try It Right Now

What You'll Do:

  1. Install our Auth app on your phone (5 minutes)
  2. Simulate an OIDC app login using Auth or Passkey
  3. Watch real-time trust scores update as CA monitors your session
  4. See what happens when you trigger an exception (like turning off Bluetooth)

Trust Scores You'll See:

  • Identity Trust Score
  • Proximity Trust Score
  • Location Trust Score
  • Device Health Trust Score

Time Required: ~10 minutes total (5 min setup, 5 min demo)

Full Platform Walkthrough

What You'll See:

  • Complete architecture in a controlled environment
  • Policy configuration and real-world enforcement scenarios
  • Integration examples with your identity provider
  • Custom use case discussion for your organization

Format: WebEx session with our team