About Affirmed Identity

Continuous Authentication and Identity Assurance: AI Agent security without gaps.

The Vision, Realized in Pulse CA

End-to-end security without gaps beginning with a login ceremony based on dual assertions of both user identity and device-bound phishing resistant identity. Building on that a continuous monitoring framework inclusive of AI agents, agentic and otherwise, extending without gaps to end of session logout.

Our Founding Perspective

The inspiration came from a hard lesson: a cyber-attack in 2000 that resulted in significant personal and business losses. That experience, and the years of formal cybersecurity training, independent research, and patent work that followed, shaped a foundational conviction: the way the industry thinks about authentication is fundamentally incomplete.

Login does not imply session security. Most IdP and IAM frameworks treat the login moment as the finish line. They ignore the session that follows where real exposure lives, and it is where attackers increasingly focus. OAuth consent phishing, session hijacking, credential theft mid-session, these attacks succeed precisely because these frameworks stop caring once the login ceremony ends.

Pulse CA eliminates that exposure entirely.

Evolving With The Times

In 2026, Reflex end point protection expanded the core CA service, adding continuous active endpoint user presence and engagement verification. If the user goes missing, is unaccounted for, or disengages mid-session, not only is the event logged as normal, but active defense kicks in to automatically pause the user process and initiate step-up authentication or optionally, to end the user process.

Pulse CA becomes a reactionary detect-and-protect force.

Our Approach

We believe security architecture should be honest about where the risks actually are. Passkeys and MFA are important advances, we support them and build on them. But they are point-in-time mechanisms, and the threats have moved beyond the login moment. Continuous authentication is not a replacement for strong authentication; it is the extension of that assurance across the full session lifecycle.

We also believe that the security of AI agent systems depends on a principle easy to state but hard to implement: every agent, no matter how autonomous, has a traceable human origin. Pulse, combined with AuthZEN, gives that principle teeth, providing the policy enforcement layer that ensures agent actions remain within the scope authorized by the originating human, for as long as that human's trust remains valid.