NEW YORK CITY, August 18, 2026. Twosense, which provides Continuous Authentication and Continuous Access Evaluation (CAE) for workforce identity and access management, today announced an integration with CAEP (Continuous Access Evaluation Profile) that lets any application in a customer's identity stack react instantly to changes in user trust. Organizations get real-time, automated response to identity risk using the tools they already have, without waiting for a security team to build a custom integration first.
The integration works by connecting Twosense's continuous, biometric trust signal to the Continuous Access Evaluation Profile (CAEP), an open standard within the Shared Signals Framework (SSF). CAEP and the broader SSF let identity and security platforms share real-time signals about changes in session risk and user trust, so any CAEP-compliant platform a customer already runs can consume Twosense's signal and act on it immediately.
Most IAM infrastructure today is built on a point-in-time, human-driven model of authentication: verify once at login, then trust for the rest of the session. That model has no native pathway for dynamic de-authentication and doesn't account for mid-session changes, whether up or down, in a user's trust level. As a result, organizations that deploy Continuous Authentication haven't been able to automatically realize its full security benefit; doing so has required custom, per-application integration work that only the most sophisticated engineering teams could take on.
"Continuous Authentication delivers its full value when the rest of the identity stack can actually act on it in real time," said Dawud Gordon, Ph.D., CEO of Twosense. "CAEP removes the integration burden that's kept organizations from operationalizing continuous trust signals. This is what makes continuous identity practical at enterprise scale, not just a checkbox feature."
Five ways our customers are using this
For customers, this means the gap between "something looks wrong" and "something gets fixed" closes from an entire session down to the moment it happens. Twosense's beta customers are already using this integration in production to catch:
- Unauthorized use, with automatic session revocation. If that behavior stops matching the authenticated user mid-session, whether from stolen credentials used elsewhere or deliberate impersonation, the session is automatically revoked, regardless of whether a workstation was ever left unlocked.
- Credential sharing. A login or access badge lent out for convenience is one of the most common ways credentials get misused. The integration flags the mismatch the moment it happens.
- Session hijacking. A stolen session token doesn't help an attacker if the behavior behind it doesn't match. The mismatch gets caught and the session can be ended before it's misused.
- MFA compromise. MFA can be phished, socially engineered, or worn down through repeated push prompts. This integration keeps watching after MFA clears, catching an imposter who's already gotten past that step.
- Accidental open session takeover. Someone steps away from a workstation without logging out, and the next person to sit down inherits full access without ever entering their own credentials. The integration detects the identity switch immediately.
The underlying technical details, including how trust signals map to the CAEP risk model, are available in Twosense's documentation.
Twosense's integrations, including SGNL (CrowdStrike), Okta, Ping, and Imprivata, are already positioned to ingest these signals to drive policy enforcement and orchestration on their own platforms, from step-up authentication challenges to session termination and access revocation. Imprivata and Ping are Twosense's initial integration partners for this release. The Imprivata integration is documented and live on Imprivata's platform as Advanced Passwordless Access, with CAEP signals flowing between platforms automatically. Ping integration is available today through the Ping DaVinci SKU, with the same automatic signal flow.
"CAEP gives us a standard, out of the box way to plug Twosense's trust signal directly into a customer's existing policy engine," said John Tanios, CTO of Twosense. "Organizations get real-time, automated responses to changes in user trust without writing custom integration code for every application in their stack."
Customer benefits
- Immediate time-to-value: consume standardized, real-time trust signals out of the box, without bespoke engineering or custom integration work
- Faster response to risk: integrated platforms can act on a trust signal the moment it changes, closing the gap between authentication events and enforcement
- Frictionless user experience: continuous, invisible authentication that keeps valid users productive without repeated login interruptions
- Ecosystem interoperability: built on an open standard already supported by leading identity and security platforms, so customers aren't locked into a single vendor's integration path
Availability
This CAEP integration is available now to Twosense customers. Organizations already using Okta, Ping, SGNL, or Imprivata can begin consuming real-time trust signals without additional development work. To see it in action, get a demo or visit www.twosense.ai to learn more.
About Twosense Twosense provides Continuous Authentication and Continuous Access Evaluation (CAE) for workforce identity and access management. Using passive biometrics such as typing patterns and mouse movements, Twosense delivers invisible, always-on authentication that runs in the background, with no phones, tokens, or user training required. It stops threats that occur after login, including session hijacking, credential misuse, and unauthorized access, and can be deployed in a single day, entirely through software. Twosense is trusted by leading BPOs, healthcare systems, and enterprises operating in high compliance, high friction environments. For more information, visit www.twosense.ai.
Media Contact Isabeau Boody Marketing Manager, Twosense E: isabeau@twosense.ai