CAEP brings real-time trust signals to your IAM stack.
Know the moment trust changes, and act on it instantly.
- 1 Twosense continuously verifies identity in the background
- 2 CAEP broadcasts that trust signal in real time
- 3 Your existing tools act on it instantly
- Okta
- Ping
- Imprivata
- SGNL
One trust signal, propagated everywhere it's needed
Continuous authentication watches the session. CAEP makes sure the rest of your stack hears about it too.
Most identity systems only check who you are once, at login. After that, they assume you're still you for the rest of the session.
Twosense's CAEP integration changes that. It makes that same real-time trust signal available to every application in your identity stack, using CAEP, an open standard within the industry's Shared Signals Framework (SSF). Platforms like Imprivata, already common across health systems, can act on a change in trust the instant it happens, without a custom integration project.
CAEP is one part of Twosense's Continuous Authentication Platform → See how it works

What real-time trust unlocks for your stack
Three things get better the moment a trust signal reaches every platform that needs it.
-
Faster response
Most organizations find out about a compromised session after the fact. Your platforms can now act the moment trust changes, whether that's on the clinical floor or in a back office.
-
Zero added friction
This runs invisibly in the background, the same way Twosense already does. Clinicians and administrative staff keep moving at the same pace, your security posture just gets stronger.
-
Works with your existing tools
Okta, Ping, Imprivata, and SGNL can all act on it today. No rip and replace, no new integration to manage.
How our customers are using the CAEP integration
Twosense customers are already using this integration in production, across both clinical and administrative settings, to catch:
-
Unauthorized access
When the behavior behind a session stops matching the authenticated user, whether from stolen credentials or deliberate impersonation, the session is revoked automatically.
-
Badge sharing
A badge lent out for convenience is one of the most common ways credentials get misused in a hospital, in clinical and administrative settings alike. The mismatch gets flagged the moment it happens.
-
Session hijacking
A stolen session token doesn't help an attacker if the behavior behind it doesn't match. The session can end before it's misused.
-
MFA compromise
MFA can be phished or worn down through repeated prompts. This integration keeps watching after MFA clears, catching an imposter who's already gotten past that step.
-
Accidental open session takeover
Someone steps away from a shared clinical device or an admin desk without logging out. The next person doesn't inherit access, the identity switch gets caught immediately.
-
Imprivata Integration Partner
Joint integration documented and live on Imprivata's platform as Advanced Passwordless Access. Read the documentation →
-
Ping Integration Partner
Available today through the Ping DaVinci SKU. CAEP signals flow between platforms automatically.
- Okta
- SGNL
See it running in your own environment
The clearest way to understand what this unlocks is to see it working in a setup that looks like yours. If your organization already runs Okta, Ping, Imprivata, or SGNL, this is worth seeing in action.