Protect first, Predict breaches, Enforce action

Protect

Strong IDV

Predict

Persona™

Enforce

TruU’s Proprietary Identity Persona™

TOTAL understands who is acting — not just what they’re doing

TOTAL builds 72-dimension Personas based on cross-domain principles of behavior and psychology.

TOTAL evaluates the risk of each event in the context of an identity Persona.

Personas are continually tested for drift to avert slow moving sophisticated actor and collusion threats.

By setting context, TOTAL reduces false negatives (prevents breaches) & false positives (reduces noise).

  • Mouse movement entropy
  • Keyboard dynamics stability
  • Device Quantity
  • Login cadence anomalies
  • Biometric failures
  • Routine Stability Window
  • Frontline vs knowledge worker
  • Primary device type
  • Deviation from peer enrollments
  • In-person vs remote verification
  • Device trust at enrollment
  • Identity proofing score
  • AI Agent Usage
  • Self Policing Response
  • Cluster Switching Volatility
  • Remote vs In-Person
  • Daily responsibilities
  • Sensitive Data Access
  • Social Eng. Target Score
  • Sentiment shift
  • Context Switch Cadence
  • Collusion indicators
  • Job function congruence
  • Peer cluster
  • Workspace Geo-Anchor
  • Network destination risk
  • Off-hour access attempts
  • VPN or Proxy Reliance
  • SU access to other devices
  • Access Request Denial
  • Entitlement Expansion Velocity
  • Privileged Activity Level
  • File accesses
  • Peer interaction graph
  • Application Usage Patterns
  • Resource access breadth

TruU’s Proprietary Persona Cluster™

Several ”like-cyber-minded” Personas are clustered together using TruU's proprietary algorithm.

Our clustering algorithm enables continuous drift measurements to estimate both threat & vulnerability risk right from Enrollment.

Clustering and drift measurements let TOTAL work with a large stage of risk-actors so even the faintest threats can be monitored in nascent stages.

How TOTAL catches Insider Threats

Risk = f ( Intent, Capability, Stressor, Opportunity)

LEVEL 1

Explicit Rule Violations

Simple EDR/DLP products miss sophisticated threats that do not violate hard-coded rules and persist inside your cyber infrastructure forever. These rule-based systems also generate considerable false positives that flood the SOC with alerts.

To reduce false positives, TOTAL continuously learns from every reviewed alert and confirmed threat. With each analyst decision, the prediction engine grows smarter, reducing noise and automatically enforcing action on known threat patterns. Over time, the result is a SOC that’s leaner, faster, and more intelligent.

LEVEL 2

Contextual Abuse of Legitimate Access

With traditional tools, events are forwarded to the SIEM and investigated retrospectively, after the attack chain has already begun.

TOTAL assesses risk in real time by applying Persona context.

LEVEL 3

Complex Sophisticated & State Actor Attacks

  1. Persona, Clusters & Drift are TruU Proprietary foundations of predicting and thwarting the type of attacks we read about in the news.

  2. A drift from base Persona & a drift from Cluster is measured – whether slow or fast. If it exceeds a threshold, the offending identity is put on an internal watchlist.

  3. When two identity Personas drift either in similar or complementary direction, they are put on collusion watchlist.

TOTAL Eliminates Account Takeover Risk

Sophisticated threat actors launch Account Takeover (ATO) as a multi-pronged vector attack that can neither be avoided nor detected with IT-based IAM tools. State actors lurk, they pounce upon opportunity and relentlessly target vulnerable accounts long after the initial enrollment process. TOTAL delivers early protection, continuous authentication and a backstop AI prediction engine to identify vulnerable identities to self-police or to lock.

LEVEL 1

Eliminate the Credential Attack Surface

Every account takeover begins with credential compromise — passwords, tokens, session cookies, and increasingly, stolen or bypassed MFA.

Attackers no longer need to “hack” systems - they phish credentials, intercept MFA codes, deploy MFA fatigue attacks, or leverage adversary-in-the-middle tooling to steal session tokens in real time.

TOTAL Protect neutralizes this attack vector by eliminating the credentials attackers are trying to steal. If credentials cannot be stolen, the ATO chain cannot begin.

LEVEL 2

Human Compromise and AI-Driven Social Engineering

Modern ATO's escalate beyond credential theft. Attackers increasingly target help desks, support workflows, and identity verification processes through social engineering and AI-powered deepfakes.

TOTAL IDV addresses this through:

  1. Biometric identity verification
  2. Active liveness detection
  3. AI-driven deepfake detection
  4. Device trust verification

LEVEL 3

Continuous Persona Integrity Monitoring

Even the most advanced deepfake detection systems can be challenged. This is where TOTAL extends beyond point-in-time identity verification.

TOTAL continuously evaluates the digital persona behind the account in real time. By analyzing behavioral signals and detecting identity drift, TOTAL determines whether the account remains in the control of its rightful owner.

See TOTAL in action