PresenceAssure

Verify Presence.
Assure Access.

PresenceAssure delivers high-assurance authentication for Windows and web single sign-on by verifying user identity and real-time physical presence. It supports touchless experiences and phishing-resistant methods such as FIDO and certificate-based authentication, including PIV, at initial login and can continuously verify presence throughout the session—without replacing existing identity infrastructure.

Request a demo How it works
Challenge

When Identity Alone Is Not Enough

Passwords, one-time codes, and federated identities can establish that a valid credential was presented. Even strong authentication methods do not necessarily confirm that the authorized person remains physically present and actively participating after authentication.

For regulated organizations, that distinction matters. Credentials may be phished, shared, relayed, or misused. High-risk applications and sensitive workflows require assurance that the right person—not merely the right credential—is present at login and, when policy requires, remains present throughout the session.

PresenceAssure closes this assurance gap by orchestrating supported authentication methods with configurable presence, proximity, liveness, and biometric signals.

Credential Theft and Relay Attacks

Bad actors can steal, mimic, or exploit captured credentials. Organizations need strong authentication methods that resist phishing attempts and tether the authorized interactive user to the authentication process before access is granted.

Point-in-Time Authentication/h3>

A successful login verifies a moment in time. It does not necessarily establish that the same authorized user remains present and actively participating throughout the session.

Fragmented High-Assurance Controls

Different applications, users, and risk levels often require different factors. Without centralized orchestration, stronger controls can become inconsistent, difficult to audit, and disruptive to users.

Solution

PresenceAssure: High-Assurance Authentication Built Around Real Presence

PresenceAssure began as a touchless biometric authentication system and has evolved into a configurable authentication and policy-orchestration platform. It verifies who the user is and whether the user is physically present by combining supported authentication methods with proximity or wearable signals, liveness detection, and biometric matching. Workflows can be tailored to each application, user group, role, and risk level.

Designed for regulated enterprises, PresenceAssure strengthens Windows Authentication and web SSO while integrating with Active Directory, cloud identity providers, and standards-based federation. It supports FIDO and certificate-based authentication, including PIV, and can be deployed on-premises or through a public/SaaS cloud model.

01

Presence-Based Authentication

Confirms that the authorized user is physically present when access is requested.

02

Strong Authentication Methods

Supports phishing-resistant methods such as FIDO and certificate-based authentication, including PIV. Smart cards, security keys, and wearables are supported form factors rather than separate authentication methods.

03

Configurable Workflow Engine

Lets administrators compose authentication journeys with mandatory or optional steps, retry limits, timeouts, fallback methods, and biometric logic.

04

Targeted Policy Assignment

Applies workflows to specific applications, user groups, roles, and risk conditions for proportionate assurance.

05

Login and Continuous Assurance

Verifies the user at initial login and can continuously verify presence throughout the session according to configured policy.

06

Contactless and Passwordless Experiences

Provides a touchless alternative to conventional inserted-card PIV workflows while preserving certificate-based authentication. PresenceAssure can also add presence or biometric verification before or after an existing PIV authentication step.

07

Centralized Governance and Audit

Provides dashboards, authentication outcomes, user trends, reporting, and audit trails for operational oversight, compliance, and investigation.

08

Identity Provider Integration

Integrates with Windows Authentication, Active Directory, cloud identity providers, and web SSO environments without replacing existing identity or authorization systems.

How It Works

A Configurable Journey from Access Request to Assured Session

PresenceAssure evaluates the authentication context, invokes the required methods and factors, verifies identity and real presence, and applies the organization’s authentication policy. The workflow supports initial authentication and, when configured, continued presence verification throughout the session.

Select the Authentication Workflow

A Windows Authentication or web SSO request initiates the workflow assigned to the application, user, group, role, or risk condition. Administrators determine which methods and verification steps are required and which fallback paths are permitted.

Verify Possession and Proximity

PresenceAssure can use FIDO or certificate-based authentication, including PIV, to confirm possession. Supported form factors can include smart cards, security keys, wearables, hardware tokens, and proximity devices according to policy.

Confirm Liveness, Presence, and Identity

Configurable liveness detection helps resist spoofing, while facial or iris matching verifies the user. Thresholds, retries, timeouts, and fallback methods can be adjusted to the environment and level of risk.

Complete Authentication and Reassess Presence

When authentication policy requirements are satisfied, PresenceAssure returns the authentication result to the connected Windows or web SSO environment. The identity provider or application then applies its authorization policy. When configured, PresenceAssure continues to verify presence during the session and records authentication outcomes for audit and investigation.

PresenceAssure Process Diagram
Integration and Deployment

Integrate with the Identity Providers and Platforms You Already Use

PresenceAssure adds presence and biometric assurance to existing authentication environments. Organizations retain their identity providers, applications, credentials, and authorization policies while integrating configurable verification into Windows Authentication and web SSO workflows.

Windows Authentication and Active Directory

Extend high-assurance authentication to Windows access in local and Active Directory environments.


Cloud Identity
Providers

Connect PresenceAssure to Microsoft Entra ID and other supported cloud identity providers within existing web SSO environments.

Enterprise Application Integration

Integrate enterprise applications through supported federation interfaces, including SAML and OIDC, while retaining the existing identity provider and authorization model.

FIDO and Certificate-Based Authentication

Orchestrate FIDO and certificate-based authentication, including PIV, within policy-driven workflows. Supported form factors can include smart cards, security keys, and wearables.

Biometric and Presence Signals

Combine camera-based face or iris matching and liveness checks with supported wearable, token, and proximity signals according to the deployment.

Deployment
Options

Deploy PresenceAssure on premises or through a public/SaaS cloud model according to security, operational, and regulatory requirements.

Regulated Environments

Designed for Organizations That Require Higher Identity Assurance

PresenceAssure supports regulated enterprises that require higher identity assurance, consistent authentication policy, and auditable authentication outcomes. This includes federal government and defense, healthcare, financial services, critical infrastructure, and manufacturing environments.

Federal government and defense

Federal and defense organizations can modernize PIV-based authentication with touchless workflows that preserve certificate-based authentication. PresenceAssure can also add proximity, liveness, or biometric verification before or after an existing PIV step and continuously verify presence throughout the session according to policy.

Healthcare

For healthcare providers, PresenceAssure supports touchless authentication at clinical and shared workstations, helping authorized staff sign in without repeatedly handling cards or readers while maintaining high identity assurance. Zeva’s real-world healthcare experience informs workflows designed for speed, hygiene, shared-device use, and auditable authentication.

Standards and Zero Trust Alignment

Support Stronger Digital Identity and Zero Trust Programs

PresenceAssure supports policy-driven authentication aligned with the principles of the NIST SP 800-63-4 Digital Identity Guidelines and NIST SP 800-207 Zero Trust Architecture. It combines supported authentication methods, federation, contextual policy, and real-time presence signals to strengthen identity assurance at login and throughout the session.

Why PresenceAssure

Stronger Assurance

Verify both the credential and the person through configurable combinations of possession, proximity, liveness, and biometric factors.

Lower User Friction

Use touchless and passwordless experiences where supported while maintaining the level of identity assurance required by each environment.

Centralized Control

Apply consistent workflows, monitor authentication outcomes, and maintain audit trails across Windows and web SSO environments.


Verify More Than Credentials.

See how PresenceAssure can add real-time presence assurance to your existing Windows Authentication, web SSO, and identity environment. Request a demonstration to explore the authentication methods, presence factors, and deployment model that fit your organization.

Request a Demo