Continuous behavioral authentication
Login proves who you were.
2bME keeps checking who you are.
2bME learns how you type, point, scroll and switch apps, using timing alone and never content. It keeps a live trust score for the person at the keyboard. When someone else takes over, trust falls block by block and a voice check steps in. That check catches cloned voices too.
confidence that the enrolled owner is still at the keyboard
How it works
Identity isn't a moment. It's a rhythm.
Three steps, running all the time in the background.
Enroll
Work normally for a while. The on-device agent turns keyboard, pointer, scroll and app-switch timing into privacy-safe evidence blocks, and 2bME trains an identity model that is yours alone.
Continuous trust
Every 5 seconds, fresh blocks are scored against your profile and fused into one trust score. Credentials never buy high trust. Only behavior does. A different person at the keyboard drags it down.
Voice step-up
When trust stays below 40% or a risky action needs more, ElevenLabs speaks a random phrase. We check the words, the speaker and the spectrum, and an anti-spoof model catches cloned voices.
- Behavioral confidence ≈ 97%
- Known user, co-present with the laptop
- Y frictionless checkout
- Behavioral confidence ≈ 31%
- C step-up authentication
- Voice (or TOTP) challenge
- Verify Y or block N
The behavioral signature
Every branch of the signature maps to measured features
Each leaf below comes straight from our feature spec. A dot lights up when a recent evidence block carried that signal (simulated stream). Hover a leaf to see its features.
- Hold duration
- Inter-key latency
- Digraph/trigraph timing
- Typing cadence
- Pause/burst behavior
- Correction behavior
- Velocity
- Acceleration
- Curvature
- Jerk/smoothness
- Click timing
- Hover/dwell behavior
- Velocity
- Burst length
- Inter-scroll timing
- Direction/reversals
- Application switching
- Task-switch latency
- App transition patterns
- Window/tab behavior
- Keyboard-mouse transitions
- Event frequency
- Burstiness
- Idle intervals
- Periodicity
- Frequency-domain / FFT
Privacy is part of the product
Timing, never content
We never record
- Anonymized on the device. Which key you pressed is reduced to a hand-level class (left letter, right letter, space…) the moment it's captured, and the original is discarded. All digits collapse into one class, so PINs and card numbers can't be recovered.
- Only aggregates leave. The agent sends percentiles, rates and counts per evidence block. It never sends a per-key sequence, absolute screen coordinates, app names or window titles. Apps become a category such as browser or IDE.
- Password fields make the keyboard blind. While macOS Secure Event Input is on, keyboard evidence is treated as missing, not anomalous.
Voice, disclosed plainly
Our server deletes challenge audio after scoring and stores only embeddings and scores. ElevenLabs processes the prompt and STT audio and, on our plan, retains it in account history (Zero Retention is enterprise-only). STT_BACKEND=local avoids this.Every dashboard has a “What left this laptop” drawer. It shows the literal last payload the agent sent.
Built with