Founding Program · 4 of 5 slots remaining

Behavioral Identity Threat Detection

Microsoft identifies identity risk. AuthLokr extends that detection with tenant-specific behavioral baselines, post-authentication activity correlation, and explainable risk scoring.

A complementary layer for Microsoft 365 environments — surfacing insider risk, session anomalies, and attack-chain correlations that benefit from tenant-specific behavioral context.

  • Microsoft-native
  • Agentless
  • Read-only by default
  • Explainable AI
  • Designed to deploy in under an hour
6
Detection dimensions
30-day
Baseline learning
Explainable
AI reasoning per alert
High Risk2m ago

Impossible travel + unfamiliar device

alice.anderson@company.com

Finance · Global Admin · Baseline: 94 days

0.87
Risk
Impossible travel detected
Moscow, Russia → 5,309 mi from baseline (Denver, CO)
New device: macOS Safari
User always authenticates on Windows 11 Chrome
Time: 02:34 AM local
Outside normal pattern (08:12–18:47)
Dimension scores
0.00 – 1.00
Location0.94
Temporal0.81
Device0.88
Access0.63
Volume0.21
State0.35
Explainable AI

Location baseline for this user is Denver metro (98% of sign-ins, 90 days). Combined with a first-seen device and off-pattern time window, the correlated risk exceeds the compromise threshold.

Founding Program — 4 of 5 Slots Remaining

Become part of AuthLokr's founding customer cohort

A limited-time offer for the first 5 qualifying organizations. Locked founding economics in exchange for reference rights and quarterly roadmap input. Applications close September 30, 2026.

  • 24-month price lock at $7.20/user/month (20–40% below market rate)
  • Perpetual 10% discount forever after the 24-month lock — price protection for life
  • Reference rights included (become a case study, help us close future deals)
  • Quarterly roadmap input — you influence what gets built next
  • $15–25K pilot fee credited toward your first month of subscription
  • Direct engineering access, not just support
The gap other tools leave

Authentication succeeded. Is the identity still behaving like itself?

Microsoft Entra ID Protection and SIEM tooling identify identity risk at sign-in and across audit streams. AuthLokr adds a complementary layer: tenant-specific behavioral baselines and post-authentication correlation that helps surface insider risk, session anomalies, and attack chains with analyst-friendly, explainable reasoning.

  • Insider and post-auth activity benefits from user-level behavioral context.
  • Tenant-specific baselines complement native, global risk models.
  • Correlating sign-in, role, session, and data events shortens investigations.
Native tooling

Global identity risk model with strong sign-in and audit signals.

AuthLokr extends

Adds tenant-specific behavioral baselines per user across 6 dimensions.

Native tooling

Rich individual events across sign-in, role changes, and audit logs.

AuthLokr extends

Correlates those events into explainable attack-chain narratives.

Six detection dimensions

Baselines per user. Correlation across every dimension.

Every alert includes plain-English reasoning. You see why a score was assigned — not just a number.

Location Intelligence

Is this location normal for THIS user? Detects impossible travel and unusual geography.

  • Sign-in from Russia 4h after Denver login
  • First-time country access for a non-traveling role

Temporal Patterns

Does this match when this person normally authenticates?

  • Global Admin accessing systems at 02:00
  • Weekend privileged role activation for a M–F role

Device Fingerprinting

Does this user normally use this device/OS/browser combination?

  • macOS Safari sign-in on a Windows-only baseline
  • Unfamiliar TLS fingerprint on a corporate identity

Access Patterns

Does this user typically touch this resource?

  • Finance user accessing patient records for the first time
  • Engineer opening 42 SharePoint sites never touched in 90 days

Volume Analysis

Is this volume of activity normal for this user?

  • 10× normal file download volume before resignation
  • Bulk mailbox export at off-hours

Account State Monitoring

Detects privilege escalation, MFA tampering, and backdoor authentication.

  • Risky sign-in + Global Admin role granted + suspicious activity
  • MFA method changed inside a scored session

Session Hijacking Detection

Real-time mid-session IP and user-agent monitoring. Blocks continuation on suspicious transitions.

Privilege Escalation Correlation

Ties risky sign-ins to role grants and downstream access — one attack chain, not three isolated events.

AiTM / MitM Indicators

Session trust degradation, network-path anomalies, and browser stack deviation.

Detection in motion

Three real-world attack patterns, scored against tenant-specific behavioral baselines.

Impossible Travel Detection

  1. 109:14 — Login from Denver, CO (trusted device, baseline match)
  2. 210:22 — Login from Moscow, RU (unrecognized device)
  3. 3Δ 68 minutes — 5,400 miles — physically impossible
What P2 alone typically misses

P2 flags atypical travel against generic global thresholds. AuthLokr scores it against this user's own 30-day movement baseline.

Risk score94
  • IMPOSSIBLE TRAVEL — 5,400 miles in 68 minutes
  • UNRECOGNIZED DEVICE FINGERPRINT
  • BASELINE DEVIATION — 4.7σ from user's normal geography
Explainable AI: every score shows the contributing signals, the baseline they deviated from, and the confidence behind the verdict.

How it works

Three phases. No production changes required. Detection starts on day 31.

1. Connect your tenant

Read-only Microsoft Graph API access via OAuth 2.0 for the monitoring platform. Agentless. No production changes. Designed to deploy in under an hour.

2. SanctumOS AI learns baselines

30-day silent learning window per user: location, temporal, device, resource, volume, and account-state patterns — tenant-specific, not a global model.

3. Detect, score, respond

Real-time alerts with explainable AI reasoning. Optional response actions (revoke session, require MFA, disable account) require separately approved delegated permissions.

Why AuthLokr + P2 beats P2 alone

Microsoft Entra ID P2 is strong at identifying known identity risk signals. AuthLokr adds the tenant-specific behavioral context, session-level detection, and attack-chain correlation that sits on top of it.

CapabilityEntra ID P2 aloneAuthLokr + P2
Impossible travel detectionGeneric global thresholdsPer-user behavioral baselines learned from your tenant
Session hijacking detectionLimitedMid-session IP, device, and token anomaly detection
Privilege escalation correlationNot correlated with sign-in riskAudit log + sign-in correlation for full attack chains
Insider threat detectionFocused on external compromiseBehavioral deviation from each user's own normal
Custom behavioral baselinesTenant-wide heuristics30-day learning period per organization and per identity
Attack chain visibilityEvent-by-eventMulti-event temporal correlation and timeline view
Risk score transparencyOpaque risk levelsExplainable scoring with tunable LOW/MED/HIGH/CRITICAL thresholds

AuthLokr is designed to complement Microsoft Entra — not replace it. Capability descriptions reflect typical customer deployments; exact P2 behavior varies by licensing and configuration.

Procurement timing

Making a Microsoft licensing decision this quarter?

P1 → P2 upgrades. P2 annual renewals. E5 cost reviews. Each is a chance to evaluate how a behavioral analytics layer fits alongside your Microsoft identity stack — before the next 12-month commitment.

On P1 today
Evaluating upgrade to P2

Before you upgrade, see how AuthLokr complements native detection with tenant-specific baselines and explainable post-auth correlation.

On P2 today
Annual renewal this quarter

Renewing P2? A 30-day AuthLokr pilot can layer behavioral baselines and attack-chain analytics on top of your existing Entra investment.

On E5 today
Cost optimization review

Reviewing E5 spend? AuthLokr can help identify where behavioral analytics reduce reliance on higher-tier bundles — potentially lowering unnecessary licensing costs.

Transparent pricing

Pricing model

Flat-fee tiers for organizations with 2,500+ users. Per-user pricing below 2,500. Published rates — no "contact us" black box.

Growth

2,500 – 4,999 users
$28,000/month
$336,000 / year
15–20% below comparable P2 spend
  • Custom behavioral baselines
  • Real-time monitoring
  • Privileged role approval workflows
  • Email support
Most common

Scale

5,000 – 9,999 users
$40,000/month
$480,000 / year
30–40% below comparable P2 spend
  • Everything in Growth
  • Advanced dashboards
  • Alert tuning
  • Audit logging

Enterprise

10,000+ users
Customflat fee
Custom annual
40–50% below comparable P2 spend
  • Full suite
  • Dedicated support
  • 24/7 response
  • Custom integrations
Under 2,500 users
$8/user/month

Consistently 20% below Microsoft Entra ID P2 list pricing of $10/user/month.

Founding customer discount
$7.20/user/month for 24 months

All tiers. After the 24-month lock, founding customers keep a permanent 10% discount off the then-current rate.

What's included (all tiers)

Core detection
  • Custom behavioral baselines (30-day learning period per organization)
  • Real-time session monitoring (session hijacking, token replay, impossible travel)
  • Privilege escalation correlation (audit log + sign-in correlation for attack chains)
  • Multi-event temporal correlation (attack chain visibility)
  • Transparent risk scoring (LOW / MEDIUM / HIGH / CRITICAL — tunable thresholds)
Workflows
  • Privileged access approval workflows (block privileged access on HIGH risk events)
  • Real-time alerts dashboard
  • Attack timeline visualization
  • Monthly executive summary reports
Support
  • Email support (business hours, 24-hour response SLA)
  • Self-service deployment (documentation portal, 2-hour kickoff call)

Optional add-ons

Professional Support

+$5,000/month
  • Priority email + phone support (business hours)
  • 4-hour response SLA for critical issues
  • Quarterly business reviews (QBR)
  • Direct Slack channel with the support team
  • Custom detection rule setup (3 rules included)
  • Integration assistance (1 integration)
  • Quarterly risk posture reports

Enterprise Support

+$10,000/month
  • 24/7 phone + email support
  • 1-hour response SLA for critical issues
  • Dedicated Customer Success Manager (CSM)
  • Private Slack channel with the engineering team
  • Monthly strategic check-ins
  • Unlimited custom detection rules
  • Unlimited integrations
  • Bi-weekly detection tuning sessions
  • SOC workflow optimization consulting
  • Incident response assistance (up to 10 hours/quarter)
  • Post-incident analysis and recommendations
  • Monthly threat hunting support
Paid pilot
$15–25K fixed fee · ~60 days

30 days baseline learning + 30 days live detection. Credited dollar-for-dollar toward your first month(s) of subscription on conversion.

Industry research consistently reports insider incidents in the hundreds of thousands to millions per event. A single detected incident can materially offset platform cost.

What the Founding Customer Program actually is

AuthLokr is early, deliberately. We are taking on 5 founding customers and no more before September 30, 2026. Founding customers get economics and influence that will never be offered again — in exchange for being publicly referenceable and genuinely engaged. It is a two-way commitment, not a discount code.

24-month price lock

$7.20/user/month, or the discounted flat-fee equivalent for your tier. No mid-term increases, regardless of published pricing changes.

Perpetual 10% discount

After the 24-month lock expires, founding customers keep a permanent 10% discount off the then-current rate. Price protection for life.

Quarterly roadmap input

A standing call with the founding cohort where we walk the roadmap, take your prioritization input, and commit to what ships next.

Direct engineering access

Not a support queue. Founding customers work directly with the engineers building the detection logic.

What we ask in return
  • · Reference rights: participate in a case study, testimonial, and periodic reference calls with prospects.
  • · Deploy in production within 60 days of signature so baselines have real data to learn from.
  • · Attend the quarterly roadmap call and give candid feedback on detections and false positives.

Pilot path: a $15–25K, ~60-day paid pilot rolls straight into a founding slot at conversion, with the pilot fee credited toward your first month(s) of subscription.

Built for

Regulated, understaffed, high-risk.

AuthLokr is tuned for mid-market Microsoft 365 environments (2,500–50,000 users) where a small security team owns a large blast radius.

Healthcare

Designed to support HIPAA-regulated environments. Insider-risk analytics tuned for patient-record access patterns, off-hours activity, and departing-employee risk windows.

Defense & CMMC

Designed to support CMMC-aligned deployments (Level 2/3 objectives). CUI access monitoring and behavioral correlation. Air-gap capable (Phase 3 roadmap).

Financial Services

SOX-aligned audit trails, fraud-pattern analytics, and privileged-user behavioral scoring for trading, treasury, and admin roles.

Security & Compliance

Built for regulated environments.

Patent pending

Behavioral threat detection methodology patent filed Q3 2026.

SOC 2 Type II

Roadmap objective. Targeted for Q4 2026; not yet certified.

HIPAA-ready

Designed to support HIPAA-regulated environments. Read-only audit-log access. No PHI stored.

CMMC-aligned

Designed to support CMMC-aligned deployments (Level 2/3 objectives). Air-gap capable on Phase 3 roadmap.

Data privacy

Customer data stored in customer region. No external telemetry.

Least-privilege access

Core monitoring uses read-only Microsoft Graph scopes via OAuth 2.0. Optional response actions require separately approved delegated permissions.

Ready to see what your baselines look like?

Start with a Founding Program application or a scoped demo. No auto-scheduler — John reads every submission personally and reaches out to book time that works.

The team behind AuthLokr

About BlackCert Labs

BlackCert Labs

BlackCert Labs was founded by engineers and architects who spent years implementing, securing, integrating, and responding inside real enterprise environments — not building marketing demos. Our work has spanned Fortune 500 enterprises, government, critical infrastructure, financial services, and healthcare — across Microsoft cloud, enterprise identity, Zero Trust programs, incident response, threat hunting, compliance, AI security, blockchain and cryptocurrency security, cloud architecture, and enterprise modernization.

After deploying nearly every major security platform available, one pattern became obvious: traditional products generate enormous amounts of alerts and telemetry, yet security teams still spend too much time determining whether authenticated users can actually be trusted. BlackCert Labs exists to close that gap.

AuthLokr was created because this problem appeared repeatedly during real customer engagements — not because it looked interesting on a whiteboard. BlackCert builds the products the team wished they had while defending production environments: focused, explainable, and useful in the middle of an incident.

BlackCert Labs builds security software for organizations that demand practical answers, explainable intelligence, and technology that earns trust in production — not just in demonstrations.