Secure launch

The click is simple.The checks behind it are not.

A launch validates the signed-in user, current 2FA state, effective permission, policy conditions and the exact approved destination before the supported login component proceeds.

Short-lived, single-use, destination-bound launch authorization

How a launch runs

Four checks between the click and the client site.

  1. Step 1

    Verify

    The session must be current and the account must have completed mandatory two-factor enrolment.

  2. Step 2

    Authorize

    Effective permission is evaluated per resource, and a short-lived single-use authorization is issued.

  3. Step 3

    Open

    The exact approved destination is opened in a new tab and the supported login component completes sign-in without auto-submitting.

Boundaries we state plainly

What Secure Launch does and does not promise.

Does

Removes reveal, copy and export from everyday work, binds each launch to one destination and records the event.

Does not

Claim a browser-delivered credential is impossible to extract by a technically privileged endpoint user, or bypass third-party MFA, CAPTCHA or anti-bot controls.

Standard systems get Secure Launch today.

For systems where the credential should never reach the endpoint, Brokered Access is in development — talk to us about the timeline.