Secure launch
The click is simple.The checks behind it are not.
A launch validates the signed-in user, current 2FA state, effective permission, policy conditions and the exact approved destination before the supported login component proceeds.
Short-lived, single-use, destination-bound launch authorization
How a launch runs
Four checks between the click and the client site.
Step 1
Verify
The session must be current and the account must have completed mandatory two-factor enrolment.
Step 2
Authorize
Effective permission is evaluated per resource, and a short-lived single-use authorization is issued.
Step 3
Open
The exact approved destination is opened in a new tab and the supported login component completes sign-in without auto-submitting.
Boundaries we state plainly
What Secure Launch does and does not promise.
Does
Removes reveal, copy and export from everyday work, binds each launch to one destination and records the event.
Does not
Claim a browser-delivered credential is impossible to extract by a technically privileged endpoint user, or bypass third-party MFA, CAPTCHA or anti-bot controls.
Standard systems get Secure Launch today.
For systems where the credential should never reach the endpoint, Brokered Access is in development — talk to us about the timeline.
