
A fourth security layer is forming.
Yuthent is defining its standard.
A stolen session, an AI agent, and a real person look identical to your logs. Yuthent proves a specific human authorized a specific action, at the moment it fires, not after. Execution authority: the layer after authentication, authorization, and audit. PSEA: Post-Session Execution Assurance.
Session valid ≠ human approved.
Every system verifies identity once, at login, then trusts the session, not the human. Tokens get stolen, replayed, and handed to AI agents, and every control the enterprise already owns still clears the action. FIDO2 and passkeys sign the login, not the action: no deployed control binds a specific action to a specific human's approval at the moment it executes.
Business email compromise
clearsControl already owned: MFA at login + valid session
The attacker operates inside a fully authenticated session.
AI agent action
clearsControl already owned: OAuth token / service credential
The agent acts with the session's authority, no human present.
Account takeover
clearsControl already owned: Step-up auth / transaction signing
Re-authenticates the session, not the human. A script that passed step-up passes again.
Insider privilege abuse
clearsControl already owned: RBAC + audit logging
Records that the session acted, never that a human approved it.
of web-app breaches use valid stolen credentials, the session is real; the human is not.
of all breaches involve the human element, with MFA bypass via token and session-cookie theft now a documented, scaled technique.
in business email compromise losses across 21,442 incidents in one year, a single vector operating inside valid sessions.
Sources: Verizon 2025 DBIR (basic web application attacks via stolen credentials; human element). FBI IC3 2024 (BEC losses and incident count).
Non-human action went mainstream. Human proof became law.
Autonomous agents now execute real actions at scale with no human behind them, and binding regulation now requires proof that a human authorized high-risk actions. The two forces met this year, and the layer that provides that proof does not exist yet.
The market force · autonomous agents
of enterprise apps embed task-specific AI agents, in a single year, 2025 to 2026 (Gartner).
already run AI agents in production, not first deployments. The shift already happened (CSA / Aembit, RSAC 2026).
cannot tell a human action from an AI agent's. The blind spot, measured (CSA / Aembit).
The regulatory force · human authorization
Art 9(4)(d): strong authentication and cryptographic key protection. RTS Art 21: ad-hoc privileged access.
Req 8.4.2 / 8.5.1: phishing-resistant authentication, not susceptible to replay.
Affirmative human override for high-risk systems; four-eyes for biometric systems. Up to €15M or 3% of global turnover.
Machine-speed action met human-accountability law in the same year. The market answers with process, halt buttons, and audit logs, none of which prove the authorized human approved the action. The standard that does is being written now, and Yuthent is writing it , the IETF draft and the OWASP AISVS approval-integrity requirement.
The fourth security control plane. We own the definition.
Authentication answers who you are. Authorization answers what you may do. Audit keeps the record. The moment of action falls in the gap between them, execution authority is the fourth layer that closes it. A $100B+ category by 2030 (IAM and fraud prevention combined, MarketsandMarkets). Yuthent is not competing inside this category; it is defining its standard.
US 19/404,862
No §101 / §102 / §112 rejections. The §103 response moves the independent claims to a device-centric architecture, a narrower, less-crowded category than the cited prior art. Copending sibling 19/401,636.
draft-yossif-psea-02
Published specification with canonical encoding test vectors, and first author of the survey that named the Authorization Evidence category, where PSEA holds the highest assurance bar.
Requirement C9.2.4
Authored the approval-integrity requirement merged into OWASP AISVS 1.0. The category is converging across two standards bodies.
Incumbents pay to enter
Per-action proof concedes that session validity is insufficient, the premise incumbents sell. They acquire the category, not build it. Nine figures is the floor, not the ceiling.
Why incumbents cannot build this.
The barrier is incentive, not engineering. An IdP's revenue model is per-seat session licensing. Per-action signing redefines the unit of value, requires a different buyer, a Head of Risk or CCO, not an IT admin, and concedes that session validity is insufficient, undermining what incumbents sell. The expected path is acquisition, not build.
Per-action cryptographic proof
IdPs prove the session. PAM covers the vault. Passkeys sign the login. Nobody signs the action itself, the amount, the recipient, the command, at the moment it fires.
Hardware-bound on the device people carry
Signed inside Secure Enclave and StrongBox on the operator's own phone, not a software token, not a data-center HSM.
Offline-first per-action signing
The approval needs no network. Only the highest assurance tier calls the server synchronously.
AI-agent human-oversight proof, by design
A direct mapping to EU AI Act Article 14 human-override requirements, a positioning no incumbent has taken.
Fixed annual price. Priced on throughput.
The CFO gets a predictable number, never a per-action bill. Price is sized by contracted throughput, in actions per second: three published plans, with a custom step above them. Users, devices and action volume are uncapped. Deployment is an isolation choice and does not move the figure. Price steps up only at renewal, never a mid-year invoice. Usage shapes our cost, never the customer's invoice.
Hosted multi-tenant
Live todayRegulated enterprise
Fully isolated tenant, Yuthent-hosted.
Dedicated cloud
By requestEnterprise with data-residency mandates
Single-tenant isolation, scoped on request.
On-prem black-box
By requestGovernment, sovereign deployments
Runs inside the customer's own perimeter, scoped on request.
Entry to the published ladder: 25 actions per second sustained, with users, devices and action volume uncapped.
Top published plan: 150 actions per second. Sustained rates above that are scoped directly.
Structural gross margin, modeled, confirmed under first deployment billing. Per-deployment infrastructure runs at near-zero marginal cost.
One category, sized two ways, and they agree.
A top-down ceiling and a bottom-up count of institutions legally required to prove human authorization, built independently, landing in the same neighborhood.
by 2030, IAM and fraud prevention combined (MarketsandMarkets), placed as the category ceiling.
Institutions legally required to prove human authorization: ~22,000 DORA financial entities in the EU, plus banks, health, and government. Serviceable subset × fixed annual price.
2–5% capture, tens of enterprise logos. The financial plan reaches $6–12M by year 3; this is the same trajectory, extended.
The cross-check: the bottom-up SAM lands at 1–3% of the $100B top-down category. Two independent methods, same neighborhood.
Every dollar traces to a measured unit: a capacity ladder priced on sustained throughput alone: three published plans at $350K for 25 actions/sec, $900K for 75 and $2M for 150, with a custom step above them. Users, devices and action volume are uncapped on every plan. Only the rate is contracted, and only the rate moves the price.
One wedge. Three markets. Three forcing functions.
The wedge never changes: cryptographic proof that a specific human authorized a specific action, under a regulatory mandate. An open standard (IETF, OWASP) lets a regulated buyer adopt a category, not a lock-in. The signer is a Head of Risk or CISO, and the mandate compresses the cycle to months.
Israel
Trusted introductions inside the financial and health network.
Where we prove it, the first deployments.
Europe
DORA is in force; per-action human authorization moves from optional to expected.
Where the mandate sells, ~22,000 regulated entities.
United States
Cyber insurers price execution-authority risk into coverage.
Where it turns must-have, a condition, not a nice-to-have.
Where Yuthent stands today.
Everything below is traceable to a document in the data room or to code, including the parts that are still ahead.
Full stack, built and measured
iOS and Android SDKs, backend, and admin portal, built pre-funding. Verified in code: A-tier fail-closed, server-side caller-binding and attestation, crypto-health gate. Load- and soak-tested: ≈150 req/s sustained on the proof path; 99.99985% accept over an 8-hour soak (646,443 of 646,444).
Two standards bodies
First author of the IETF draft (psea-02) and of the approval-integrity requirement merged into OWASP AISVS 1.0. The category definition is converging around work we authored.
Patent in prosecution
US 19/404,862 with no §101 / §102 / §112 rejections, sibling 19/401,636 copending, the device-centric primitive under the SDK.
$400K Google Cloud credits
Google Cloud for Startups, infrastructure runway at near-zero cost through the first deployment phase.
Programs
SafeNology (Takwin Ventures and S.T-Impact): active. Hasoub Labs: Cohort 4.
Stated plainly
Pre-deployment, zero paying customers. The pipeline is real and moves on trusted introductions inside the financial and regulatory network. External cryptographic review and penetration test are funded milestones of this round, not yet performed.
Founder, advisor, and technical validation.
Mohamad Khalil Yossif
Founder & CEO
Authored the PSEA model and the IETF draft. Built the full stack, iOS and Android SDKs, backend, portal, pre-funding.
Itamar Laron
Advisor
Asparna Venture Studio. Product and go-to-market guidance.
Senior Security Engineer
Validation · engaged
Independent protocol and SDK security review.
PhD Researcher
Hardware security · engaged
Bar-Ilan Secured Electronic Systems Lab. Cryptographic design review.
Key-person risk, addressed. The full stack was built solo and pre-funding: execution capability is proven, not promised. The first hires on close are a technical BD lead and engineering, removing single-founder dependency; the advisor and independent security validators are engaged today.
A seed round built to validate the category, and lock it.
Capital-efficient by structure: two tranches, with the second gated to a signed paid first deployment or binding LOI, investor exposure capped until willingness-to-pay is proven. Full terms, the financial plan, and the data room are shared under NDA.
Revenue proof
First paid deployments converted to annual contracts in the entry vertical, the commercial proof that unlocks Series A.
Audit-passed platform
External cryptographic and penetration-test audits and hardening, delivered by a founding team hired against these milestones.
Category ownership
draft-yossif-psea at the IETF, first author of the survey that named the category, and the patent in prosecution.
The questions diligence asks first.
What stage is Yuthent?
Seed. The full stack, iOS and Android SDKs, backend, and admin portal, is built and load-tested. The commercial motion is a paid first deployment on one critical flow, converting to an annual capacity plan between $350K and $2M. Today Yuthent has zero paying customers, and says so plainly; the pipeline moves on trusted introductions inside the financial and regulatory network.
What is actually built today?
The full product: native iOS and Android SDKs, the backend, and the customer portal, built pre-funding. Measured performance: ≈150 req/s sustained on the proof path and 99.99985% accept over an 8-hour soak. External cryptographic review and penetration test are funded milestones of the round, not yet performed, that distinction is stated everywhere it matters.
What protects the position?
Three assets. A patent in prosecution (US 19/404,862, no §101/§102/§112 rejections, sibling copending). Standards authorship, first author of the IETF draft (psea-02) and of the approval-integrity requirement merged into OWASP AISVS 1.0. And an incentive barrier: per-action proof concedes that session validity is insufficient, which is the premise incumbents sell, the precedent is that they acquire the category (Spera → Okta, Entitle → BeyondTrust), not build it.
What is the business model?
A fixed annual price sized by contracted throughput, in actions per second: three published plans at $350K for 25, $900K for 75 and $2M for 150, with a custom step above them. Users, devices and action volume are uncapped on every plan. Deployment (hosted multi-tenant live, dedicated cloud and on-premise by request) is an isolation choice and does not move the price. Price steps up only at renewal. Structural gross margin is modeled above 80%, confirmed under first deployment billing.
How do I get the deck and the data room?
Email investors@yuthent.com. The full data room, financial model, technical whitepaper, measured-performance results, cap table, and regulatory research, is organized, current, and available under NDA.
Proving human authority at the moment of action, never inherited from login.
The full data room is organized and current: financial model, technical whitepaper, measured performance, cap table, regulatory research, available under NDA on request.