Plurilock
Publicly traded Canadian identity-security company whose DEFEND platform uses behavioral biometrics for continuous, passive authentication beyond point-in-time MFA.
Visit Website ↗ + Add to CompareOverview
Plurilock is a publicly traded (TSXV: PLUR, OTCQB: PLCKF) Canadian identity-security company built around behavioral biometrics. Its DEFEND platform continuously authenticates users by analyzing keystroke and mouse-movement patterns in real time, aiming to catch account takeover, session hijacking, or credential sharing even after an attacker has obtained valid login credentials.
The differentiation versus standard multi-factor authentication is continuity: DEFEND runs passively in the background rather than checking identity only at login, which is meant to catch misuse that happens after a legitimate authentication event, something one-time push or OTP checks cannot do. Alongside DEFEND, Plurilock also operates a broader identity, PAM, and SSO integration and reseller business under the Plurilock Solutions brand.
Plurilock has been a public company since 2021 and reports meaningful trailing revenue, though a significant share of that revenue appears to come from its IT/identity reseller and integration business rather than DEFEND product licensing alone — a distinction worth separating when evaluating the company’s core security-product traction versus its total top line. Its market capitalization is small relative to disclosed revenue, and the stock has traded thinly.
Innovation Matrix Assessment
Ongoing DEFEND product and identity-integration development is evidenced by public investor and product updates, indicating active continued investment.
Real disclosed revenue and public-company reporting discipline are genuine signals, but a large share of that revenue reportedly comes from lower-margin IT/identity reselling rather than the core DEFEND security product.
Steady rather than accelerating; small market capitalization (roughly $11-12M) relative to reported revenue suggests the market is not pricing in high growth confidence.
Continuous, passive behavioral-biometric authentication is a genuinely different approach from static point-in-time MFA, addressing the real gap of post-authentication session integrity.
No independent third-party efficacy or accuracy testing of the behavioral-biometrics engine was found; effectiveness claims are vendor-sourced from Plurilock's own materials and investor content.
Account takeover and session hijacking remain major attack vectors that static MFA does not fully address, keeping continuous authentication relevant to modern identity strategy.
Why CISOs Should Care
For CISOs who have already deployed MFA but still worry about session hijacking, credential sharing, or an attacker operating inside an already-authenticated session, Plurilock DEFEND adds a continuous, passive layer of identity verification.
What Makes It Different
Unlike point-in-time MFA such as push notifications, OTP, or hardware tokens, DEFEND authenticates continuously in the background using behavioral signals, catching account misuse that occurs after a legitimate login.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A real, publicly reporting company with a genuinely differentiated continuous-authentication product, but a large share of disclosed revenue comes from Plurilock's IT reseller and integration business rather than DEFEND licensing, and independent efficacy validation of the core engine is limited.
Editorial Note: Claims vs. Verified Findings
Plurilock's revenue figures are independently verifiable through public company filings (TSXV: PLUR), but the split between core DEFEND product revenue and lower-margin identity/IT reseller revenue is not clearly broken out in public sources. Specific efficacy and accuracy claims about the behavioral-biometrics engine itself are vendor-sourced rather than independently tested.
Sources
Alternatives to Plurilock
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Silverfort
Agentless unified identity protection platform that extends MFA, ITDR, and access policy to legacy and unmanaged systems traditional…