F8th
Toronto-based continuous authentication vendor using passive behavioral biometrics (mouse, keyboard and device signals) to detect account takeover and session hijacking after login, rather than relying on a single MFA check at the front door.
Visit Website ↗ + Add to CompareOverview
F8th is a Toronto-based cybersecurity vendor founded in 2019 that builds continuous, passive authentication technology based on behavioral biometric analysis. Rather than authenticating a user once at login, F8th’s platform analyzes ongoing signals such as mouse movement, keyboard cadence and device interaction patterns to validate session integrity throughout a user’s activity, aiming to catch account takeover, session hijacking and insider threats that occur after a legitimate MFA challenge has already been passed.
The company positions its technology as a complement to existing IAM and MFA infrastructure rather than a replacement, integrating via API so that banks, government agencies and enterprises can add a continuous trust layer without ripping out existing authentication stacks. F8th has cited partnerships and integration work involving IBM and AWS-hosted environments as part of its go-to-market with financial institutions and government customers.
F8th closed a pre-money seed round reported at $17 million, valuing the company at roughly $20.5 million, and has been recognized in Canadian fintech/fraud-prevention startup rankings. For CISOs and fraud teams concerned about post-authentication attacks, particularly session hijacking and credential replay that bypass a one-time MFA check, F8th’s passive continuous-authentication layer addresses a real gap; as a small, early-stage vendor its efficacy claims currently rest primarily on its own reporting rather than independent third-party testing.
Innovation Matrix Assessment
Single core continuous-authentication product line since 2019 with incremental integration partnerships (IBM, AWS); no evidence found of major recent platform expansion or new product lines.
Small team (11-50 employees), limited independent press coverage, and go-to-market claims (banks, government) not corroborated by named customer case studies in available sources.
A reported ~$17M pre-money seed round and a 'top fraud detection startup in Canada' listing are the main momentum signals found; both come from company/PR-adjacent sources rather than independent financial reporting.
Continuous, passive post-authentication monitoring using behavioral biometrics addresses a real gap left by point-in-time MFA, though the behavioral-biometrics approach itself is an established technique used by several other vendors (BioCatch, F5, etc.), limiting true novelty.
Efficacy claims (real-time detection of account takeover, session hijacking, insider threats) are presented on the company's own site without independent benchmarking or named customer validation found in available sources.
Post-login session compromise and account takeover remain active, well-documented attack patterns for banks and government agencies, keeping the continuous-authentication use case relevant regardless of F8th's own market share.
Why CISOs Should Care
Security teams that already have MFA in place but remain exposed to session hijacking, cookie theft and account-takeover after a successful login get a passive, low-friction continuous verification layer that integrates alongside existing IAM rather than replacing it.
What Makes It Different
Focuses specifically on post-authentication session integrity via passive behavioral biometrics (mouse, keyboard, device signals), positioned as a one-line-of-code addition to an existing IAM/MFA stack rather than a standalone identity platform.
The Matrix Verdict
45/100 — EMERGING / UNRANKED
A small, early-stage continuous-authentication vendor addressing a genuine post-MFA security gap; the underlying approach is credible but not unique to F8th, and independent validation of its detection efficacy is currently thin.
Editorial Note: Claims vs. Verified Findings
Funding figures ($17M pre-money seed, ~$20.5M valuation) and the IBM/AWS partnership claims were found primarily in company-adjacent sources (Crunchbase, PitchBook profile summaries, company site) without independent financial-press corroboration; treated here as company-reported rather than independently confirmed.
Sources
Alternatives to F8th
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
AppViewX
Machine identity management platform automating certificate lifecycle management (CLM) and PKI operations at enterprise scale, including post-quantum cryptography…