Skip to content

Plurilock

Publicly traded Canadian identity-security company whose DEFEND platform uses behavioral biometrics for continuous, passive authentication beyond point-in-time MFA.

Visit Website ↗ + Add to Compare
55/100Incremental Innovator

Overview

Plurilock is a publicly traded (TSXV: PLUR, OTCQB: PLCKF) Canadian identity-security company built around behavioral biometrics. Its DEFEND platform continuously authenticates users by analyzing keystroke and mouse-movement patterns in real time, aiming to catch account takeover, session hijacking, or credential sharing even after an attacker has obtained valid login credentials.

The differentiation versus standard multi-factor authentication is continuity: DEFEND runs passively in the background rather than checking identity only at login, which is meant to catch misuse that happens after a legitimate authentication event, something one-time push or OTP checks cannot do. Alongside DEFEND, Plurilock also operates a broader identity, PAM, and SSO integration and reseller business under the Plurilock Solutions brand.

Plurilock has been a public company since 2021 and reports meaningful trailing revenue, though a significant share of that revenue appears to come from its IT/identity reseller and integration business rather than DEFEND product licensing alone — a distinction worth separating when evaluating the company’s core security-product traction versus its total top line. Its market capitalization is small relative to disclosed revenue, and the stock has traded thinly.

Innovation Matrix Assessment

Innovation Velocity 6/10

Ongoing DEFEND product and identity-integration development is evidenced by public investor and product updates, indicating active continued investment.

Operational Value 5/10

Real disclosed revenue and public-company reporting discipline are genuine signals, but a large share of that revenue reportedly comes from lower-margin IT/identity reselling rather than the core DEFEND security product.

Market Momentum 5/10

Steady rather than accelerating; small market capitalization (roughly $11-12M) relative to reported revenue suggests the market is not pricing in high growth confidence.

Category Disruption 6/10

Continuous, passive behavioral-biometric authentication is a genuinely different approach from static point-in-time MFA, addressing the real gap of post-authentication session integrity.

Real-World Efficacy 4/10

No independent third-party efficacy or accuracy testing of the behavioral-biometrics engine was found; effectiveness claims are vendor-sourced from Plurilock's own materials and investor content.

Enduring Relevance 7/10

Account takeover and session hijacking remain major attack vectors that static MFA does not fully address, keeping continuous authentication relevant to modern identity strategy.

Why CISOs Should Care

For CISOs who have already deployed MFA but still worry about session hijacking, credential sharing, or an attacker operating inside an already-authenticated session, Plurilock DEFEND adds a continuous, passive layer of identity verification.

What Makes It Different

Unlike point-in-time MFA such as push notifications, OTP, or hardware tokens, DEFEND authenticates continuously in the background using behavioral signals, catching account misuse that occurs after a legitimate login.

The Matrix Verdict

55/100 — INCREMENTAL INNOVATOR

A real, publicly reporting company with a genuinely differentiated continuous-authentication product, but a large share of disclosed revenue comes from Plurilock's IT reseller and integration business rather than DEFEND licensing, and independent efficacy validation of the core engine is limited.

Editorial Note: Claims vs. Verified Findings

Plurilock's revenue figures are independently verifiable through public company filings (TSXV: PLUR), but the split between core DEFEND product revenue and lower-margin identity/IT reseller revenue is not clearly broken out in public sources. Specific efficacy and accuracy claims about the behavioral-biometrics engine itself are vendor-sourced rather than independently tested.

Sources