Dispel Identity

Passwords Don't Know Who's Typing Them. Dispel Identity Does.

Complete confidence in who's behind every high-risk OT remote access session, not just the credential, verified to NIST IAL2, without slowing down routine work.

Dispel Identity

Passwords Don't Know Who's Typing Them. Dispel Identity Does.

OT secure remote access at scale, without legacy complexity or delays.

Dispel Identity

Passwords Don't Know Who's Typing Them. Dispel Identity Does.

OT secure remote access at scale, without legacy complexity or delays.

Ready
Acme Corp
Emailaiden.spiering@acme.com
Password**********
7NXF5U / 9EGD AU PPQ9Awaiting read
SGA F07MYU
FT NVJNQ11
7J.QFF.DA.HAJ
ZGGH37G 3Q9NA8X5
G4JCVL, 29 / NB
2MQ8G5
9F4CW G4.P / 5WDJS1 E1F
XQK 86BJ6L
P2VNG8K / YTS9HLNJ
CL5H 0XNDA
RS
KHQXTAY
W7T-JLRB-PSEA
Acme Corp
Emailaiden.spiering@acme.com
Password**********
7NXF5U / 9EGD AU PPQ9Awaiting read
SGA F07MYU
FT NVJNQ11
7J.QFF.DA.HAJ
CL5H 0XNDA
RS
ZGGH37G 3Q9NA8X5
G4JCVL, 29 / NB
KHQXTAY
W7T-JLRB-PSEA

Reducing Identity Risk

Verify the Person, Not Just the Password

Confirm the person, not just the credential. Identity checks, policy triggers, and verification status, all visible the moment access is requested.

Reducing Identity Risk

Verify the Person, Not Just the Password

Confirm the person, not just the credential. Identity checks, policy triggers, and verification status, all visible the moment access is requested.

Reducing Identity Risk

Verify the Person, Not Just the Password

Confirm the person, not just the credential. Identity checks, policy triggers, and verification status, all visible the moment access is requested.

Acme Corp
/Settings/Identity/Aiden Spiering
‹Identities/Aiden Spiering
AS

Aiden Spiering Verified

Identity assurance
What the identity provider verified.
Proven identityVerified
Assurance levelIAL2
DocumentIssuing authorityNumberIssuedExpiresChecksVerified
Driver's licenseTX•••• 51922/24/20201/12/2033GenuineLiveIssuer8/13/2026
Linked User Accounts (1)
User accounts linked to this identity.
Activity
Recent changes to this identity and its user accounts.
•
Linked seeded-user9934@dispel.test 11 minutes ago
via identity verification
Identity ProofingGovernment ID validation, liveness check, and biometric match confirm a real, verified person, meeting NIST IAL2.
Policy-Driven VerificationFires the moment session risk crosses a threshold, not on a schedule. A risky session triggers an identity check in real time.
Identity BlockOne identity maps to every account a person holds, shared, service, or personal. Revoke all sessions, access closes everywhere at once.
Acme Corp
/Settings/Identity/Aiden Spiering
‹Identities/Aiden Spiering
AS

Aiden Spiering Verified

Identity assurance
What the identity provider verified.
Proven identityVerified
Assurance levelIAL2
DocumentIssuing authorityNumberIssuedExpiresChecksVerified
Driver's licenseTX•••• 51922/24/20201/12/2033GenuineLiveIssuer8/13/2026
Linked User Accounts (1)
User accounts linked to this identity.
Activity
Recent changes to this identity and its user accounts.
•
Linked seeded-user9934@dispel.test 11 minutes ago
via identity verification
Identity ProofingGovernment ID validation, liveness check, and biometric match confirm a real, verified person, meeting NIST IAL2.
Policy-Driven VerificationFires the moment session risk crosses a threshold, not on a schedule. A risky session triggers an identity check in real time.
Identity BlockOne identity maps to every account a person holds, shared, service, or personal. Revoke all sessions, access closes everywhere at once.
Acme Corp
/Settings/Identity/Aiden Spiering
‹Identities/Aiden Spiering
AS

Aiden Spiering Verified

Identity assurance
What the identity provider verified.
Proven identityVerified
Assurance levelIAL2
DocumentIssuing authorityNumberIssuedExpiresChecksVerified
Driver's licenseTX•••• 51922/24/20201/12/2033GenuineLiveIssuer8/13/2026
Linked User Accounts (1)
User accounts linked to this identity.
Activity
Recent changes to this identity and its user accounts.
•
Linked seeded-user9934@dispel.test 11 minutes ago
via identity verification
Identity ProofingGovernment ID validation, liveness check, and biometric match confirm a real, verified person, meeting NIST IAL2.
Policy-Driven VerificationFires the moment session risk crosses a threshold, not on a schedule. A risky session triggers an identity check in real time.
Identity BlockOne identity maps to every account a person holds, shared, service, or personal. Revoke all sessions, access closes everywhere at once.

A Valid Login Isn't the Right Person

The same certainty you'd have checking an ID at the gate, now built into remote sessions protecting your crown jewel assets.

A Valid Login Isn't the Right Person

The same certainty you'd have checking an ID at the gate, now built into remote sessions protecting your crown jewel assets.

A Valid Login Isn't the Right Person

The same certainty you'd have checking an ID at the gate, now built into remote sessions protecting your crown jewel assets.

The Challenge

A Phone Call Can Defeat Every Technical Control You Have

Once handed over, authentication has nothing left to check.

In July 2026, ShinyHunters breached Abbott Laboratories' Exact Sciences, not with an exploit, but a phone call. A vished employee handed over a valid SSO login, and every downstream system trusted the session.

Dispel's Solution

A Different Question: Are You the Verified Human?

A stolen password and a phished MFA code get an attacker nothing here.

Identity Proofing doesn't ask "do you hold the credential," it asks "are you the verified human this account belongs to." Government ID and biometric verification confirm the person.

The Challenge

We Verify Identity at the Gate, Not on the Wire

You prove who you are at the gate. Not on the wire.

NERC CIP already requires in-person identity verification for physical access to a critical asset. The remote session reaching that same asset carries no equivalent check, especially with contractor credentials that rotate within a firm or shift.

Dispel's Solution

The Same Standard, Extended to Remote Access

Any hour, any location, tied to one verified identity record.

Dispel Identity extends in-person-grade verification to remote sessions, confirming a real, verified person is behind every third-party connection, whether they're at the gate or a thousand miles away.

Verification, Built Into Every Remote Access Decision

Verification fires only when the risk warrants it, by user type, asset risk score, behavioral threshold, or geography.

Verification, Built Into Every Remote Access Decision

Verification fires only when the risk warrants it, by user type, asset risk score, behavioral threshold, or geography.

Verification, Built Into Every Remote Access Decision

Verification fires only when the risk warrants it, by user type, asset risk score, behavioral threshold, or geography.

What Identity Verification Actually Delivers

54,000,000

People worldwide protected by utilities running Dispel

<60 sec

ID check through biometric match, end to end

195

Countries with supported identity documents for verification

3

Stage IAL2 verification

What Identity Verification Actually Delivers

54,000,000

People worldwide protected by utilities running Dispel

<60 sec

ID check through biometric match, end to end

195

Countries with supported identity documents for verification

3

Stage IAL2 verification

Confirmed by Teams in the Field

“Before we chose Dispel we reviewed other Remote Access solutions, none of them gave us that level of security and smooth experience.”
Senior Security Engineer
IT Services

Frequently Asked Questions

Frequently Asked Questions

Frequently Asked Questions

Not on most platforms, authentication confirms a credential, not a person. Dispel Identity adds that missing layer directly into the remote access session itself, rather than requiring a separate identity tool bolted on afterward.

MFA stops attacks that rely on a stolen password alone. It doesn't stop an attacker who gets a real employee to approve the login in real time, exactly what vishing campaigns like ShinyHunters' do. Once the credential and the MFA prompt are both handed over, authentication has nothing left to check. Identity proofing adds the missing step: confirming the actual person.

AAL (Authenticator Assurance Level) measures how strongly a credential was authenticated. IAL (Identity Assurance Level) measures how strongly you've proven who the person actually is. Most access tools handle AAL and stop there; Dispel Identity adds IAL2 through government ID validation and a biometric match.

NERC CIP already requires in-person identity verification for physical access to critical assets, but not for the remote sessions that reach those same assets. Dispel Identity extends the same standard to remote access, and because verification is policy-driven, you can require it specifically on high-impact BES Cyber assets without slowing routine work.

No. Verification triggers only where you define it: by user type, asset risk, a behavioral threshold, or geography. Low-risk, routine sessions aren't interrupted to catch the rare high-risk one.

Biometric data is processed through an accredited third-party provider and stored in a non-reversible, non-reconstructable format, never as a raw image. Processing stays within US or EU-based infrastructure, with GDPR data minimization and BIPA-compliant consent and retention, so verification doesn't create a new biometric data liability for your organization to manage.

Verify the Person. Not Just the Password.

See IAL2 identity proofing running inside a real remote access session — book 30 minutes with an OT security specialist.

Verify the Person. Not Just the Password.

See IAL2 identity proofing running inside a real remote access session — book 30 minutes with an OT security specialist.