- TruU sells enterprise identity security: passwordless access, identity verification, behavioral risk detection, and automated response.
- Its best-known public deployment put more than 10,000 Stanley Black & Decker employees on passwordless login by 2021.
- The company has raised about $37.7 million and now extends its models to insiders, service accounts, and AI agents.
- The useful idea to borrow: treat authentication as a stream of evidence, not a ceremony performed once at the door.
The password failed in the most ordinary way possible. It became so complicated that a person reached for a sticky note. Rhonda Gass, then chief information officer at Stanley Black & Decker, described the trap neatly: the company did not want passwords so complex that employees wrote them down and carried them around. The security measure had turned into office stationery.
TruU’s first answer was to make the secret string disappear. A worker’s phone, biometrics, proximity, device condition, and surrounding environment could supply better evidence. In 2021, Stanley Black & Decker said more than 10,000 employees were using TruU’s system, with plans to double enrollment. PCs came first; Macs, virtual desktops, single sign-on applications, and physical access were meant to follow. For a young security company founded in 2017, this was the valuable kind of proof: not a clever booth demo, but thousands of people arriving for work.
“We didn’t want the password to be so complex that people were writing them down on sticky notes and carrying them around.”Rhonda Gass, then CIO of Stanley Black & Decker
The front door was only the beginning
A login is a photograph. Enterprise life is a film. The person who signs in at 9:03 may open payroll at 9:12, enter a factory system at 9:40, move onto a café network at lunch, and ask the help desk for a reset at 3:00. Traditional authentication makes a firm decision at one frame and then hopes the plot behaves.
TruU built around the opposite idea, which it called continuous adaptive trust. Its cloud took signals from a phone, computer, network, proximity, and behavior, then adjusted the confidence attached to an identity. The early products had clean names - FluidID for presence and passwordless access, RiskID for evaluating events, ConnectID for authentication. The current portfolio folds that logic into TOTAL: Protect handles access and verification, Predict evaluates risk, and Enforce responds.
The distinction matters because TruU is not merely another way to tap a phone instead of typing a password. Microsoft, Okta, Duo, HYPR, Beyond Identity, and others can all occupy some part of that territory. TruU’s pitch is convergence: the same system can bind a person to a device, open a workstation, support shared machines, feed physical access, watch what happens after login, and push the resulting signals into a risk model.
A Persona for the machine in the corner
Then the cast changed. Enterprises filled with service accounts, API keys, workload identities, bots, and autonomous agents. These actors do not have faces or fingerprints. They do have habits. An invoice bot calls a familiar set of services. A deployment account touches a predictable cluster of systems. An AI agent has a mandate, tools, and a human steward. When one reaches beyond its normal scope, the movement can look less like a login failure and more like a personality change.
This is the idea behind TruU’s Persona. The company describes it as a generative model of how an identity actually behaves, rather than a job title or directory group. Personas are clustered with behavioral peers and watched for drift. TruU says its reasoning layer tests predicted intent against the identity’s baseline and its cluster, using a courtroom metaphor of evidence and verdict. The applications now include insider threat, account takeover, non-human identity discovery, rogue-agent detection, identity verification, and passwordless access.
Replace passwords and badges with verified presence, devices, and biometrics.
Turn login signals into continuous identity and adaptive risk.
Apply behavioral Personas to people, service accounts, and AI agents.
Seen this way, TruU did not abandon passwordless. It discovered that passwordless generated useful raw material. Every enrollment, device check, access request, location change, biometric interaction, and failed attempt became identity telemetry. The product widened because the data widened. The nuisance of login had led to the harder business of deciding whether an actor still looked like itself.
What $37.7 million bought
Public funding records describe four events: $525,000 in 2017, $2.3 million in 2019, $11.85 million in 2020, and $23 million in 2022. The reported total is roughly $37.7 million. Early backers included CXO Fund, The Hive, and Stanley Ventures. Customer license prices are not published; this is enterprise software sold through demos, integrations, and channel relationships, not a $12-a-month checkout button.
That money funded the unglamorous breadth enterprise identity requires. TruU lists support across Windows, macOS, Linux, iOS, Android, VDI, VPNs, shared workstations, servers, cloud applications, and legacy systems. It has advertised integrations with familiar identity, privileged-access, virtualization, security-key, and physical-access vendors. A Prague engineering hub, opened in 2021, sought data scientists and engineers across AWS, Java, mobile, desktop, QA, reliability, and operations. The product may talk about Personas; somebody still has to make the Mac client behave after a cold boot.
The company also accumulated institutional markers: Citrix Ready validation, a 2021 Global InfoSec award for passwordless authentication, a U.S. patent granted in 2024, and a Telarus distribution agreement aimed at the mid-market. The business model is familiar enterprise SaaS, helped by partners that already sit between security vendors and corporate buyers.
The first thing to fail was the rule
Passwords failed visibly. Static rules fail quietly. A rule can say that a finance employee should not download a thousand files at midnight. It struggles with the employee who downloads 150 files every afternoon, then begins adding ten more each day. It struggles even more with an agent that was legitimately given broad access and slowly drifts away from its intended role.
TruU’s answer is context: compare the event with the actor and with similar actors. This is also the part buyers should test hardest. A Persona is only as useful as the signals feeding it, the explanations it produces, and the cost of its mistakes. An organization with thin telemetry, inconsistent identity ownership, few integrations, or no appetite for continuous behavioral analysis will not get the same result. Biometric use adds consent and regulatory obligations. Automated enforcement should begin with reversible, low-consequence actions before anyone lets a model suspend an executive or stop a production agent.
Start with one costly access journey. Bind the person to a trusted device. Collect signals without blocking. Establish a baseline. Measure false alarms. Add gentle interventions. Automate hard enforcement last.
That sequence is the practical lesson inside TruU’s more ambitious claims. Do not begin by promising to predict intent across the company. Begin with a password reset, a shared workstation, a help-desk call, or a sensitive application where friction and risk are both visible. Let the system observe before it judges. Preserve an alternate path for people who cannot or will not use biometrics. Decide which errors are merely annoying and which could stop the business.
TruU’s story is amusing because its villain kept growing. First it was the password. Then it was the stolen session. Then the disgruntled insider. Now it is the service account nobody remembers and the AI agent that behaves perfectly until it does not. The common thread is not a particular credential. It is the gap between an identity’s label and its conduct.
A directory can tell you what something is called. TruU wants to tell you what it is becoming. Whether that prediction proves reliable across messy enterprises is the question on which the new company story rests. But the observation underneath it is hard to shake: the moment the password disappears, identity does not become simpler. It finally becomes visible.