Glossary

The vocabulary of session security.

Every term MindVault uses, defined once. The same sentence appears here, in the article that introduces the term, in that article's structured data, and in the file we hand to AI assistants.

Terms
23 terms
Updated
Updated

The market blends these words freely. This page does not. Each entry is the one definition MindVault uses, followed by the article that introduces it at length. Terms are grouped by what they describe: the category itself, what goes wrong after login, the evidence MindVault works from, and what happens when confidence drops.

The category

The words MindVault uses for the problem it works on and the measure it produces.

Human Confidence Signal

The live output of Continuous Identity Confidence: a High, Medium, Low, or Insufficient confidence level for the person operating a session, measured throughout the session. It is delivered to the SIEM, SOAR, or service the organization chooses, and the organization's own policy decides what happens next.

Explained on the Technology page

Identity Uncertainty

The condition in which a session remains technically authorized while the organization holds no direct evidence about who is operating it, allowing unauthorized activity to continue under legitimate access until something else notices.

Introduced in The Cost of Identity Uncertainty: What Happens After MFA

Post-Login Gap

Also called Post-Authentication Gap

The span between a successful login and the end of a session, where most security checks stop asking who is operating. A valid session no longer guarantees that a trusted operator is in control.

Introduced in The Security Gap After Authentication

Post-Login Security

The protection of an account after authentication succeeds, continuously verifying that the person operating a session is still the enrolled user and responding when confidence drops.

Introduced in Authentication Ends. Trust Shouldn't.

What goes wrong after login

The attacks and tradeoffs that happen inside a session that every credential check has already approved.

Adversary-in-the-Middle (AiTM) Phishing

A phishing technique that proxies a genuine login page so the victim authenticates for real, completes MFA, and unknowingly hands the attacker a valid session token. Every credential check passes because every credential was real.

Introduced in Session Hijacking in 2026: The Attack That Bypasses MFA

Agentic Threat Actor

An attacker whose operation is carried out by an AI agent rather than a human-driven toolkit.

Introduced in AI Agents Need Identity Too

Prompt Injection

A structural weakness of language model agents in which untrusted input is interpreted as instructions, letting an attacker redirect the agent's behavior.

Introduced in AI Agents and the New Attack Surface

Session Handoff

The moment a different person or process takes over a session that is already signed in.

Explained on the Technology page

Token Duration Tradeoff

The security versus productivity tension between short session tokens that log users out often and long tokens that widen the window for session theft.

Introduced in The Token Duration Tradeoff

Evidence and architecture

How MindVault gathers what it needs, and what it refuses to collect.

Behavioral Signal

A security signal derived from how a person interacts (timing, rhythm, and movement), used to judge operator continuity rather than environmental metadata alone.

Introduced in From Alert Fatigue to Behavioral Signal

Continuous Authentication

Repeatedly reevaluating identity evidence while a session runs, rather than once at login. Industry usage often means periodic re-checks of identity factors; MindVault uses Operator Continuity for the outcome being protected and Continuous Identity Confidence for the framework that measures it.

Introduced in Continuous Authentication vs. Session Monitoring vs. Continuous Identity Confidence

Evidence Classes

The independent categories of continuity evidence: behavioral, the human pattern at the controls; provenance, where inputs and tokens actually come from; device, endpoint state and processes; identity, account and policy state; and context, network, time, and location.

Introduced in When a Valid Session Changes Hands: The Evidence Behind Each Takeover

Session Monitoring

The ongoing evaluation of an authenticated session's characteristics, such as usage patterns, timing, behavioral traits and device or network signals, as described in NIST SP 800-63B-4. NIST notes it is sometimes called continuous authentication; MindVault treats it as the capability that gathers the evidence for Operator Continuity.

Introduced in NIST SP 800-63B-4 and the Future of Session Monitoring

Response and deployment

What happens when confidence drops, and where protection starts.

Evaluation by Evidence

Judging session monitoring technology by the evidence it evaluates, the question that evidence answers, and its behavior when confidence is wrong, rather than by labels like continuous, AI-powered, or behavioral.

Introduced in 12 Questions to Ask Before Evaluating Session Monitoring

Missing a term you expected? The Resources FAQ answers the questions security teams ask first, and the comparison page sets these terms beside the controls you already run.