Assume the trusted app is already compromised. Prove and cut what it left behind.

Leftover trust. Cut it. Keep the receipt.

After the breach and the rotation, we cut leftover access and prove it bounced. Password managers store secrets. Identity providers prove login. LingerCut finds the sessions, OAuth grants, and API tokens that stay alive — then revokes them and issues a kill receipt.

Beachhead

Live-first GitHub org NHI: inventory SSO + PATs, cut, absence re-list, VALID or WITHHELD, export evidence. Demo rows stay separate for practice.

Cut + probe

Out-of-band revoke. Then independent failed-replay or absence probe. Transport failure is probeError — never a fake WITHHELD.

Kill receipt

Stamp CUT only if replay bounces. Customer-held Evidence Pack ZIP for IR lockers — that artifact is the product.