Assume the trusted app is already compromised. Prove and cut what it left behind.
We prove leftover access is actually dead.
Leftover trust. Cut it. Keep the receipt.
After the breach and the rotation, we cut leftover access and prove it bounced. A kill receipt is VALID only if replaying the old session, grant, or token fails — never because a vendor said revoked:true.
Not SOC 2, ISO, or FedRAMP certified. CAEP ingest is inspired, not a certificate. Limitations. Founder Ugochukwu Eneh.
Interest — LingerCut owns the list
Demo, design partner, or pilot. Not a mailbox bounce.
Send this form so we can reply about Residual Trust Assurance. We use only the details you provide here. Email to the founder is notify-only if a mailer key is configured. We do not sell a mailing list.
Beachhead
Live-first GitHub org NHI: inventory SSO + PATs, cut, absence re-list, VALID or WITHHELD, export evidence. Demo rows stay separate for practice.
Cut + probe
Protection is the cut. Checking is an independent failed-replay or absence probe — not HMAC, not the vendor revoke API. Transport failure is probeError — never a fake WITHHELD.
Kill receipt
After an incident the question is not did we click revoke — it is can the old grant still get in. The kill receipt is IR evidence the cut held: VALID only on bounce. Audit, compliance, and cyber insurance reuse the same Evidence Pack. One stamp. Not a green dashboard.
They revoke. We prove bounce.
Entra, Okta, AWS, and GitHub already revoke.
Necessary. Not proof. Their APIs can report revoked:true while the old grant still works. LingerCut is independent of the compromised vendor: we adversarially replay, and VALID only if it bounces.