Assume the trusted app is already compromised. Prove and cut what it left behind.

We prove leftover access is actually dead.

Leftover trust. Cut it. Keep the receipt.

After the breach and the rotation, we cut leftover access and prove it bounced. A kill receipt is VALID only if replaying the old session, grant, or token fails — never because a vendor said revoked:true.

Lab leftovers. Signed sample receipts. Live connectors stay locked. Sample walkthrough — not your tenant.

Sample walkthroughLab fixtures · not your tenant

Replay failed. Then we stamp it.

Illustration / synthetic · lc_gt_01 · Google OAuth

Access cut — replay bounced

Illustration / synthetic leftover — not a live cut. Static card; mint a server-signed sample on /demo.

Stamp
CUT / BOUNCE
Identity
security-eng@enterprise.example
Vendor flag
revoked=true (not trusted)
Replay (liveness)
Illustration / synthetic — Replay bounce — this is the liveness proof (old grant rejected)
Hash / signature
Illustration / synthetic — not a cryptographic proof on this static card
VALID

Illustration / synthetic · lc_ms_02 · Entra session

Still live — vendor was green

Illustration / synthetic leftover — vendor-green lie (IdP said revoked; probe still live). Static card; not a cryptographic proof.

Stamp
WITHHELD
Identity
admin@example.org
Vendor flag
revoked=true (not trusted)
Replay (liveness)
Illustration / synthetic — Still live — liveness proof that leftover access was not killed
Hash / signature
Illustration / synthetic — not a cryptographic proof on this static card
WITHHELD

Not connect, revoke, verify.

Inventory leftover trust. Cut out-of-band. Replay the old grant. A kill receipt is VALID only on bounce. WITHHELD if still live.

  1. Inventory leftover trust

    Sessions, OAuth grants, refresh tokens, API keys, and machine leftovers that stay alive after rotation or a vendor incident.

  2. Out-of-band cut

    Revoke from a plane that is not the possibly stolen session. Do not trust the compromised vendor to be the only cutter.

  3. Adversarial replay / bounce

    Present the old grant again from an isolated probe. Bounce means the credential failed. Still live means it worked.

  4. Kill receipt VALID only on bounce

    VALID if replay bounced. WITHHELD if still live -- even when the vendor said revoked:true. Not connect, revoke, verify.

Click once -- see VALID vs WITHHELD / Verify a receipt / Security / Why IdP revocation is not enough

Server-signed kill receiptsEd25519 or HMAC-SHA256. Private key never ships to the browser.Public /verifyIntegrity of receipt bytes. Not vendor liveness unless a replay was recorded.Independent replayVALID only if the old grant bounces. We do not trust revoked=true.

Not SOC 2, ISO, or FedRAMP certified. CAEP ingest is inspired, not a certificate. Limitations. Founder Ugochukwu Eneh.

Demo, design partner, or pilot. Not a mailbox bounce.

Send this form so we can reply about Residual Trust Assurance. We use only the details you provide here. Email to the founder is notify-only if a mailer key is configured. We do not sell a mailing list.

Beachhead

Live-first GitHub org NHI: inventory SSO + PATs, cut, absence re-list, VALID or WITHHELD, export evidence. Demo rows stay separate for practice.

Cut + probe

Protection is the cut. Checking is an independent failed-replay or absence probe — not HMAC, not the vendor revoke API. Transport failure is probeError — never a fake WITHHELD.

Kill receipt

After an incident the question is not did we click revoke — it is can the old grant still get in. The kill receipt is IR evidence the cut held: VALID only on bounce. Audit, compliance, and cyber insurance reuse the same Evidence Pack. One stamp. Not a green dashboard.

Entra, Okta, AWS, and GitHub already revoke.

Necessary. Not proof. Their APIs can report revoked:true while the old grant still works. LingerCut is independent of the compromised vendor: we adversarially replay, and VALID only if it bounces.

Entra and Okta cannot be the only verifier of leftover Entra or Okta trust. AWS deactivate is not an independent bounce. A green GitHub console is not absence of the old PAT. Why identity providers cannot prove residual access is gone.

Founder

Ugochukwu Eneh

Builds LingerCut so leftover sessions, OAuth grants, and API keys do not survive a rotation or a vendor incident.

hello@lingercut.comLive mailbox