01 · About the customer
About Touchstone Life Care
Touchstone Life Care is an advance care planning platform that helps people securely create, store and share important care documents with the people and professionals who may need them.
Because those records are both personal and sensitive, protecting access cannot stop at a successful login. Touchstone needed to preserve a simple user experience while strengthening the evidence available to its security team after authentication.
02 · The challenge
Security controls stopped at the exact point risk became harder to see
Touchstone Life Care already protected its perimeter with a WAF and MFA. Those controls confirmed access at login, but they could not continuously answer whether the person driving the session was still the legitimate account owner.
For a platform that securely stores and shares sensitive advance care documents, waiting for a user to report an account takeover was not an acceptable detection strategy. The team needed stronger evidence after login without rebuilding controls that already worked.
“Our concern wasn’t whether we needed more visibility—we knew we did. It was whether getting it meant rebuilding the WAF and MFA setup we already had. CrossClassify was running alongside our existing stack in under 48 hours, and within the first month it surfaced 37 suspicious sessions we wanted our team to investigate.”
Before CrossClassify
With CrossClassify
03 · The solution
A risk layer that worked with the stack—not around it
CrossClassify added behavioral biometrics, device intelligence and continuous session scoring as a complementary layer. The existing WAF and MFA stayed in place; users saw no new hurdle and the security team gained a live view of post-login behavior.
Instead of turning every anomaly into noise, CrossClassify attached explainable signals to the sessions that merited investigation, giving the team an evidence-backed review queue.
How it works
One continuous loop replaced the one-time trust decision.
04 · The results
37 previously invisible sessions became actionable
In the first month, CrossClassify surfaced 37 suspicious sessions for investigation—activity that perimeter controls alone had not made visible.
Touchstone gained a practical post-login detection layer in under 48 hours, without forcing users through another challenge or asking the team to replace its WAF or MFA.

