"Suspicious sign-in." From where, and how risky?
Most identity tools flag "impossible travel" and call it a day. Dralvia's Identity Risk Console, in preview, scores sign-in events using the same engines you trust for URLs and domains, the infrastructure a sign-in came from, OAuth grant reputation, and behavioural signal, so an alert comes with evidence, not just a label.
Identity security
See Dralvia in action.
Review sign-in risk and contributing context, then revoke or escalate with an audit trail.
- Ingest supported identity events
- Review risk and contributing context
- Revoke or escalate with audit history
This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

Identity risk with the same evidence model.
A sign-in is more than a location. Dralvia scores the infrastructure and grants behind it.
Sign-in infrastructure
The IP, ASN, and hosting reputation a sign-in came from, scored with the same domain and infrastructure engines as the scanners.
OAuth grant reputation
Risky third-party app grants and consent-phishing patterns surfaced before they become persistent access.
Behavioural signal
Deviation from a user's normal pattern, combined with infrastructure risk rather than read in isolation.
Evidence per event
Each scored sign-in carries the signals behind its verdict, exportable as an EvidencePack.
Honest answers.
It is in preview. The Identity Risk Console scores sign-in events today; coverage and integrations are being shaped with design partners before general availability.
Turn "suspicious sign-in" into evidence.
Join the design-partner program and help shape identity risk scoring built on the engines you already trust.