Zero Trust Workload Connectivity

The only identity-first Zero Trust fabric for every AI, API, and machine interaction.

Security You Can Prove. Governance You Can Show. Operations That Scale With Ease.

Built on OpenZiti, the world’s most widely deployed open source Zero Trust networking platform.

In production at

The Challenge

Connecting by IP Address Costs You More

Every new workload with an IP address and open port is reachable, adding security, governance, and operational burdens.

Five Problems, Each Landing on a Different Team

  • Reachable, Breachable, Traversable. Attackers scan, breach what they find, and move laterally. AI drives all three faster than teams can patch.
  • The Connectivity Tax. Every new service, model, API, or connection triggers another round of firewall, NAT, routing, DNS, and exception work, slowing deployments and the business.
  • Heterogeneous Networks. Distributed data centers, clouds, plant floors, edge devices, and partner networks each bring a patchwork of fragmented IP addressing, controls, tooling, policies, and views.
  • North-South or East-West, Never Both. Attackers leverage the disconnect between SASE governing traffic crossing the perimeter and microsegmentation governing traffic inside it.
  • Fragmented, Costly, and Rapidly Obsoleted. Firewalls, VPNs, SASE, API gateways, and other standalone tools raise costs and complexity, require costly hardware refreshes or upgrades, and can lag behind new needs such as PQC.
Six environments - a data center, two clouds, a plant floor, edge devices, and a partner network - joined by 17 connections across three different methods: site-to-site tunnels, remote access, and API calls. Each crossing passes through its own firewall or gateway, 14 in total, and two pairs of environments use overlapping address ranges, so no single policy or view spans the estate.
The NetFoundry Solution

One Identity-First Fabric for Every Workload

Every workload has an identity and dials out, leaving no inbound ports to attack. Identity-based policy governs every connection, only opening the end-to-end encrypted path after mutual authentication.

Workload A Cryptographic identity No inbound ports Workload B Cryptographic identity No inbound ports Private Fabric Identity-Based Policy Identity verified IP address ignored Outbound dial IP 10.10.4.12 Outbound dial IP 10.20.7.33
AI Security

Govern All AI Access Across Heterogenous Environments

Current Problem: AI moves faster than firewall rules and ticket queues.

  • Connect and govern by identity — no firewall rules, no open ports, no shared secrets
  • One policy governs agent traffic north-south and east-west
  • New agents connect in minutes, with no firewall ticket
  • Token tracking for cost accounting, optimization, and limits
Explore AI Security →
Microsegmentation

Stop Lateral Movement In Days, Not Months

Current Problem: IP-based segmentation hasn’t worked or scaled.

  • Identity-driven policy creates least-privilege paths between authorized workloads
  • One policy framework for all connections in distributed, heterogeneous environments
  • Incremental deployment, no hardware or forklift upgrades
  • Future-proof segmentation with software-defined policy and cryptographic agility
Explore Microsegmentation →
Site-to-Site Connectivity

Easily Connect Everything, Expose Nothing

Current Problem: Every site-to-site VPN tunnel adds inbound attack surface.

  • Sites, clouds, OT, and partner networks connect outbound-only, each reaching only what policy allows
  • Identity governs the connection, making overlapping IP address ranges irrelevant
  • New sites join by policy, without tunnels or routing changes
Explore Site-to-Site Connectivity →
OT & IoT Security

Securely Connect & Segment OT Without Uptime Risk

Current Problem: The riskiest assets are the ones you can’t patch or touch.

  • No inbound ports on plant networks, no agent on legacy controllers
  • Deploys on the existing network with no redesign and no downtime
  • One platform for vendor access, site connectivity, and workload segmentation
Explore OT & IoT Security →
Solution Providers

Zero Trust Connectivity With Faster Setup & Less Effort

Current Problem: Every deployment waits on someone else’s firewall or VPN.

  • Integrate Zero Trust as a native feature of your solution, with nothing for the customer’s or partner’s team to configure
  • Reach into others’ environments outbound-only — no inbound ports, no VPNs, no firewall rules
  • Accelerate sales and time-to-revenue, because there is nothing for network and security teams to approve
Explore Solution Providers →
API Security

Make APIs Invisible Until Access Is Authorized

Current Problem: Every API you publish is an API attackers can reach.

  • APIs stay invisible until authentication and authorization complete
  • The same identity model in the data center, any cloud, and at the edge
  • One policy model removes per-API firewall rules, tunnels, and allowlists
Explore API Security →
How it works

Every Connection Starts With Identity

NetFoundry reverses the traditional order — for every connection, human or machine.

Four-step sequence. One: two endpoints sit apart with no network path between them while one presents its cryptographic identity. Two: policy decides whether that identity may reach this specific service, and still no path exists. Three: once authorized, an end-to-end encrypted session opens, outbound-only from both sides. Four: to everyone else there are no open ports and nothing to scan.

Want the architecture in depth — the fabric, identities, SDKs, and the control plane?
Explore the platform →

Your Users Have Zero Trust.Your Machines Are Still on the Honor System.

SASE and ZTNA cover your people.

Your sites, workloads, APIs, OT systems, and AI agents still connect through open ports and implicit trust.

In production

Trusted Where Failure Isn’t an Option

The organizations that can least afford downtime also can’t afford delay — and NetFoundry gives them both: production-grade security and connectivity that clears review instead of stalling in it.

3,000companies use NetFoundry
2 of 5largest US companies connect with NetFoundry
8 of 10largest US banks connect with NetFoundry
1B+sessions/month across global infrastructure
#1most widely deployed open source Zero Trust networking platform
“Our customers don’t even need to open a single inbound firewall port for us to remotely manage our software deployed on their networks. InfoSec reviews that historically took weeks became single-meeting events.”
John Wilson, CEO, TZ Limited
“NetFoundry provides the secure network foundation Rhapsody needs to support private, policy-based access across distributed healthcare environments, including applications, APIs, workloads, and emerging AI-enabled workflows.”
Kevin Day, CTO, Rhapsody
“We moved beyond the perimeter with NetFoundry. It delivers a strictly least-privileged access model that is incredibly easy to deploy, turning what used to be a tangle of firewall rules into a streamlined, visual command center.”
Viktor Szabó, Deputy CTO, Ominimo
Built in the Open

The Platform Runs on OpenZiti, and We Built It

NetFoundry created and maintains OpenZiti, the most widely deployed open source Zero Trust networking platform. The code carrying your traffic is auditable by anyone — no hidden behavior, no lock-in, no vendor you cannot verify. Run it yourself, or run it as a managed service with a global fabric and 24×7 Enterprise support behind it.

Explore NetFoundry OpenZiti →

Every Connection Governed.Nothing Visible to Attackers.

Deploy on the network you already have, with no redesign and no firewall tickets.