Secure Workload Connectivity

Zero Trust for Machines

The only identity-first Zero Trust fabric for every AI, API, and machine interaction.

Stop managing your attack surface. Eliminate it.

netfoundry infographic zero trust for machine workloads
The Challenge

Five Attack Surfaces, One Root Cause

Attackers are now using AI to find and weaponize exposed surfaces faster than any team can patch, tune, or review. The same underlying flaw surfaces as five separate problems, each one a different team’s fire to fight:

  • Attackers discover and hijack AI agents, LLMs, and MCP servers the moment they’re exposed
  • Automated bots scan and exploit public APIs faster than teams can patch them
  • A single breach rides site-to-site VPN tunnels to every network they connect
  • One compromised host moves laterally across a flat network to reach everything else
  • Remote access into OT and IoT hands attackers a path to systems no one can take offline to patch
Exploitation of reachable services is the leading initial breach vector at 31 percent, ahead of phishing at 16 percent and stolen credentials at 13 percent, per the Verizon 2026 DBIR.

Different symptoms, one root cause: legacy networking. It creates reachability — and reachability is what becomes breachability and then traversability, a workload an attacker can find, breach, and move through. Eliminate the reachability and the rest of the chain never starts.

The NetFoundry Solution

One Fabric for Every Workload

NetFoundry removes the root the five share: reachability. One identity-first overlay authenticates and authorizes every connection before any network path exists — unauthorized actors reach nothing. The same model that closes the attack surface opens the business: connect any site, workload, partner, or AI agent by policy alone, with no firewall tickets or re-architecture. Five solutions, one policy model — start with the problem in front of you and expand at your own pace.

Building a product? Stop building connectivity and start shipping it. Embed outbound-only Zero Trust connectivity in your software or devices with NetFoundry SDKs, white-labeled and live in a sprint.

For Product Builders →
How it works

Authenticate First. Connect Second. Always.

NetFoundry reverses the traditional order — for every connection, human or machine.

1 Every endpoint authenticates with its cryptographic identity — before any connection attempt
2 Policy decides whether this identity may reach this specific service
3 If authorized, a private, end-to-end encrypted session is created — outbound-only on both sides
4 Everyone else sees nothing: no open ports, nothing to scan, nothing to exploit

Want the architecture in depth — the fabric, identities, SDKs, and the control plane?
Explore the platform →

Where existing tools stop

Your Users Have Zero Trust. Your Machines Are Still on the Honor System.

SASE and ZTNA connect your people to applications. Your sites, workloads, APIs, OT systems, and AI agents still have to reach each other some other way.

The legacy approach

  • VPNs, MPLS, and SD-WAN move packets between networks, then trust whatever arrives inside
  • Every machine connection needs an inbound firewall rule and a reachable address — each one more attack surface
  • Access decisions ride on IP addresses that change constantly and identify nothing
  • A foothold anywhere becomes lateral movement everywhere

The NetFoundry approach

  • Identity and policy decide every connection before any network path exists
  • Outbound-only from every endpoint — your firewalls enforce one deny-all inbound rule
  • Visibility and audit by identity, for humans, workloads, devices, and AI agents alike
  • A breach in one place reaches nothing else, because nothing else is reachable
In production

Trusted Where Failure Isn’t an Option

The organizations that can least afford downtime also can’t afford delay — and NetFoundry gives them both: production-grade security and connectivity that clears review instead of stalling in it.

3,000companies use NetFoundry
2 of 5largest US companies connect with NetFoundry
8 of 10largest US banks connect with NetFoundry
1B+sessions/month across global infrastructure
“Our customers don’t even need to open a single inbound firewall port for us to remotely manage our software deployed on their networks. InfoSec reviews that historically took weeks became single-meeting events.”
John Wilson, CEO, TZ Limited
“NetFoundry provides the secure network foundation Rhapsody needs to support private, policy-based access across distributed healthcare environments, including applications, APIs, workloads, and emerging AI-enabled workflows.”
Kevin Day, CTO, Rhapsody
“We moved beyond the perimeter with NetFoundry. It delivers a strictly least-privileged access model that is incredibly easy to deploy, turning what used to be a tangle of firewall rules into a streamlined, visual command center.”
Viktor Szabó, Deputy CTO, Ominimo
Built in the open

Built on OpenZiti — the open source project NetFoundry created and maintains.

The code that carries your traffic is auditable by anyone: no hidden behavior, no lock-in, and a managed control plane, global fabric, and enterprise support so you never maintain it alone.

Explore OpenZiti
FAQ

Identity-First Reachability, Answered

What is Identity-First Reachability?

NetFoundry’s Identity-First Reachability™ is a Zero Trust connectivity model in which no routable network path exists until a connection’s cryptographic identity is authenticated and authorized by policy. Services connect outbound-only, open no inbound ports, and stay invisible to every unauthorized actor, which removes the reachable attack surface that attackers scan and exploit. NetFoundry applies this model to AI agents, APIs, site-to-site connectivity, workload microsegmentation, and OT and IoT environments through one identity-first overlay.

How is NetFoundry different from SASE and ZTNA?

NetFoundry secures the connections that SASE and ZTNA leave out: site-to-site, workload-to-workload, API, OT, and AI traffic. SASE and ZTNA connect people to applications by routing traffic through a vendor’s cloud, while NetFoundry provides a private overlay that makes machine workloads unreachable by default and authenticates identity before any network path exists. NetFoundry deploys as SaaS, self-hosted, or fully air-gapped, and your data path never depends on a third party’s inspection points.

Can NetFoundry secure AI agents, MCP servers, and LLMs?

Yes. NetFoundry deploys Zero Trust AI Enclaves in which every AI agent, MCP server, and LLM endpoint receives its own cryptographic identity and connects outbound-only, with no shared API keys and no open inbound ports. Policy governs which identities reach which services, and identity-based visibility extends to AI token tracking for cost accounting, optimization, and limit setting. The result is AI governance that operates at the same speed as the AI itself.

Does NetFoundry require opening inbound firewall ports?

No. NetFoundry connections are outbound-only from every endpoint, which means you open no inbound firewall ports, publish no public IP addresses, and run no listening services for attackers to find. Authentication and authorization complete before any routable path is created, and your firewalls can enforce a single deny-all inbound policy. This applies across all NetFoundry use cases, from AI and API security to site-to-site, microsegmentation, and OT connectivity.

What is the relationship between NetFoundry and OpenZiti?

NetFoundry created and maintains OpenZiti, the world’s most widely used open source Zero Trust networking platform, and the NetFoundry platform is built on it. Open source means the code that carries your traffic is inspectable and auditable, which protects you from vendor lock-in and hidden behavior. NetFoundry adds the managed control plane, global fabric, enterprise support, and compliance capabilities that production deployments require.

Which compliance frameworks does NetFoundry support?

NetFoundry supports Zero Trust architectures aligned with PCI-DSS, IEC 62443, NIST 800-207, NIST 800-171, NERC CIP, NIS2, DORA, HIPAA, EU CRA, SOC 2 Type II, FIPS, and CJIS. Deny-by-default reachability, mutual TLS on every session, end-to-end encryption, and identity-based audit logging map directly to the access-control and monitoring requirements these frameworks share. NetFoundry deploys on-premises and in air-gapped environments where regulation constrains the data path.

See Your Attack Surface Disappear

Bring us the use case in front of you. One identity-first fabric covers them all.