The NetFoundry Platform

Stop Managing Your Attack Surface. Eliminate It.

Identity-First Reachability™ makes your workloads unreachable by default. Every connection dials outbound, authenticates before it connects, and leaves no open port for an attacker to find.

  • Outbound-only connections, with no inbound ports to scan or exploit
  • Every session authenticated before it connects, using mutual X.509 identity
  • Least-privilege access enforced by identity, not by IP address
  • One control plane across cloud, data center, edge, and embedded workloads
Identity-first network: a connection authenticates before it connects to an application.
Unreachable by Design

Why a NetFoundry-Protected Workload Has No Attack Surface

A NetFoundry-protected workload never listens for inbound connections. It dials out to the fabric, proves its identity with a mutual X.509 certificate, and reaches only the destinations its policy allows. An attacker scanning the network finds no open port, no listening service, and no address to target.

NetFoundry connects services, APIs, MCP servers, AI agents, networks, and cloud services through identity-defined connections.
Where It Fits

NetFoundry Alongside What You Already Run

SASE and ZTNA solve the human-to-application problem well. NetFoundry covers the machine workloads they leave out.

What SASE and ZTNA Cover

  • Secure remote access for human users on managed devices
  • Human identity connecting to a sanctioned application
  • Device posture, browser isolation, and user policy

What NetFoundry Covers

  • Site-to-site connectivity without VPNs or lateral movement
  • Service-to-service, API, and AI-agent workloads with no human in the loop
  • Zero Trust connectivity embedded inside your own products
The Platform, Component by Component

Four Building Blocks Deliver Identity-First Reachability

Four components deliver Identity-First Reachability, from a workload’s outbound reach to enforcement at the edge.

Reach

Tunnelers

Tunnelers bring workloads you cannot modify onto the fabric. Install one on a host, container, or gateway, and it dials outbound to the network with no change to the application and no new firewall rules to open. Tunnelers run on Windows, macOS, and Linux, with mobile clients for Android and iOS.

Embed

NetFoundry SDKs

The NetFoundry SDK embeds Zero Trust connectivity directly inside your application: the app itself dials out and authenticates, with no separate agent to deploy. SDKs are available for Go, C, .NET, Java, Node, and Swift, and they build on the open-source OpenZiti project, whose source is public and auditable.

Decide

The Control Plane

The control plane holds every identity, the policies that govern them, and the orchestration that ties them together. It authorizes each connection request and pushes policy out to the edge.

Enforce

Enforcement

Enforcement happens at the edge, where the platform applies least-privilege policy to every connection request. A workload can dial only what its identity is authorized to reach, and everything else stays undiscoverable.

Cryptographic Trust

The Cryptography Behind Identity-First

Every endpoint proves who it is with a private key that never leaves its system.

Identity That Can’t Be Stolen in Transit

Every identity is a private X.509 key pair that the system generates locally. The private key never leaves that system and never crosses the wire, leaving an attacker no credential in transit to intercept or replay.

Mutual Authentication on Every Connection

NetFoundry authenticates both ends of every connection with mutual TLS. The initiator proves its identity to the destination, and the destination proves its identity in return, before any application data flows.

Encryption That Stays End to End

NetFoundry encrypts traffic end to end between the two authenticated endpoints and never terminates the TLS session in the middle. The platform carries your data without the ability to read it, and the fabric itself never becomes a point of exposure.

How It Works

The Anatomy of an Identity-First Connection

Every connection follows the same identity-first sequence — the steps below trace it end to end, from a workload registering itself to an encrypted session between two proven endpoints.

Client Workload NetFoundry Controller NetFoundry Router(s) Server Workload 1. Server authenticates & registers hosting capabilities (mTLS) 2. Assign edge router targets for the service 3. Bind edge listener (outbound connect) Server dials the fabric. No inbound ports open. The firewall stays dark. 4. Authenticate & bootstrap identity (mTLS) 5. Authorize against policy, return service directory & tokens 6. Dial service (request a path to the server) 7. Provision a dedicated dynamic circuit across the fabric 8. Circuit established, return edge token to the client 9. End-to-end encrypted data channel established — dark to the public internet Client Workload NetFoundry Controller NetFoundry Router(s) Server Workload
How You Run It

Two Ways to Deploy the Platform

The same identities, policies, and SDKs apply whether NetFoundry operates the platform for you or you run it yourself.

Fully Managed

NetFoundry-Hosted

NetFoundry operates the control plane and the network fabric for you. You define identities and policy; NetFoundry runs the infrastructure, scales it, and keeps it current. Teams that want Zero Trust connectivity without operating it choose this path.

  • Fully managed by NetFoundry, scaled and kept current
  • Fully automated lifecycle management of all hosted components
Self-Operated

Self-Hosted

Run the control plane and fabric in your own environment when data residency, air-gap, or sovereignty requirements demand it. Every identity, policy, and SDK works exactly as it does in the hosted model.

  • Full operational control in your own environment
  • Lifecycle-management support for the components you operate
The Fabric

A Global Fabric Built for Production

The NetFoundry fabric is a globally distributed mesh of routers that runs across every major cloud, carrying authenticated traffic close to your workloads wherever they run.

100+Points of presence across every major cloud
99.95%Uptime service-level agreement
24×7×365Support, every day of the year
Operate and Observe

Full Visibility and Control

You run NetFoundry with the visibility you expect from the rest of your stack: one console, event and audit streams, exportable metrics, and integrations that fit the tools you already use.

Console

Management Dashboard

A single console governs every identity and policy. You create identities, author policy, and see what each workload is authorized to reach from one place.

Events

Event and Audit Management

NetFoundry records every authentication, authorization, and policy change, then streams those events and audit trails to the security tools your team already runs.

Metrics

Metrics and Telemetry

Export connection, throughput, and health metrics into your own dashboards and monitoring stack, where platform behavior lives alongside the rest of your observability data.

Integrations

Integrations

A full API and webhooks connect NetFoundry to your identity provider for authentication, to your monitoring tools for events, and to the automation you already rely on.

Incremental by Design

Start with One Workload, Not a Forklift Replacement

NetFoundry overlays your existing network instead of replacing it. You give one workload an outbound-only connection, prove the model on something real, and extend it to the next workload on your own schedule. Your current firewalls, VPNs, and security controls keep running the whole time.

1 Start with one workload
2 Prove the model in production
3 Expand on your own schedule
  • No firewall rules to rewrite and no VLANs to redesign
  • No rip-and-replace of your existing network security stack
  • No coordinated cutover, because new workloads join one at a time
  • Runs alongside your current controls, letting you adopt at your own pace
Gateways

Gateways for AI Workloads

NetFoundry provides gateways that apply Identity-First Reachability to AI traffic, so your model calls and MCP tools run over the same Zero Trust networking with no open ports.

Model Routing

LLM Gateway

The NetFoundry LLM Gateway is an OpenAI-compatible API proxy that routes requests across multiple LLM providers over Zero Trust networking.

  • Multi-provider routing to any OpenAI-compatible backend
  • Semantic routing and load balancing
  • Per-identity budgets and cost tracking
  • Guardrails for PII detection, content safety, and prompt injection
Tool Access

MCP Gateway

The NetFoundry MCP Gateway gives distributed systems secure, isolated access to Model Context Protocol (MCP) tools without exposing any public endpoint.

  • Single-command setup for any MCP server
  • Permission filtering that removes tools from the registry entirely
  • Per-client session isolation
  • Identity-based access with no open ports and no VPN
Built in the Open

An Open Foundation, a Production Platform

NetFoundry is built by the team behind OpenZiti, the open-source Zero Trust networking project. The protocol, the SDKs, and the tunnelers are public and auditable: you can read exactly how a connection is authenticated and encrypted rather than trust a black box.

Thousands of developers build on OpenZiti directly. The NetFoundry platform adds the hosting, orchestration, support, and scale that production teams need on top of it, and it keeps the open-source foundation you can inspect for yourself.

Compliance and Standards

Aligned to the Frameworks Your Auditors Require

Identity-First Reachability maps cleanly onto the controls auditors look for: strong authentication, least-privilege access, encryption in transit, and identity-based audit trails.

SOC 2 Type II FIPS IEC 62443 NIS2 NERC/CIP EU CRA SOCI NIST 800-171 DORA
Proof at Scale

Trusted Where Reachability Matters Most

3,000companies run on NetFoundry
2 of 5largest U.S. companies
8 of 10largest U.S. banks
1B+sessions secured every month
“NetFoundry enabled us to move to Infrastructure-as-Code automation, including customer connectivity. As we roll this out to our customers, we are changing the game for MIS printing and labeling to deliver unmatched innovation to our clients, without asking them to open firewall ports or manage S2S VPNs.” Nico Delaere, IT and Security Manager, CERM
“We have significantly reduced our VPN complexity and mitigated issues related to NAT and FTP with overlapping IPs, which has enabled us to onboard new clients and workloads with as little friction as possible. NetFoundry has allowed us to scale faster, safer, and more cost effectively, while the Zero Trust overlay mesh network provides secure provisioning, management, and networking into our solutions as pure software.” Rodrigo Bernardinelli, CEO & Co-Founder, Digibee
Questions

Platform FAQ

What is the NetFoundry platform?

The NetFoundry platform delivers Identity-First Reachability™, a Zero Trust connectivity platform for AI, API, and machine-to-machine workloads. NetFoundry gives every workload an outbound-only connection with no open or listening ports, authenticates each session before it connects, and enforces least-privilege access by identity rather than by IP address.

How does Identity-First Reachability make a workload unreachable?

NetFoundry makes a workload unreachable by removing every inbound entry point. The workload never listens for connections; it dials outbound to the NetFoundry fabric, proves its identity with a mutual X.509 certificate, and reaches only the destinations its policy permits. An attacker scanning the network finds no open port and no listening service to target.

How does NetFoundry secure and encrypt a connection?

NetFoundry secures every connection with mutual TLS: both endpoints authenticate to each other using X.509 identities before any application data flows. The system generates each private key locally, and that key never leaves the system or crosses the wire. NetFoundry encrypts traffic end to end between the two authenticated endpoints and never terminates the TLS session in the middle, so the fabric carries your data without the ability to read it.

What is the difference between a NetFoundry tunneler and the NetFoundry SDK?

A NetFoundry tunneler brings workloads you cannot modify onto the fabric: you install it on a host, container, or gateway and it dials out without any change to the application. The NetFoundry SDK embeds the same Zero Trust connectivity directly inside your application, so the app itself dials out and authenticates with no separate agent to deploy. SDKs are available for Go, C, .NET, Java, Node, and Swift.

Can I self-host the NetFoundry platform?

Yes. NetFoundry runs as a hosted service in which NetFoundry operates the control plane and fabric for you, and it also runs fully self-hosted in your own environment when data residency, air-gap, or sovereignty requirements demand it. The same identities, policies, and SDKs apply in either model.

How does NetFoundry relate to OpenZiti?

NetFoundry is built by the team behind OpenZiti, the open-source Zero Trust networking project. The protocol, the SDKs, and the tunnelers are public and auditable, so you can read exactly how a connection is authenticated and encrypted. The NetFoundry platform adds the hosting, orchestration, support, and scale that production teams need on top of OpenZiti.

Does NetFoundry replace my SASE or ZTNA solution?

NetFoundry complements SASE and ZTNA rather than replacing them. SASE and ZTNA connect human users on managed devices to the applications they are entitled to use. NetFoundry closes the gap those tools leave for machine workloads: site-to-site connectivity, service-to-service and API traffic, AI agents, and connectivity embedded inside your own products.

See Your Attack Surface Disappear

Walk through Identity-First Reachability with our team and see how your workloads become unreachable by default.