Quick answer: NetFoundry builds OpenZiti, the most widely deployed open-source Zero Trust networking framework, and has spent every year since 2020 embedding identity-based connectivity into the infrastructure other companies ship — from AWS and Microsoft’s cloud platforms, to Oracle and IBM’s Zero Trust Kubernetes tooling, to Siemens’ industrial networks, to the AI agent deployments running today. Each phase below is documented by the adopting company or a named customer, not by NetFoundry.
2020: the year the perimeter stopped making sense
When offices emptied in March 2020, the corporate VPN became the bottleneck for everything at once. Remote work, cloud migration, and edge computing all arrived together, and each pulled traffic somewhere the perimeter had never been drawn.
NetFoundry’s answer was already built: connectivity as code, Zero Trust native overlays. Leading providers — Microsoft, Supermicro, and AWS — adopted it that year for cloud, enterprise application, edge, and IoT connectivity:
- AWS documented NetFoundry and AWS CloudEndure cutting cloud migration times by up to 79 percent while eliminating the need for site-to-site VPNs.
- Microsoft added NetFoundry Zero Trust to the Office 365 ecosystem as it rethought how remote users reach SaaS.
- Microsoft added NetFoundry Zero Trust to Azure Edge Zones and private MEC. Supermicro followed by embedding NetFoundry Zero Trust in its Intelligent Retail Edge for stores that needed IoT workloads without the networking, VPN, and firewall tax.
2021–2024: Zero Trust becomes an architecture
Once every board deck said “Zero Trust,” the practical question became who actually implements it, and where it mattered most.
Leaders including IBM, Oracle, and Microsoft turned to NetFoundry. Use cases spanned chip to cloud: connected vehicles, surveillance cameras, Zero Trust APIs and webhooks, databases, and connected products.
- Oracle initially applied NetFoundry to Zero Trust Kubernetes, connecting Kubernetes APIs without a VPN, bastion host, or open port.
- Developers began making MuleSoft APIs into private APIs via NetFoundry, accessible over the internet with mTLS built in.
- Microsoft added NetFoundry to the inner circle of its Zero Trust partner ecosystem.
- IBM published a walkthrough for building a NetFoundry-powered multicloud Zero Trust network across AWS and IBM Cloud.
- Capgemini folded the approach into an automotive Zero Trust blueprint with NetFoundry and other partners for connected vehicles and plants. Arm added NetFoundry Zero Trust to its IoT and edge ecosystem.
- When Log4Shell hit, Oracle used NetFoundry’s OpenZiti to close ports so the vulnerability couldn’t be exploited — it is difficult to breach what you cannot reach.
- The same logic spread to edge compute and IoT: Arrow added NetFoundry to a Zero Trust reference architecture for edge infrastructure, and LiveView Technologies (LVT) added NetFoundry Zero Trust to its cameras.
- Intrusion embedded NetFoundry ZTNA in Intrusion Shield Endpoint to meet US federal Zero Trust mandates.
- GitHub’s documentation recommends NetFoundry’s OpenZiti for delivering Zero Trust webhooks to private systems without opening ports.
- Microsoft listed NetFoundry as an Azure Virtual WAN automation partner.
- CERM uses NetFoundry Zero Trust in the label and packaging MIS vendor space to secure site-to-site connections.
- FerretDB published a database over NetFoundry’s OpenZiti with nothing left listening.
2025–2026: industrial scale and AI both need identity-first Zero Trust
Manufacturers had spent a decade connecting machines. 2025 was when securing them stopped being optional.
- Siemens embedded NetFoundry in SINEC Secure Connect and SCALANCE, putting the overlay into industrial networks at Siemens’ distribution scale.
- FreeWave and Keyfactor joined a three-way industrial IoT alliance pairing wireless and PKI with NetFoundry’s identity-based networking.
Generative AI arrived and brought a new version of an old problem: software agents that act on their own, hold shared API keys, and can reach whatever the network allows. The overlay turned out to fit.
- Agyn uses OpenZiti to isolate Kubernetes AI agents per pod, so a compromised agent has nowhere to go.
- Rhapsody now connects more than 1,900 healthcare organizations across 30+ countries with no inbound ports, having replaced hundreds of VPN tunnels — its AI agents use the same identity-first approach.
- A top defense contractor carries drone reconnaissance feeds over Zero Trust private 5G at the tactical edge.
- Ominimo retired its VPNs and stood up microservices in new EU markets in under 72 hours as AI becomes embedded in insurance.