Zero Trust Workload Connectivity
The only identity-first Zero Trust fabric for every AI, API, and machine interaction.
Stop managing your attack surface. Eliminate it.
Cloak Your Network with OpenZiti by NetFoundry. Secure Services not IPs.
Managing networks with static IPs, subnets, NAT, and firewalls is complex, fragile, and error-prone. As environments scale across cloud, hybrid, and mobile, traditional IP-based control falls apart. OpenZiti eliminates this headache by making identity—not IP—the core of your network. No more IP conflicts, no more guessing, just secure, Zero Trust connectivity that works anywhere.
Start with OpenZiti.
Move to NetFoundry When You Are Ready to Scale.
Take on the operations yourself, or hand them to NetFoundry for a faster, easier path to production at scale. Every tier runs the same open-source OpenZiti software.
OpenZiti
Deploy the world’s most widely-used open-source Zero Trust networking platform yourself. Stand up your own controllers and edge routers, issue certificate-based identities to every user, service, and workload, and run services dark with no inbound ports. You own and run the OpenZiti Fabric, free under the Apache 2.0 license.
- Self-hosted and self-managed, with full control of the fabric
- Seven language SDKs, multi-OS tunnelers, and BrowZer for the browser
- Quickstarts, Docker, and Helm for stand-up and upgrades
- Community support through Discourse, GitHub, and documentation
NetFoundry Self-Hosted
Run your own OpenZiti fabric using NetFoundry’s licensed management suite. Purpose-built for regulated, air-gapped, and sovereign environments, it keeps the infrastructure under your control while NetFoundry’s tooling, support, and compliance evidence lighten the operational lift.
- NetFoundry management suite to accelerate and simplify deployment, orchestration, operation, and scaling
- 24×7 Enterprise support from the team that builds and maintains OpenZiti
- FIPS-compliant cryptography and post-quantum-ready encryption
- Controls pre-mapped to NIST 800-53 and 800-207 to speed RMF work
NetFoundry Cloud
Let NetFoundry provision and operate a dedicated OpenZiti fabric for you in minutes, then secure, manage, monitor, and scale it on your behalf. You run no infrastructure and build on the network instead of running it, backed by a contractual uptime SLA of up to 99.95%.
- Dedicated, global, isolated fabric provisioned in minutes
- 100+ points of presence across AWS, Azure, Google Cloud, and OCI
- Managed PKI, upgrades, backups, and proactive monitoring
- SOC 2 Type II report and pre-mapped evidence to accelerate ATO
- Up to 99.95% SLA
Want to learn alongside other builders? Join the Community →
Reachability Is the Root Cause
Attackers now use AI to find and weaponize exposed surfaces faster than any team can patch, tune, or review. The same underlying flaw surfaces as five separate problems, each one a different team’s fire to fight.
- Attackers discover and hijack AI agents, LLMs, and MCP servers the moment they are exposed.
- Automated bots scan and exploit public APIs faster than teams can patch them.
- A single breach rides site-to-site VPN tunnels into every network they connect.
- One compromised host moves laterally across a flat network to reach everything else.
- Remote access into OT and IoT hands attackers a path to systems no one can take offline to patch.
Legacy networking creates reachability, and reachability is what becomes breachability and then traversability.
The result is a workload an attacker can find, breach, and move through. Open ports advertise a target, IP-based access decisions identify nothing, and inbound firewall rules multiply the surface with every new connection.
Eliminate the reachability, and the rest of the chain never starts.
Identity-First, Dark by Default
OpenZiti removes the root that the five problems share: reachability. One identity-first overlay authenticates and authorizes every connection before any network path exists, so unauthorized actors reach nothing.
How OpenZiti closes the surface.
Every user, device, service, and workload holds an X.509 certificate identity. The fabric of controllers and edge routers carries traffic only after a session authenticates and authorizes, and it re-checks continuously. Services listen on no ports, routers dial outbound, and your firewalls enforce a single deny-all inbound rule.
The same model that closes the attack surface opens the business: connect any site, workload, partner, or AI agent by policy alone, with no firewall tickets and no re-architecture.
- Authenticate and authorize before any routable path is created
- Outbound-only, dark-by-default services with no listening ports
- Least-privilege access: reaching one service grants nothing else
- Mutual TLS on every hop and end-to-end encryption with keys sovereign to the endpoints
- Secure apps, workloads, servers, containers, VMs, and endpoints
- Embed Zero Trust directly in apps with SDKs for Go, C, C#/.NET, Python, Node.js, Java/Kotlin, and Swift
- Cover apps you cannot modify with tunnelers, and reach browsers with BrowZer, no install required
Authenticate First. Connect Second. Always.
OpenZiti reverses the traditional order for every connection, human or machine.
Want the architecture in depth, including the fabric, identities, SDKs, and the control plane?
OpenZiti and NetFoundry, Answered
What is OpenZiti?
OpenZiti is the world’s most widely-used open-source Zero Trust networking platform, created and maintained by NetFoundry and licensed under Apache 2.0. It gives every user, device, service, and workload an X.509 certificate identity, then authenticates and authorizes each connection before any network path exists. Services run dark with no inbound ports, routers dial outbound, and traffic is encrypted end to end, which removes the reachable attack surface that attackers scan and exploit.
What is the relationship between OpenZiti and NetFoundry?
NetFoundry created and maintains OpenZiti, and the NetFoundry platform is built on it. Open source means the code that carries your traffic is inspectable and auditable, which protects you from vendor lock-in and hidden behavior. NetFoundry’s commercial solutions add the operational tooling, managed control plane, global fabric, enterprise support, and compliance capabilities that production deployments require, without changing the underlying technology.
Is OpenZiti really free, and what can I build with it?
Yes. OpenZiti is free and open source under the Apache 2.0 license, and you can run it in production at no license cost. You deploy and operate your own controllers and edge routers, issue and manage identities, and embed Zero Trust connectivity into applications with SDKs for Go, C, C#/.NET, Python, Node.js, Java/Kotlin, and Swift. Tunnelers cover applications you cannot modify, and BrowZer extends Zero Trust to standard web browsers with no install or code changes. There is no licensing cost; the cost of running OpenZiti at enterprise scale is operational: the people, infrastructure, and ongoing engineering the deployment requires.
Does OpenZiti require opening inbound firewall ports?
No. OpenZiti connections are outbound-only from every endpoint, which means you open no inbound firewall ports, publish no public IP addresses, and run no listening services for attackers to find. Authentication and authorization complete before any routable path is created, and your firewalls can enforce a single deny-all inbound policy.
When should I move from self-run OpenZiti to NetFoundry?
Run OpenZiti yourself when you want full control and have the team to operate it. Consider NetFoundry Self-Hosted or NetFoundry Cloud when the operational demands of production start to compete with running your business: scaling, monitoring, incident response, disaster recovery, coordinated upgrades, compliance attestation, and a contractual uptime commitment. Self-Hosted keeps the fabric in your own environment with NetFoundry’s licensed tooling and support, which suits regulated, air-gapped, and sovereign deployments. Cloud hands the entire operation to NetFoundry which provides you with a dedicated, managed fabric.
Which compliance frameworks does NetFoundry support?
NetFoundry supports Zero Trust architectures aligned with PCI-DSS, IEC 62443, NIST 800-207, NIST 800-171, NERC CIP, NIS2, DORA, HIPAA, EU CRA, SOC 2 Type II, FIPS, and CJIS. Deny-by-default reachability, mutual TLS on every session, end-to-end encryption, and identity-based audit logging map directly to the access-control and monitoring requirements these frameworks share. NetFoundry delivers FIPS-compliant cryptography, post-quantum-ready encryption, and SOC 2 Type II reports, with controls pre-mapped to NIST 800-53 and 800-207 to accelerate authorization.
Ready to Secure Services, Not IPs?
Stand up the open-source platform today, or let NetFoundry run it for you at production scale.