Stop Managing Your Attack Surface. Eliminate It.
Identity-First Reachability™ makes your workloads unreachable by default. Every connection dials outbound, authenticates before it connects, and leaves no open port for an attacker to find.
- Outbound-only connections, with no inbound ports to scan or exploit
- Every session authenticated before it connects, using mutual X.509 identity
- Least-privilege access enforced by identity, not by IP address
- One control plane across cloud, data center, edge, and embedded workloads
Why a NetFoundry-Protected Workload Has No Attack Surface
A NetFoundry-protected workload never listens for inbound connections. It dials out to the fabric, proves its identity with a mutual X.509 certificate, and reaches only the destinations its policy allows. An attacker scanning the network finds no open port, no listening service, and no address to target.
NetFoundry Alongside What You Already Run
SASE and ZTNA solve the human-to-application problem well. NetFoundry covers the machine workloads they leave out.
What SASE and ZTNA Cover
- Secure remote access for human users on managed devices
- Human identity connecting to a sanctioned application
- Device posture, browser isolation, and user policy
What NetFoundry Covers
- Site-to-site connectivity without VPNs or lateral movement
- Service-to-service, API, and AI-agent workloads with no human in the loop
- Zero Trust connectivity embedded inside your own products
Four Building Blocks Deliver Identity-First Reachability
Four components deliver Identity-First Reachability, from a workload’s outbound reach to enforcement at the edge.
Tunnelers
Tunnelers bring workloads you cannot modify onto the fabric. Install one on a host, container, or gateway, and it dials outbound to the network with no change to the application and no new firewall rules to open. Tunnelers run on Windows, macOS, and Linux, with mobile clients for Android and iOS.
NetFoundry SDKs
The NetFoundry SDK embeds Zero Trust connectivity directly inside your application: the app itself dials out and authenticates, with no separate agent to deploy. SDKs are available for Go, C, .NET, Java, Node, and Swift, and they build on the open-source OpenZiti project, whose source is public and auditable.
The Control Plane
The control plane holds every identity, the policies that govern them, and the orchestration that ties them together. It authorizes each connection request and pushes policy out to the edge.
Enforcement
Enforcement happens at the edge, where the platform applies least-privilege policy to every connection request. A workload can dial only what its identity is authorized to reach, and everything else stays undiscoverable.
The Cryptography Behind Identity-First
Every endpoint proves who it is with a private key that never leaves its system.
Identity That Can’t Be Stolen in Transit
Every identity is a private X.509 key pair that the system generates locally. The private key never leaves that system and never crosses the wire, leaving an attacker no credential in transit to intercept or replay.
Mutual Authentication on Every Connection
NetFoundry authenticates both ends of every connection with mutual TLS. The initiator proves its identity to the destination, and the destination proves its identity in return, before any application data flows.
Encryption That Stays End to End
NetFoundry encrypts traffic end to end between the two authenticated endpoints and never terminates the TLS session in the middle. The platform carries your data without the ability to read it, and the fabric itself never becomes a point of exposure.
The Anatomy of an Identity-First Connection
Every connection follows the same identity-first sequence — the steps below trace it end to end, from a workload registering itself to an encrypted session between two proven endpoints.
Two Ways to Deploy the Platform
The same identities, policies, and SDKs apply whether NetFoundry operates the platform for you or you run it yourself.
NetFoundry-Hosted
NetFoundry operates the control plane and the network fabric for you. You define identities and policy; NetFoundry runs the infrastructure, scales it, and keeps it current. Teams that want Zero Trust connectivity without operating it choose this path.
- Fully managed by NetFoundry, scaled and kept current
- Fully automated lifecycle management of all hosted components
Self-Hosted
Run the control plane and fabric in your own environment when data residency, air-gap, or sovereignty requirements demand it. Every identity, policy, and SDK works exactly as it does in the hosted model.
- Full operational control in your own environment
- Lifecycle-management support for the components you operate
A Global Fabric Built for Production
The NetFoundry fabric is a globally distributed mesh of routers that runs across every major cloud, carrying authenticated traffic close to your workloads wherever they run.
Full Visibility and Control
You run NetFoundry with the visibility you expect from the rest of your stack: one console, event and audit streams, exportable metrics, and integrations that fit the tools you already use.
Management Dashboard
A single console governs every identity and policy. You create identities, author policy, and see what each workload is authorized to reach from one place.
Event and Audit Management
NetFoundry records every authentication, authorization, and policy change, then streams those events and audit trails to the security tools your team already runs.
Metrics and Telemetry
Export connection, throughput, and health metrics into your own dashboards and monitoring stack, where platform behavior lives alongside the rest of your observability data.
Integrations
A full API and webhooks connect NetFoundry to your identity provider for authentication, to your monitoring tools for events, and to the automation you already rely on.
Start with One Workload, Not a Forklift Replacement
NetFoundry overlays your existing network instead of replacing it. You give one workload an outbound-only connection, prove the model on something real, and extend it to the next workload on your own schedule. Your current firewalls, VPNs, and security controls keep running the whole time.
- No firewall rules to rewrite and no VLANs to redesign
- No rip-and-replace of your existing network security stack
- No coordinated cutover, because new workloads join one at a time
- Runs alongside your current controls, letting you adopt at your own pace
The Same Architecture Behind Every Use Case
The same architecture powers every use case NetFoundry supports.
AI Security
Governance at machine speed — security, visibility, and cost accountability for every AI workload.
Learn more
API Security
Prevent exposure before it ships, in an era of AI-accelerated vulnerability discovery.
Learn more
Site-to-Site Connectivity
Connect sites without VPNs and without leaving room for lateral movement.
Learn more
Microsegmentation
Identity-first segmentation with no VLAN or firewall changes, deployable on day one.
Learn more
OT / IoT Connectivity
Security for operational networks without putting uptime at risk.
Learn more
Building Your Own Product
Zero Trust connectivity built directly into your product, white-labeled and portless.
Learn more
Gateways for AI Workloads
NetFoundry provides gateways that apply Identity-First Reachability to AI traffic, so your model calls and MCP tools run over the same Zero Trust networking with no open ports.
LLM Gateway
The NetFoundry LLM Gateway is an OpenAI-compatible API proxy that routes requests across multiple LLM providers over Zero Trust networking.
- Multi-provider routing to any OpenAI-compatible backend
- Semantic routing and load balancing
- Per-identity budgets and cost tracking
- Guardrails for PII detection, content safety, and prompt injection
MCP Gateway
The NetFoundry MCP Gateway gives distributed systems secure, isolated access to Model Context Protocol (MCP) tools without exposing any public endpoint.
- Single-command setup for any MCP server
- Permission filtering that removes tools from the registry entirely
- Per-client session isolation
- Identity-based access with no open ports and no VPN
An Open Foundation, a Production Platform
NetFoundry is built by the team behind OpenZiti, the open-source Zero Trust networking project. The protocol, the SDKs, and the tunnelers are public and auditable: you can read exactly how a connection is authenticated and encrypted rather than trust a black box.
Thousands of developers build on OpenZiti directly. The NetFoundry platform adds the hosting, orchestration, support, and scale that production teams need on top of it, and it keeps the open-source foundation you can inspect for yourself.
Aligned to the Frameworks Your Auditors Require
Identity-First Reachability maps cleanly onto the controls auditors look for: strong authentication, least-privilege access, encryption in transit, and identity-based audit trails.
Trusted Where Reachability Matters Most
“NetFoundry enabled us to move to Infrastructure-as-Code automation, including customer connectivity. As we roll this out to our customers, we are changing the game for MIS printing and labeling to deliver unmatched innovation to our clients, without asking them to open firewall ports or manage S2S VPNs.” Nico Delaere, IT and Security Manager, CERM
“We have significantly reduced our VPN complexity and mitigated issues related to NAT and FTP with overlapping IPs, which has enabled us to onboard new clients and workloads with as little friction as possible. NetFoundry has allowed us to scale faster, safer, and more cost effectively, while the Zero Trust overlay mesh network provides secure provisioning, management, and networking into our solutions as pure software.” Rodrigo Bernardinelli, CEO & Co-Founder, Digibee
Platform FAQ
What is the NetFoundry platform?
The NetFoundry platform delivers Identity-First Reachability™, a Zero Trust connectivity platform for AI, API, and machine-to-machine workloads. NetFoundry gives every workload an outbound-only connection with no open or listening ports, authenticates each session before it connects, and enforces least-privilege access by identity rather than by IP address.
How does Identity-First Reachability make a workload unreachable?
NetFoundry makes a workload unreachable by removing every inbound entry point. The workload never listens for connections; it dials outbound to the NetFoundry fabric, proves its identity with a mutual X.509 certificate, and reaches only the destinations its policy permits. An attacker scanning the network finds no open port and no listening service to target.
How does NetFoundry secure and encrypt a connection?
NetFoundry secures every connection with mutual TLS: both endpoints authenticate to each other using X.509 identities before any application data flows. The system generates each private key locally, and that key never leaves the system or crosses the wire. NetFoundry encrypts traffic end to end between the two authenticated endpoints and never terminates the TLS session in the middle, so the fabric carries your data without the ability to read it.
What is the difference between a NetFoundry tunneler and the NetFoundry SDK?
A NetFoundry tunneler brings workloads you cannot modify onto the fabric: you install it on a host, container, or gateway and it dials out without any change to the application. The NetFoundry SDK embeds the same Zero Trust connectivity directly inside your application, so the app itself dials out and authenticates with no separate agent to deploy. SDKs are available for Go, C, .NET, Java, Node, and Swift.
Can I self-host the NetFoundry platform?
Yes. NetFoundry runs as a hosted service in which NetFoundry operates the control plane and fabric for you, and it also runs fully self-hosted in your own environment when data residency, air-gap, or sovereignty requirements demand it. The same identities, policies, and SDKs apply in either model.
How does NetFoundry relate to OpenZiti?
NetFoundry is built by the team behind OpenZiti, the open-source Zero Trust networking project. The protocol, the SDKs, and the tunnelers are public and auditable, so you can read exactly how a connection is authenticated and encrypted. The NetFoundry platform adds the hosting, orchestration, support, and scale that production teams need on top of OpenZiti.
Does NetFoundry replace my SASE or ZTNA solution?
NetFoundry complements SASE and ZTNA rather than replacing them. SASE and ZTNA connect human users on managed devices to the applications they are entitled to use. NetFoundry closes the gap those tools leave for machine workloads: site-to-site connectivity, service-to-service and API traffic, AI agents, and connectivity embedded inside your own products.
See Your Attack Surface Disappear
Walk through Identity-First Reachability with our team and see how your workloads become unreachable by default.