Everything we shipped
Agent Authority
For securing and governing AI agent access to enterprise systems
Give every agent exactly the access it needs, and nothing more
Agents don’t get full access and their reach can be controlled, so an agent gets only what it should, such as read-only access to Jira, and the impact of any single agent stays contained.
Keep sensitive data from leaving through AI tool calls
Your sensitive corporate data is safely masked at the gateway, so PII and secrets don’t leak.
An Enterprise MCP gateway for all the AI tools your teams use
All your integrations, including GitHub, Microsoft 365, Confluence, Claude, ChatGPT, Salesforce, Notion, and Stripe, can be routed through the AI Gateway to get the data they need. Security teams keep centralized visibility and control over exactly what data each AI tool and agent can reach.
Prove which agent did what and why
Agent activity, actions, and behavior can be tracked and isolated. They carry their own identity, tied to a human user without using a shared service account: giving you provable accountability for every agent action.
See what your AI subscription tools are costing
You can now assess the cost of using agents to do various jobs, monitor the token usage, attribute it to agent instance, user and AI model across providers, including Claude Code and Codex.
Read the full Agent Authority release → Agent Radar: MCP Gateway
B2B Authority and Customer Authority
For teams running partner or B2B access and customer sign-in
Lower OTP costs
If your organization sends a high volume of one-time passcodes to customers, you can save on cost by connecting to your own SMS carrier, like Twilio, Vonage, or TeleSign, and route your OTP traffic through the contract you have already negotiated.
Running OTP traffic on your own contract almost always costs less than bundled pricing, and the more you send, the more you keep. Your deliverability goes up, because you can set fallback ordering, so a second carrier steps in when the first one drops messages in a region. And you are no longer tied to whichever provider we picked.
Block attackers from OTP fraud
OTP fraud is now blocked by default, and your OTP flow can no longer be abused to run up your SMS bill.
Attackers trigger floods of OTP texts to farm carrier payouts, or brute-force their way through codes. Per-user and per-address rate limits now cap how many attempts or sends can happen in a given window and block anything over the line, with nothing for you to set up.
More access control for admin access roles
Your configuration APIs now sit behind OAuth2 client-credentials authentication with separate read and write scopes, so access is controlled and auditable like everything else in your environment.
Read access alone can reveal how your environment is wired and write access could let someone change the rules that govern the gateway. Locking both down closes an exposure that penetration tests flag on sight, and it is often exactly what you need to pass a security review. Scoping the two separately means you grant exactly the access each integration needs, and nothing more.
Customer Authority
For customer-facing sign-in and registration experiences (CIAM)
Passkeys are now portable across your brand domains
Roll out phishing-resistant passkeys with confidence. Passkeys are locked to the specific web address where a user first sets them up. That creates a problem if your company runs more than one site or ever changes a domain: someone who registered on login.yourbrand.com can suddenly be shut out on app.yourbrand.com, and a domain change can force everyone to start over.
With Customer Authority, you can anchor passkeys to your real brand domain from day one, use a single credential across multiple properties, and move or migrate domains later without invalidating everyone’s passkeys. If you have ever watched a passkey rollout break in a multi-domain setup, this is the setting that prevents it.
Workforce Authority
For employee and contractor sign-in across your workforce
Routine, low risk sign-ins are now passwordless
Let the users you already trust skip the password and get straight to work. When the platform scores a sign-in as low risk, based on a known device, a normal location, and recent activity, it removes the password step for that login. Anything suspicious still gets challenged.
Let low-risk users skip the password.
Scoped Dashboard Access
Until now, giving an auditor or SOC analyst a look at the Dashboard meant granting them full admin. If that person got phished, the attacker inherited far more than read access.
Now you can publish the Dashboard as a standalone app scoped to specific datastores, policies, and user groups. This gives the right people read-only visibility without handing out full admin rights, which clears a least-privilege gap that security reviews tend to flag.
Give auditors dashboard access without admin rights.
Skip the directory migration with native support
Start using the platform without moving your existing user directory. If you run OpenLDAP (a common system for storing your list of employees and their access), the platform now connects directly to your existing OpenLDAP and uses it as the system of record, reading your users straight from the directory you already maintain. You don’t need a migration project to plan, nor a second copy of your employee data to protect and keep in sync.
Connect your OpenLDAP directory.
Improved sign-in experience for Entra ID users
Get your Microsoft Entra ID users logging in reliably again. In a common Entra ID and Microsoft 365 setup, sign-ins were getting stuck in a loop that bounced users back and forth and locked them out entirely.
How Entra ID users are matched at sign-in.
Our platform can authenticate users against Entra ID directly now, through its token validation endpoint, instead of running a full interactive flow.
How users sign-in without the Microsoft redirect.
Improved login availability
Login availability is something every customer counts on, so we have made the login experience even more resilient. Push, OTP, and biometric flows are more resilient; recovery after restarts is faster, and mobile authentication no longer depends on full-service availability. We also retired legacy components, which reduces the attack surface your audits look at.
Assurance Authority
For risk-based login scoring across your environment
Login scoring at scale
The risk engine now scores logins faster and at higher throughput, returning each decision in milliseconds with capacity tuned for around 20,000 logins per minute. Its pooled connection architecture keeps that speed consistent whether you are running steady traffic or a high-volume surge.
Every single login gets a real-time risk evaluation, even during peak traffic and attack conditions, so no session slips through unscored. For the business, logins stay quick and users get in without delay during your busiest traffic hours.