ZERO TRUST ACCESS · VPN-FREE

Never trust. Verify every request.

Cipheron Access checks identity, device and behaviour on every request to every app, then gets out of the way. Replace your VPN in an afternoon.

Free for 10 users · SOC 2 Type II · No agent for web apps

01 // REQUEST
GET /finance/payrollapp: payroll.internal09:41:07 UTC
02 // CONTINUOUS VERIFICATION
  • Identityj.hale@arcline.example · FIDO2 key
    PASS
  • DeviceManaged · disk encrypted · OS current
    PASS
  • LocationOslo, NO · usual network
    PASS
  • BehaviourRisk 12/100 · normal hours
    PASS
03 // DECISION
ALLOWsession 15 min · re-evaluated every request
Trust score94grade A

Securing access for 4,800+ companies

Meridia LabsPinegate InsuranceOriel CloudHalden RetailVantor EnergyArcline LogisticsKestrel HealthNorthwall Bank
01 — Capabilities

Access that adapts to risk, not location.

Phishing-resistant MFA

Passkeys and FIDO2 keys by default, with number matching as a fallback.

Device posture

Encryption, OS version, EDR health and screen lock checked on every request.

Adaptive risk

Behavioural signals trigger step-up auth only when something looks off.

Policy as code

Write policies in YAML, review them in pull requests, roll back in seconds.

SSH & databases

Short-lived certificates for servers and databases. No shared keys, ever.

HR-driven lifecycle

Joiners get access on day one; leavers lose it the minute HR says so.

DEVICE // ARC-MBP-0412RE-CHECKED 4 S AGO
Device score88grade A-
  • Disk encryptionPASS
  • OS patched < 14 daysPASS
  • EDR running & healthyPASS
  • Screen lock ≤ 5 minWARN
  • Firewall enabledPASS
  • Jailbreak / rootPASS
02 — Posture

A score for every device, every request.

Unhealthy devices get a clear fix-it screen instead of a silent block, so users repair their own posture in minutes.

71%Fewer access tickets
11 daysMedian rollout
0VPN concentrators
POLICYpolicies/finance.yaml
policy: finance-apps
match:
  apps: [payroll, ledger]
require:
  identity.mfa: phishing_resistant
  device.managed: true
  device.posture_score: ">= 80"
step_up_when:
  risk.score: "> 60"
session: { ttl: 15m, record: true }
✓ validated · synced to 14 points of presence
03 — Policy as code

Reviewed like code. Enforced everywhere.

Version, test and roll out access policy with the same workflow your engineers already trust.

  • Git sync with signed commits
  • Dry-run mode shows who would be blocked
  • Instant rollback to any previous version
04 — Pricing

Per user. Every app included.

Team

Replace the VPN for small teams.

$4 / user / mo
  • SSO + phishing-resistant MFA
  • Device posture checks
  • Up to 50 apps
  • Email support
Start free

Enterprise

Global scale and compliance.

$15 / user / mo
  • Everything in Business
  • Private points of presence
  • SCIM + HR-driven lifecycle
  • 99.99% uptime SLA
  • Dedicated success engineer
Contact sales
05 — Proof

Rolled out in days.

// CLIENT REPORT VERIFIED
Zero-trust rollout took eleven days for 1,400 staff. Nobody filed a ticket about VPNs again.
Marcus Dahl
Marcus DahlIT Director, Halden Retail

A named incident commander joins a bridge within your SLA, contains the threat with pre-approved actions, and keeps stakeholders updated on a fixed cadence until recovery.

Telemetry stays in the region you choose (EU, US or APAC), is encrypted at rest and in transit, and is never shared or used to train third-party models.

Yes. We integrate with the major EDR, cloud, identity and ticketing platforms, so you keep the investments you have already made.

cipheron@soc:~$ ./engage --now

Retire the VPN. Keep the peace of mind.

Free for your first 10 users. Connect your identity provider in five minutes.