Enterprise Wi-Fi authentication,
reimagined for cloud.
WPA2/3-Enterprise (802.1X) authentication, dynamic VLAN segmentation, and per-user device management.
All managed from the cloud with your existing identity provider — no hardware, live in under an hour.
WPA2/3-Enterprise
Service-issued credentials
EU Data Residency
AWS Frankfurt (eu-central-1)
-
802.1X
Standards-based Layer 2
-
EU
Data residency (Frankfurt)
-
< 3 min
SaaS-powered onboarding
-
Zero
Hardware to deploy
Powerful Features
Everything you need for modern enterprise Wi-Fi authentication
-
802.1X Authentication
Cloud RADIUS with WPA2/3-Enterprise (PEAP-MSCHAPv2) and service-issued credentials — your IdP password is never used for Wi-Fi. Dynamic VLAN assignment per user and device.
-
IdP Integration
Identity-first onboarding. Federate with Google Workspace or any OIDC-based identity provider. Zero manual identity management.
-
Self-Service Portal
Users manage their own device slots and credentials. Wi-Fi credentials arrive by email with step-by-step setup guides for Windows, macOS, iOS, and Android. No IT tickets needed.
-
Back Office & Audit
Admin console for policies, user and device lifecycle, real-time health dashboards, and exportable session logs. 2FA-protected admin login.
-
EU Data Residency
Multi-tenant SaaS running on AWS Frankfurt. EU data residency by design. Per-tenant isolation through dedicated NLBs and isolated database schemas.
-
Printers & IoT (MAB)
Bring non-802.1X devices onto the network with an admin-managed MAC allowlist (MAB) and isolated VLANs. Available on Professional and Enterprise plans.
-
IP Mobility
Identity-bound DHCP engine for lifetime IP per employee. Maintain the same IP across sites, floors, and networks seamlessly.
-
Analytics & Audit
Rule-based anomaly detection, policy violation alerts, and automated risk scoring. Capacity planning reports and structured audit query interface for compliance reviews.
Three steps for IT
One email for everyone else
Set up your organization on the Back Office once, and your team self-onboards from a single email.
For Admins
~5 minutes
Set up once. Done.
-
1
Sign up
Create your organization and choose a plan. Start with a 14-day free trial — full Professional features, nothing charged during the trial. A credit card is required; the trial converts to your selected plan after 14 days unless you cancel.
~ 2 min · cancel anytime during the trial -
2
Configure essentials
Set your organization name, SSIDs, and RADIUS endpoint.
A handful of fields — that's it.~ 3 min -
3
Add your team
Invite users manually, or sync via SAML / OIDC for automatic provisioning.
manual or SSO
For End Users
~2 minutes
Zero learning curve.
-
1
Open invitation email
Receive a secure invite link — or visit the URL the admin shared.
no app install -
2
Set up Wi-Fi with your personal credentials
Your service-issued Wi-Fi credentials arrive by email. Add the network following the step-by-step guide for your OS. Done.
no IT ticket
From sign-up to first authenticated login : under one hour.
No Appliance
No Professional services
No Tickets
Same enterprise-grade 802.1X + RADIUS as legacy NAC — without the hardware, the consultants, or the multi-year contract.
-
Traditional NAC
Hardware-era deployment
Hardware appliance to procure, rack, and license
Weeks of professional services to stand up
Capacity planning and hardware refresh cycles
Per-site deployments for multi-location orgs
Multi-year contracts and vendor lock-in
-
npass.io
Cloud-native, self-serve
Sign up and log in — no hardware, no install
Self-serve setup — no consultants required
Elastic capacity, managed for you on AWS Frankfurt
One tenant covers all sites, anywhere in the EU
Monthly subscription, scale up or down on demand
months
under 1 hour
Compliance & Security
Transparent about what's in place today, and what's on our certification roadmap.
-
Compliant by design — in place today
Legal obligations-
In place
GDPR
Privacy-by-design architecture, Art. 13/14 transparency, Art. 28 DPA available on request, Art. 30 records of processing maintained.
-
In place
NIS2 alignment
Technical and organizational measures (TOMs) aligned with NIS2 Art. 21 risk management requirements. Incident response procedures documented.
-
In place
TDDDG / DDG §5
German telemedia and digital services law: Impressum, cookie consent, and electronic communication requirements fully met.
-
In place
EU Data Residency
All customer data stored in the European Union (AWS Frankfurt, eu-central-1). Operational access by our Seoul team is role-based, logged, and covered by the EU–Korea adequacy decision (Art. 45 GDPR).
-
-
Certification roadmap
Independent audits-
In progress
ISO/IEC 27001
Information Security Management System (ISMS) implementation underway. Scope covers our operations in Seoul (HQ and R&D) and our EU service infrastructure under a single ISMS.
-
Planned
BSI C5 Type 2
German cloud security attestation (ISAE 3000) targeted after ISO 27001 certification, prioritized based on public-sector and regulated customer demand.
-
Planned
SOC 2 Type II
AICPA Trust Services Criteria attestation for customers requiring SOC 2 reports. To be pursued in parallel with BSI C5 based on customer portfolio needs.
-
Early-access transparency. npass.io is in its early-access phase. We build the service to the requirements of applicable EU and German law (GDPR, TDDDG) and align our security program with NIS2 Art. 21, and we are transparent that independent certifications are on our roadmap rather than already completed. Early-access customers receive our current TOMs documentation, DPA, and a binding commitment to our certification timeline. For detailed sub-processor and security information, see Security & Sub-processors.
Early Access — Invitation Only
npass.io is currently onboarding a limited number of design-partner customers. Plans and pricing are shared privately with invited teams.
Request an invitation
We partner closely with early customers
During our early-access phase we work hand-in-hand with a small group of enterprises to shape the product. Invited teams receive tailored onboarding, a direct line to our engineers, and transparent pricing built around their deployment — not a public rate card.
-
Dedicated onboarding and integration support
-
Custom pricing tailored to your users, sites, and devices
-
Direct access to the engineering team and roadmap
-
EU-hosted, built for GDPR and TDDDG compliance, with a NIS2-aligned security program
We'll get back to qualified requests within 2 business days.
Ready to modernize your network?
Join our early-access program and help shape the future of cloud-native network authentication.