Cloud-Native 802.1X Authentication for the Modern Enterprise

Enterprise Wi-Fi authentication,
reimagined for cloud.

WPA2/3-Enterprise (802.1X) authentication, dynamic VLAN segmentation, and per-user device management.
All managed from the cloud with your existing identity provider — no hardware, live in under an hour.

npass.io dashboard
WPA2/3-Enterprise

Service-issued credentials

EU Data Residency

AWS Frankfurt (eu-central-1)

  • 802.1X

    Standards-based Layer 2

  • EU

    Data residency (Frankfurt)

  • < 3 min

    SaaS-powered onboarding

  • Zero

    Hardware to deploy

Powerful Features

Everything you need for modern enterprise Wi-Fi authentication

  • 802.1X Authentication

    Cloud RADIUS with WPA2/3-Enterprise (PEAP-MSCHAPv2) and service-issued credentials — your IdP password is never used for Wi-Fi. Dynamic VLAN assignment per user and device.

  • IdP Integration

    Identity-first onboarding. Federate with Google Workspace or any OIDC-based identity provider. Zero manual identity management.

  • Self-Service Portal

    Users manage their own device slots and credentials. Wi-Fi credentials arrive by email with step-by-step setup guides for Windows, macOS, iOS, and Android. No IT tickets needed.

  • Back Office & Audit

    Admin console for policies, user and device lifecycle, real-time health dashboards, and exportable session logs. 2FA-protected admin login.

  • EU Data Residency

    Multi-tenant SaaS running on AWS Frankfurt. EU data residency by design. Per-tenant isolation through dedicated NLBs and isolated database schemas.

  • Printers & IoT (MAB)

    Bring non-802.1X devices onto the network with an admin-managed MAC allowlist (MAB) and isolated VLANs. Available on Professional and Enterprise plans.

  • IP Mobility

    Identity-bound DHCP engine for lifetime IP per employee. Maintain the same IP across sites, floors, and networks seamlessly.

  • Analytics & Audit

    Rule-based anomaly detection, policy violation alerts, and automated risk scoring. Capacity planning reports and structured audit query interface for compliance reviews.

How it works

Three steps for IT
One email for everyone else

Set up your organization on the Back Office once, and your team self-onboards from a single email.

For Admins

~5 minutes

Set up once. Done.

  • 1

    Sign up

    Create your organization and choose a plan. Start with a 14-day free trial — full Professional features, nothing charged during the trial. A credit card is required; the trial converts to your selected plan after 14 days unless you cancel.

    ~ 2 min · cancel anytime during the trial
  • 2

    Configure essentials

    Set your organization name, SSIDs, and RADIUS endpoint.
    A handful of fields — that's it.

    ~ 3 min
  • 3

    Add your team

    Invite users manually, or sync via SAML / OIDC for automatic provisioning.

    manual or SSO

For End Users

~2 minutes

Zero learning curve.

  • 1

    Open invitation email

    Receive a secure invite link — or visit the URL the admin shared.

    no app install
  • 2

    Set up Wi-Fi with your personal credentials

    Your service-issued Wi-Fi credentials arrive by email. Add the network following the step-by-step guide for your OS. Done.

    no IT ticket

From sign-up to first authenticated login : under one hour.

Why npass.io

No Appliance
No Professional services
No Tickets

Same enterprise-grade 802.1X + RADIUS as legacy NAC — without the hardware, the consultants, or the multi-year contract.

  • Traditional NAC

    Hardware-era deployment

    • Hardware appliance to procure, rack, and license

    • Weeks of professional services to stand up

    • Capacity planning and hardware refresh cycles

    • Per-site deployments for multi-location orgs

    • Multi-year contracts and vendor lock-in

From PO to production

months

From sign-up to first login

under 1 hour

Compliance & Security

Transparent about what's in place today, and what's on our certification roadmap.

  • Compliant by design — in place today

    Legal obligations
    • In place
      GDPR

      Privacy-by-design architecture, Art. 13/14 transparency, Art. 28 DPA available on request, Art. 30 records of processing maintained.

    • In place
      NIS2 alignment

      Technical and organizational measures (TOMs) aligned with NIS2 Art. 21 risk management requirements. Incident response procedures documented.

    • In place
      TDDDG / DDG §5

      German telemedia and digital services law: Impressum, cookie consent, and electronic communication requirements fully met.

    • In place
      EU Data Residency

      All customer data stored in the European Union (AWS Frankfurt, eu-central-1). Operational access by our Seoul team is role-based, logged, and covered by the EU–Korea adequacy decision (Art. 45 GDPR).

  • Certification roadmap

    Independent audits
    • In progress
      ISO/IEC 27001

      Information Security Management System (ISMS) implementation underway. Scope covers our operations in Seoul (HQ and R&D) and our EU service infrastructure under a single ISMS.

    • Planned
      BSI C5 Type 2

      German cloud security attestation (ISAE 3000) targeted after ISO 27001 certification, prioritized based on public-sector and regulated customer demand.

    • Planned
      SOC 2 Type II

      AICPA Trust Services Criteria attestation for customers requiring SOC 2 reports. To be pursued in parallel with BSI C5 based on customer portfolio needs.

Early-access transparency. npass.io is in its early-access phase. We build the service to the requirements of applicable EU and German law (GDPR, TDDDG) and align our security program with NIS2 Art. 21, and we are transparent that independent certifications are on our roadmap rather than already completed. Early-access customers receive our current TOMs documentation, DPA, and a binding commitment to our certification timeline. For detailed sub-processor and security information, see Security & Sub-processors.

Early Access — Invitation Only

npass.io is currently onboarding a limited number of design-partner customers. Plans and pricing are shared privately with invited teams.

Request an invitation

We partner closely with early customers

During our early-access phase we work hand-in-hand with a small group of enterprises to shape the product. Invited teams receive tailored onboarding, a direct line to our engineers, and transparent pricing built around their deployment — not a public rate card.

  • Dedicated onboarding and integration support

  • Custom pricing tailored to your users, sites, and devices

  • Direct access to the engineering team and roadmap

  • EU-hosted, built for GDPR and TDDDG compliance, with a NIS2-aligned security program

We'll get back to qualified requests within 2 business days.

Ready to modernize your network?

Join our early-access program and help shape the future of cloud-native network authentication.