802.1X Authentication
RADIUS-based authentication with EAP-TLS, built-in CA, and dynamic VLAN assignment. Automatic fail-VLAN with DNS sinkhole for rogue devices.
Cloud-Native NAC for the Modern Enterprise
802.1X authentication, dynamic VLAN segmentation, and certificate-based device identity. All managed from the cloud with your existing identity provider.
Everything you need for modern network access control
RADIUS-based authentication with EAP-TLS, built-in CA, and dynamic VLAN assignment. Automatic fail-VLAN with DNS sinkhole for rogue devices.
Identity-first onboarding. Federate with Google Workspace or any OIDC-based identity provider. Zero manual identity management.
Users register devices themselves. Profiles and 802.1X certificates install automatically on Windows, macOS, iOS, and Android. No IT tickets needed.
Admin console for policies, user and device lifecycle, real-time health dashboards, and exportable session logs. 2FA-protected admin login.
Multi-tenant SaaS running on AWS Frankfurt. EU data residency by design. Per-tenant isolation through dedicated NLBs and isolated database schemas.
Identity-bound DHCP engine for lifetime IP per employee. Maintain the same IP across sites, floors, and networks seamlessly.
Anomaly detection and policy recommendations driven by machine learning. Automated risk scoring, predictive capacity planning, and natural-language audit queries.
From device to authenticated network in minutes
Device joins the open onboarding SSID or hits a fail-VLAN port.
User signs in via Google Workspace or any OIDC provider through the portal.
802.1X profile and EAP-TLS certificate install automatically.
RADIUS returns a dynamic VLAN matched to the user's policy.
Every session is logged and visible from the Back Office.
Transparent about what's in place today, and what's on our certification roadmap.
Privacy-by-design architecture, Art. 13/14 transparency, Art. 28 DPA available on request, Art. 30 records of processing maintained.
Technical and organizational measures (TOMs) aligned with NIS2 Art. 21 risk management requirements. Incident response procedures documented.
German telemedia and digital services law: Impressum, cookie consent, and electronic communication requirements fully met.
All customer data hosted in the European Union (AWS Frankfurt, eu-central-1). No data egress outside the EU without explicit customer consent.
Information Security Management System (ISMS) implementation underway. Scope covers Berlin operations and Seoul R&D under a single ISMS. Stage 2 audit planned for Q2 2027.
German cloud security attestation (ISAE 3000) targeted after ISO 27001 certification, prioritized based on public-sector and regulated customer demand.
AICPA Trust Services Criteria attestation for customers requiring SOC 2 reports. To be pursued in parallel with BSI C5 based on customer portfolio needs.
Early-access transparency. npass.io is in its early-access phase. We are fully compliant with applicable EU and German laws (GDPR, NIS2, TDDDG) today, and we are transparent that independent certifications are on our roadmap rather than already completed. Early-access customers receive our current TOMs documentation, DPA, and a binding commitment to our certification timeline. For detailed sub-processor and security information, see Security & Sub-processors.
npass.io is currently onboarding a limited number of design-partner customers. Plans and pricing are shared privately with invited teams.
Request an invitation
During our early-access phase we work hand-in-hand with a small group of enterprises to shape the product. Invited teams receive tailored onboarding, a direct line to our engineers, and transparent pricing built around their deployment — not a public rate card.
Join our early-access program and help shape the future of cloud-native NAC.
Request an Invitation