Alternatives to ZTXGate
Compare ZTXGate alternatives for your business or organization using the curated list below. SourceForge ranks the best alternatives to ZTXGate in 2026. Compare features, ratings, user reviews, pricing, and more from ZTXGate competitors and alternatives in order to make an informed decision for your business.
-
1
SuperOps
SuperOps
SuperOps is the AI-native unified platform for modern MSPs and internal IT teams. It replaces the typical four-to-six-tool IT operations stack - PSA, RMM, helpdesk, MDM, asset tracking, network monitoring, patch management and IT documentation - with a single, built-as-one platform on a shared data layer. That architectural choice is what makes the rest of the platform work, particularly its agentic AI. Monica AI, SuperOps' intelligence layer, was designed alongside the platform from day one. It triages tickets, surfaces patch and CVE risks, drafts worklogs, suggests knowledge base articles, and increasingly handles fully autonomous workflows for routine work. SuperOps supports Windows, macOS, Linux, iOS, iPadOS and Android, integrates with the IT and MSP ecosystem (Slack, Teams, Azure AD, Okta, QuickBooks, Xero, Bitdefender, SentinelOne and more), and bundles Splashtop and ISL Online remote access free. Transparent pricing, fast deployment, founder-led product investment. -
2
Proton VPN
Proton AG
Protect your business against damaging data breaches and easily comply with security frameworks like ISO 27001, GDPR, and HIPAA. Our software-only virtual private network easily integrates with your existing infrastructure to provide a flexible and scalable way to protect your organization. With our VPN Professional plan, you can securely access your LAN and SaaS resources by assigning and segmenting permissions to private dedicated VPN servers, allowing employees to access only what they need. With all plans, your network traffic is secured using strong AES-256 or ChaCha20 encryption. You can further strengthen your organization's security with enforced 2FA and seamless login through single sign-on (SSO) with SCIM support for automated user provisioning. Proton VPN's high-speed server network is one of the largest in the world and is part of a suite of open source end-to-end encrypted products from the makers of Proton Mail that are designed to keep your business secure. -
3
Airlock Digital
Airlock Digital
Airlock Digital is an application control solution that enforces a Deny by Default security posture. It enables organizations to define trusted applications, scripts, libraries, and processes at a granular level using file hash, path, publisher, or parent process. Only those explicitly defined as trusted are allowed to execute. The platform supports Windows, macOS, and Linux systems, including legacy operating systems and operational technology (OT) environments. Airlock Digital includes allowlisting and blocklisting capabilities, integrated file reputation checks via VirusTotal, and detailed logging for audit and compliance. Exception management is supported through features such as rule-based overrides and time-bound One-Time Passwords (OTPs). Centralized policy management allows consistent enforcement across large and distributed environments. The platform is available as an on-premises deployment, in the cloud, or as a managed hosted service. -
4
SentinelOne Singularity
SentinelOne
One intelligent platform. Unprecedented speed. Infinite scale. Singularity™ enables unfettered visibility, industry-leading detection, and autonomous response. Discover the power of AI-powered, enterprise-wide cybersecurity. The world’s leading enterprises use the Singularity platform to prevent, detect, and respond to cyber attacks at machine-speed, greater scale, and higher accuracy across endpoint, cloud, and identity. SentinelOne delivers cutting-edge security with this platform by offering protection against malware, exploits, and scripts. SentinelOne cloud-based platform has been perfected to be innovative compliant with security industry standards, and high-performance whether the work environment is Windows, Mac or Linux. Thanks to constant updating, threat hunting, and behavior AI, the platform is ready for any threat.Starting Price: $45 per user per year -
5
ip·Solis
XenPool GmbH
ip·Solis is a self-hosted platform for IT asset lifecycle management with self-service and automation — the layer between a CMDB, IAM/HR systems, and provisioning runbooks. Employees request VDIs, shared desktops, SaaS or any IT through a self-service portal with OIDC SSO (Entra ID, Okta and more); managers approve in one click, with multi-approver quorums, conditional rules and out-of-office delegation. Chained PowerShell 7 runbooks automate provisioning against Active Directory, SCCM, XenServer and VMware. Assets are managed across their full lifecycle: pooled or personal assignment, quotas, expiry and recycle workflows. Compliance is built in — access certification (ISO 27001/SOX/PCI), append-only audit log, SCIM 2.0 and HR-webhook leaver automation. Cost reporting tracks spend by provider, consumer and department. API-first: deploys in an afternoon via Docker, on-prem or air-gapped. Free for up to 25 users; commercial license above that. Source-available.Starting Price: From €1,488/year (free up to 2 -
6
SSOJet
SSOJet
SSOJet is an enterprise authentication platform built for modern B2B SaaS companies. It helps teams quickly add SAML SSO, SCIM provisioning, MFA, RBAC, directory sync, audit logs, and enterprise authentication without building complex identity infrastructure internally. As SaaS companies move upmarket, enterprise customers start demanding integrations with Okta, Microsoft Entra ID, Google Workspace, and other identity providers. SSOJet helps companies become enterprise-ready faster by simplifying authentication and access management. The platform supports SAML, OIDC, OAuth, passwordless login, social login, hosted auth pages, and multi-tenant SaaS architectures. It is designed for developers using modern stacks like Node.js, Go, React, and Next.js. Unlike many auth providers that charge per MAU, SSOJet uses predictable connection-based pricing, making enterprise scaling more cost-effective.Starting Price: $49/month -
7
Tester by Alcyone Systems
Alcyone Systems OÜ
Tester is an on-premises test automation appliance: one plain-language suite drives web browsers, HTTP APIs, Android devices and iOS from the same file, and AI test generation runs on local models (Ollama), so test data, credentials and pre-release builds never leave your network. Built for regulated teams (banking, fintech, health) that cannot send test data to cloud platforms. Ships as a hardened appliance or installs on your own hardware. A manual tester can read every suite line by line; the runner picks the right drivers per case and produces full run evidence: reports, screenshots, page snapshots and logs. Enterprise controls built in: SSO (OIDC/SAML), SCIM, multi-project RBAC, metadata-only audit, signed updates and signed licenses. External AI providers are strictly opt-in with a redaction preview.Starting Price: $49/month or enterprise prcs -
8
NetBird
NetBird
NetBird is an open-source Zero Trust Networking platform built by engineers for engineers. It radically simplifies deploying secure private networks using the high-performance WireGuard® protocol. Unlike traditional VPNs, NetBird creates decentralized, low-latency, high-throughput private networks with a single management console for identity-based access control. Integrating seamlessly with your IdP for SSO and MFA, it forms direct, encrypted peer-to-peer tunnels between devices, servers, and clouds - no central bottlenecks or single points of failure. Lightweight clients ensure scalability and privacy, with traffic never passing through management services. NetBird supports integrations with CrowdStrike, Intune, SentinelOne, pfSense, and more. Ideal for Zero Trust remote access, multi-cloud connectivity, dynamic posture checks, detailed auditing, and MSP multi-tenant management - all through one intuitive platform.Starting Price: $5/user/month -
9
Phishing Club
Phishing Club
Phishing Club is an open source phishing simulation and red team phishing framework for authorized security testing. Self host it on your own server via a one line installer or Docker. Plan, launch, and measure realistic campaigns from a single Go binary with an embedded web UI, HTTP/HTTPS phishing servers, and a REST API. Features: multi stage phishing flows, flexible scheduling, multiple domains with automatic TLS, SMTP or custom API delivery with OAuth, recipient groups with CSV import and SCIM, PDF campaign reports, analytics, multi tenancy, MFA and SSO (Entra ID, OIDC), webhooks, and in app updates. Red team and AiTM: reverse proxy phishing to capture sessions, remote browser phishing, DOM and URL rewriting, dynamic obfuscation, JA4 and geo IP filtering, and device code phishing.Starting Price: 0 -
10
Tesseral
Tesseral
Tesseral is the open source platform for managing identity and access in business software. It provides enterprise-grade capabilities, including SAML single sign-on, SCIM provisioning, role-based access control, managed API keys, and audit logs, implemented in just a few lines of code. Tesseral unifies access management for employees, customers, services, and AI agents, giving organizations the flexibility to adapt to any deployment model and the authority to enforce security policies with precision. You can learn more by reading our docs or by checking out our GitHub.Starting Price: $0 -
11
SecureCodingHub
Secure Coding Hub
SecureCodingHub is an interactive secure coding training platform for AppSec teams and engineering organizations. It offers Code Review Challenges — a two-phase find-and-fix flow across 185+ vulnerability types — and Guided Attack Scenarios with 67 step-by-step walkthroughs simulating full attack chains. Challenges are written in production-realistic code across 15 languages and frameworks including JavaScript, TypeScript, Python, Java, C#, Go, React, Vue, Angular, Swift, and Kotlin. Coverage spans OWASP Web, API, Mobile, and Client-Side Top 10. Compliance evidence builds automatically, mapped to PCI DSS 4.0.1, ISO 27001:2022, and EU CRA. Enterprise features include SAML 2.0/OIDC SSO, SCIM 2.0, SCORM 1.2/2004 LMS integration, multi-tenant hierarchy, assignment workflows, and an immutable audit log for QSA, SOC 2, and ISO audits.Starting Price: Contact us -
12
Remedio
Remedio
Remedio is an AI-powered, autonomous device posture management platform that continuously discovers, monitors, and remediates security misconfigurations and configuration drift across enterprise IT and OT environments to reduce attack surface, enforce compliance, and harden endpoint security without disruption. It delivers real-time visibility into configuration risks on devices running Windows, macOS, and Linux, as well as cloud instances and servers, and automatically applies safe remediation actions that are instantly reversible, giving security teams confidence when closing gaps without business impact. Remedio simplifies policy validation and enforcement by benchmarking settings against security standards such as CIS, NIST, and MITRE frameworks and continuously re-applies policies across updates, user changes, and new devices to maintain consistent secure baselines. It provides centralized control and governance of Active Directory, Group Policy, MDM, and Intune settings. -
13
BoxyHQ
BoxyHQ
Security Building Blocks for Developers. BoxyHQ offers a suite of open-source APIs for security and privacy, helping engineering teams build and ship compliant applications faster, reducing Time to Market without sacrificing their security posture. 1. Enterprise Single Sign On (SAML/OIDC SSO) 2. Directory Sync 3. Audit Logs 4. Data Privacy Vault (PII, PCI, PHI compliant)Starting Price: $0 -
14
AWS IAM Identity Center
Amazon
AWS IAM Identity Center simplifies centralized access management across multiple AWS accounts and business applications. It enables users to access assigned accounts and applications from a unified portal. Administrators can manage user permissions centrally, assigning them based on job functions and customizing as needed. IAM Identity Center integrates with various identity sources, including Microsoft Active Directory, Okta, Ping Identity, JumpCloud, and Microsoft Entra ID, and supports standards like SAML 2.0 and SCIM for user provisioning. It facilitates attribute-based access control by allowing selection of user attributes such as cost center, title, or locale from the identity source. It supports multi-factor authentication (MFA) using methods like FIDO-enabled security keys, biometric authenticators, and time-based one-time passwords. -
15
AIDevPortal
AIDevPortal
AIDevPortal is an AI automation platform for operational teams. It turns your own documents, policies, and rules into AI assistants and workflows your staff and customers use from day one: instant, source-cited answers with a clean hand-off to a human when needed; requests, approvals, and updates that move between your tools automatically with a full audit trail; and reports sent from live data on a schedule. The AI Onboarding Studio turns your website into a launch plan, and ready-made industry kits get teams live in about two weeks. Built for IT to trust: SSO/SCIM, your own encryption keys (BYOK), data residency, single-tenant isolation, audit logs, SOC 2 in progress, plus open APIs, webhooks, and SDKs. Works with Slack, Google Drive, Notion, and Confluence. -
16
AXYVOR
CipherThought Corp
AXYVOR is an AI-native cybersecurity platform that unifies exposure management, identity threat detection, adversary intelligence, attack path analysis, and executive risk reporting into a single system operated by AI. Built for mid-market and enterprise security teams, AXYVOR continuously maps attack paths across cloud, identity, and endpoint environments, prioritizes the vulnerabilities that create real business risk, and delivers an AI-generated Board Risk Index that translates technical findings into financial and operational impact for executives and boards. AXYVOR integrates natively with leading EDR, SIEM, identity, and ITSM tools (CrowdStrike, SentinelOne, Okta, Splunk, Microsoft Sentinel, and more), deploying in days instead of months, at a fraction of the cost of legacy platforms like CrowdStrike, Splunk, or Wiz.Starting Price: $2500 -
17
QRCodeStack
QRCodeStack
QRCodeStack is a QR code generation and management platform supporting 37+ QR code types including URL, PDF, vCard, WiFi, restaurant menu, UPI payment, Google Review, WhatsApp, and more. Users can create unlimited static QR codes for free without signup, or use dynamic QR codes that allow editing the destination URL after printing without reprinting. Each code can be customized with logos, brand colors, dot patterns, eye styles, and frame templates, then exported as high-resolution PNG or scalable SVG. Dynamic codes include real-time scan analytics tracking country, city, device, browser, and time. Additional capabilities include UTM tracking, retargeting pixel support, password protection, scan limits, and expiry dates. Higher-tier plans offer bulk QR code generation, REST API access with per-key scopes and IP allowlists, team workspaces with role-based access, SAML 2.0 SSO, SCIM provisioning, and audit logs. Integrations include Canva, Zapier, HubSpot, and Google Analytic.Starting Price: $5/month -
18
Pillar Security
Pillar Security
Pillar Security is a unified AI security platform for securing the agentic workforce across the entire AI lifecycle, from development to deployment and runtime protection. It connects business context across discovery, testing, and protection so security intelligence compounds across AI applications, agents, models, prompts, frameworks, tools, MCP servers, skills, coding agents, SaaS, cloud, code, and endpoints. Pillar helps organizations discover and manage AI assets everywhere, including shadow AI and unapproved systems, assess supply chain and posture risks, map agentic attack surfaces, and validate the vulnerabilities that actually matter. Its AI Security Posture Management capabilities analyze connected agents, tools, permissions, data sources, prompts, models, and supply chain components to expose risky paths, policy violations, misconfigurations, coding agent risks, and blast radius when a single component is compromised. -
19
Microsoft Intune
Microsoft
Transform IT service delivery for your modern workplace. Simplify modern workplace management and achieve digital transformation with Microsoft Intune. Create the most productive Microsoft 365 environment for users to work on devices and apps they choose, while protecting data. Securely manage iOS, Android, Windows, and macOS devices with a single endpoint management solution. Streamline and automate deployment, provisioning, policy management, app delivery, and updates. Stay up to date with a highly scalable, globally distributed cloud service architecture. Leverage the intelligent cloud for insights and baselines for your security policies and configuration settings. Help safeguard data when you don’t manage devices used by employees or partners to access work files. Intune app protection policies provide granular control over Office 365 data on mobile devices. -
20
Bionic
Bionic
Bionic uses an agentless approach to collect all of your application artifacts and provides a deeper level of application visibility that your CSPM tool cannot. Bionic continuously collects your application artifacts and creates an inventory of all of your applications, services, message brokers, and databases. Bionic integrates as a step in CI/CD pipelines and detects critical risks in the application layer and code, so teams can validate security posture in production. Bionic analyzes your code, performing checks for critical CVEs, and provides deeper insights into the blast radius of potential attacks surfaces. Bionic prioritizes code vulnerabilities based on the context of the overall application architecture. Create customized policies to prioritize architecture risk based on your company's security standards. -
21
AccessOwl
AccessOwl
AccessOwl is an Access Governance and SaaS management tool that simplifies the management of employee access to SaaS applications, from onboarding to offboarding. As the central hub for SaaS access, it eliminates the need to ask who manages specific tools or what approval is required, while tracking every app, user access, and permission used in the organization. AccessOwl automates user account provisioning, access requests, approvals, reviews, and Shadow IT detection, helping teams replace spreadsheets with a source of truth and reduce the risk of missed offboardings. It integrates with Slack so employees can request access directly where they already work, and HRIS integrations automate employee onboarding and offboarding while syncing employee details such as title, department, and manager. AccessOwl can provision and deprovision users across hundreds of SaaS applications without requiring SCIM or SAML.Starting Price: $4.50 per month -
22
Native
Native Security
Native is a cloud security control plane designed to help organizations define, implement, and enforce security policies across cloud environments, including modern AI infrastructure. It focuses on providing secure-by-design governance by enabling teams to control how AI services and cloud resources are provisioned, accessed, and managed within their infrastructure. It allows users to define desired security outcomes and automatically map them to the appropriate technical controls for each cloud provider, eliminating the need to manually interpret best practices or configure policies for every environment. Native offers end-to-end visibility and planning capabilities, including discovering assets, simulating changes, and implementing controls to reduce risk and contain potential impact across systems. It also supports advanced features such as environment segmentation, data perimeter protection, and blast radius containment. -
23
Aquera
Aquera
The Aquera Identity Integration Platform as a Service is a cloud-based service that provides SCIM gateway services for account provisioning and aggregation, orchestration services for user and password synchronization, workflow services for the governance of disconnected applications, password rotation gateway services for privileged account management, and an extensive supporting catalog of out-of-box connectors for cloud or on-premises applications. Out-of-the-box and built on-demand connectors are plug-n-play from identity management platforms, privileged account management platforms, or HR applications to any cloud or on-premises application, database, directory, device, or B2B portal. The identity integrations require zero coding and rapidly deploy in minutes. The platform features multi-purpose gateway services and out-of-the-box connectors for user provisioning/deprovisioning, HR application user onboarding/mastering, delta account aggregation, file operations, etc. -
24
Morpheus
Morpheus Data
Reduce cloud cost 30%, provision 150x faster, close security holes, and deploy hybrid-cloud automation in record time. Morpheus is a powerful self-service engine to provide enterprise agility, control, and efficiency. Quickly enable on-prem private clouds, centralize public cloud access, and orchestrate change with cost analytics, governance policy, and automation. Create private clouds, manage public clouds, and consolidate Kubernetes deployment. Provision applications from an on-demand catalog, API/CLI, ITSM, or infrastructure-as-code. Simplify authentication, establish access controls, set policies, and manage security posture. Automate lifecycles from cradle to grave, run workflows, and simplify day-2 actions. Inventory brownfields, rightsize resources, track cloud spend, and centralize visibility. -
25
Ivanti Connect Secure
Ivanti
Ivanti Connect Secure is a next-generation secure access solution built for distributed, cloud-first environments where performance and zero trust principles must work in tandem. Running on a hardened Oracle Linux foundation with SELinux enforcement, integrated web application firewall, and Secure Boot with Trusted Platform Module key management, ICS delivers enterprise-grade remote connectivity without compromising your security posture. A unified client handles both remote and on-site access, reducing client sprawl while supporting Layer 3/4 VPN, per-app VPN, and clientless HTML5 access in a single platform. Dynamic role mapping, real-time device and identity verification, and adaptive multi-factor authentication help ensure that every session is continuously evaluated against granular policy, not just at login. Native integrations with security information and event management, next-generation firewall, mobile device management, and identity providers like Okta and Azure AD preserve -
26
Change Manager for Group Policy/Intune
SDM Software, Inc.
Change Manager for Group Policy/Intune brings modern change control and governance to customers that rely on Windows Group Policy and Intune day in and day out. Securely delegate access to GPO editing, container linking and Intune profiles and their assignments, with approval-based workflows. View differences and search for settings between versions of GPOs, containers and Intune profiles and rollback, undelete or schedule deployment of changes–all from a modern web interface. Whether you are new to GPO (and Intune) Change Control or looking for an alternative to Advanced Group Policy Management (AGPM), CMGPI can meet your needs. Bring Security and Governance to your Windows configuration environments.Starting Price: based on active computers -
27
SurePassID
SurePassID
SurePassID is an advanced, deploy-anywhere multi-factor authentication platform built to secure both IT and OT (operational technology) environments, including critical infrastructure, legacy systems, on-premise, air-gapped, hybrid cloud, or fully cloud-based operations. It supports a wide variety of authentication methods; passwordless, phishing-resistant approaches like FIDO2/WebAuthn (with FIDO2 PIN, biometric, or push), as well as one-time passwords (OTP via OATH HOTP/TOTP), mobile push, SMS, voice, and traditional methods. SurePassID integrates with common operating systems, including domain and local logins, RDP/SSH remote access, and even legacy or embedded Windows systems often found in OT/ICS/SCADA environments, enabling offline 2FA when needed. It also supports securing VPNs, network devices, appliances, legacy applications, web apps (via SAML 2.0 or OIDC identity provider functionality), and network-device access protocols.Starting Price: $48 per year -
28
Nitric
Nitric
Nitric is an open source, cloud-agnostic backend framework that enables developers to declare infrastructure as code and automate deployments using pluggable plugins. It supports multiple languages, including JavaScript, TypeScript, Python, Go, and Dart. Key features include defining APIs (REST, HTTP), serverless functions, routing, authentication/authorization (OIDC-compatible), storage (object/file storage, signed URLs, bucket events), databases (e.g., managed Postgres with migrations), messaging (queues, topics, pub/sub), websockets, scheduled tasks, and secrets management. Nitric integrates with tools like Terraform or Pulumi, or lets you write your own plugins, and works with major cloud providers (AWS, Azure, Google Cloud). It also supports local development with simulated cloud environments so you can prototype, test, and iterate without incurring cloud cost. The framework emphasizes declarative security, resource access management, and portability.Starting Price: Free -
29
Bijira
WSO2
WSO2 Bijira is an AI-native, cloud-native SaaS API management platform built to manage the full lifecycle of APIs, including design, security, governance, deployment, and monitoring, across internal, external, egress, and AI-driven APIs in hybrid and multi-cloud environments. It provides a unified control plane for consistent API policy, security, and analytics while supporting visual API proxy mapping, drag-and-drop policy management, and a customizable developer portal to accelerate API adoption and reuse. Bijira leverages AI tools to help generate OpenAPI specs, test APIs using natural language prompts, validate compliance with governance rules, and feed insights back into the API development process. It integrates robust security mechanisms, including OAuth2, OIDC, fine-grained access control, and firewall protections, and enforces governance-as-code with AI-assisted policy validation. -
30
Bearer
Bearer
Automate GDPR compliance by implementing Privacy by Design into your product development processes. Bearer helps you proactively find and fix data security risks and vulnerabilities across your application environment so you can prevent data breaches before they happen. Bearer helps security and development teams implement and monitor their data security policy at scale so they can prevent data breaches. Scan your applications and your infrastructure continuously to map sensitive data flows. Identify, prioritize and assess security risks and vulnerabilities that can lead to a data breach. Monitor your data security policy and empower your developers to fix issues on their own. Bearer’s detection engine supports 120+ data types, including personal, health and financial data, and adapts to your data taxonomy. -
31
OmniDefend
Softex
OmniDefend secures your employees, contractors and vendors by using strong authentication and universal single sign-on to access and secure business applications and processes. OmniDefend eliminates customer fraud by using multi-factor authentication to identify and secure customer transactions online or on-premise. OmniDefend allows you to quickly add authentication to your website so you can deliver a password-less experience for your customers and secure e-commerce transaction. When it comes to security, OmniDefend implements standards that have been proven in the industry. OmniDefend supports OpenId, OAuth 2.0, and SAML for maximum compatibility and security for single-sign on applications. SCIM 2.0 allows OmniDefend to work seamlessly alongside identity management and user provisioning. -
32
Acceptto eGuardian
Acceptto
Acceptto monitors user behavior, transactions, and application activity to create an enriched user profile within each application landscape and subsequently verify if access attempts are legitimate or a threat. No passwords or tokens are required. Acceptto’s risk engine calculates whether an access attempt is legitimate or not by tracking user and device posture pre-authentication, during authentication, and post-authorization. We deliver a continuous, step-up authentication process with real-time threat analytics in an age when identities are persistently under attack. Based on a risk score computed by our proprietary AI/ML algorithms, a dynamic level of assurance (LoA) is computed. Our approach automatically finds the optimal policy for each transaction to maximize security while minimizing friction for the user with machine learning and AI analytics. This provides a smoother user experience without sacrificing enterprise security. -
33
SurePath AI
SurePath AI
Ensure AI use adheres to corporate policy with our simple-to-implement AI governance control plane. Remove complexity, gain visibility, and securely increase AI adoption, with SurePath AI. Native integrations to your existing security solutions, private models, and enterprise data sources. SSO, SCIM, and SIEM are natively supported. Detect AI use at a network level. Control access and inspect requests for sensitive data leaks. Redact sensitive data found in requests to public models. In-line modification of requests enables productivity while mitigating risk. Redirect traffic to your private AI models. Leverage SurePath AI's private model access controls as your own internally branded enterprise AI portal. Policy-based controls enrich requests with only the enterprise data users are granted access to, giving meaningful responses based on relevant business context. Users' prompts are automatically enhanced to align output to enterprise objectives. -
34
TozID
Tozny
An SSO and Customer Identity Management platform with privacy and end-to-end encryption built in. Centralize Access Control without centralizing your security risk. Our cryptography-at-the-edge approach delivers identity protection where you need it – secure your customer’s accounts with strong encryption and a customizable UI, or streamline protected access for your business and employees with SSO. All the features you expect – including SAML & OIDC support along with push-based MFA and more. Here are a few key features we think you’ll love! Administrators have the keys to the kingdom. Moving to zero-trust means protecting admin accounts from hacks and malicious insiders. Tozny's Privileged Access Manager (PAM) is built directly into our single sign-on solution. Get advanced protection for any endpoint and any 3rd party with Tozny PAM. -
35
XFA
XFA
XFA is a device security and Zero Trust access platform that helps organizations discover, assess, and enforce security posture on every device accessing business systems, including BYOD, contractor, and unmanaged endpoints, by integrating with identity providers and checking key security settings such as OS updates, encryption and other posture signals at login without taking control of devices or requiring traditional MDM deployment; it gives real-time visibility into all connected devices, boosts security awareness with alerts and reports, enables conditional access policies so only compliant devices can access cloud tools, and helps teams meet compliance frameworks like SOC 2, ISO 27001 and NIS2 with audit-ready evidence, while offering friction-free self-onboarding, lightweight installation, agentless capabilities and integrations with platforms like Microsoft 365, Okta, TrustCloud and Drata to strengthen security across hybrid, remote and BYOD environments.Starting Price: €2,450 per year -
36
Better Auth
Better Auth
Better Auth is a framework-agnostic authentication and authorization framework for TypeScript designed to help developers implement secure login systems directly within their own applications and databases. It provides a full set of authentication features out of the box, including email and password login, session management, email verification, password reset, and support for over 40 social login providers such as Google, GitHub, etc., all configurable with minimal code. It is built to work with a wide range of modern frameworks like Next.js, Nuxt, SvelteKit, Astro, and Express, allowing teams to integrate authentication regardless of their tech stack while maintaining strong TypeScript support and type safety. Better Auth includes advanced capabilities such as multi-factor authentication, multi-tenant organization management, and enterprise features like SSO, SAML, and SCIM provisioning, making it suitable for both simple apps and large-scale systems.Starting Price: Free -
37
ClearPass
Alcatel-Lucent Enterprise
Easily roll out BYOD services and control devices on your enterprise network with powerful network policy management. Create and enforce policies across devices and apps with the ClearPass Policy Management System. ClearPass gives you total control over your enterprise network, offering a simpler way to roll out BYOD services. You’ll be able to offload routine tasks to users through guest self-registration portals and self-service employee portals. And leverage contextual data about user roles, devices, application use, location and time of day to streamline network operations across your networks and VPNs.Create and enforce policies across your entire network. Enable users to provision and register their own devices. Use a single view to manage policies, on-board devices, admit users, manage apps and more. Advanced endpoint posture assessments and health checks ensure security compliance and network protection before devices connect and while connected. -
38
Citrix Secure Private Access
Cloud Software Group
Citrix Secure Private Access (formerly Citrix Secure Workspace Access) provides the zero trust network access (ZTNA) your business needs to stay competitive, with adaptive authentication and SSO to IT sanctioned applications. So you can scale your business and still meet today’s modern security standards—without compromising employee productivity. With adaptive access policies based on user identity, location, and device posture, you can continually monitor sessions and protect against threats of unauthorized login from BYO devices—all while delivering an exceptional user experience. And with integrated remote browser isolation technology, users can securely access apps using any BYO device—no endpoint agent needed.Starting Price: $5 per user per month -
39
Tuebora
Tuebora
Natural language user interface eliminates UI adoption risks. Complete deployment in just a few weeks. Augment or replace with only the microservices you need. Fast-build SCIM compliant connectors. Design new IAM processes that fit your organization. Machine learning pinpoints errors and finds efficiencies. Support your “Cloud-first” strategy. Built for the cloud to control identity everywhere. Smart Businesses Rely on Tuebora’s platform of identity solutions to unlock business value and reduce risk. Use our Natural Language User Interface to communicate hundreds of IAM scenarios to your business applications. Suddenly, your IAM processes are natural, fast and agile. Our implementation of machine learning identifies unused account access and provisioning activities performed outside established processes. Rapid adoption of cloud applications requires managing identity everywhere. Traditional vendor solutions don’t natively support cloud identity needs. -
40
Diffchecker
Diffchecker
Diffchecker is a file and document comparison tool for text, code, PDFs, Word documents, Excel spreadsheets, PowerPoints, images, and folders. Diffchecker's free online tool is built for collaboration. It runs in any browser with no sign-up and lets users save diffs online, share them by link, and leave line-by-line comments. Diffchecker Desktop is built for confidential work and is the stronger choice for compliance-sensitive workflows. It runs fully offline on Windows, Mac, and Linux, so files never leave the device. That makes it a private, secure choice for redlining legal contracts and other confidential documents. Diffchecker shows precise changes down to the word and character, with professional legal redlining, PDF and Word export, OCR for scanned documents, and pixel-by-pixel image differences. The Legal plan adds iManage integration, and the Enterprise plan adds SAML single sign-on and SCIM provisioning. Plans start free, with Pro+Desktop from $15 per user per month.Starting Price: $15 per month -
41
Datica
Datica
Automatically provision and configure AWS to meet compliance targets – including your account, environments, and cloud resources. Seamless integration with CI/CD best practices. Simply connect your code pipelines and repository to get deploying. Security policy guidelines, automated remediation, and evidence collection streamline annual audit activities. Reduced expertise, time, and expense associated with security and compliance attestation/certification. Provision, scale, and deploy compliant services via platform or API without having to think about hundreds of compliance rules and configurations. Code service management and deployment pipelines make pushing your code to container images effortless. Intuitive UI for application management provides a simple way for teams to stay on top of how code intersects with your cloud services. -
42
Port0
Port0
Port0 is a cutting-edge network security platform designed to enhance visibility, control, and segmentation within complex organizational networks, providing a seamless, integrated experience with endpoint security solutions like SentinelOne. At its core, Port0 aims to empower security teams by bridging the gap between endpoint protection and network-wide security, offering complete situational awareness, simplified threat management, and a Zero Trust-aligned micro-segmentation model. -
43
6connect
6connect
Revolutionary network automation & provisioning for ISP's and enterprises around the world. Easy to deploy and integrate with, whether you use the 6connect cloud or deploy ProVision behind the firewall. Regain your sanity. Avoid the costly pitfalls of ad hoc solutions and manual network resource management. Global resource management, complete IPAM automation, easy management of DNS, DNSSEC, and DHCP. Flexible data model that seamlessly supports multi-tenant permissions, works with RADIUS, LDAP, 2FA, SAML2. Integrates, synchronizes and automates workflows over a dozen DNS platforms. Also makes migrations a snap! Easy DHCP configuration and scope management that integrates with other systems. From allocation to assignment, from CGN to IPv6, ProVision knows how to handle IPs. Carrier-grade API for easy integration across global system, fast, well documented and tested. Easy to use Peering workflows built-in – from email to BGP config pushes to reporting, it’s all there. -
44
Scalefusion OneIdP
Scalefusion OneIdP
Scalefusion OneIdP is a Zero Trust access solution that brings together Identity & Access Management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, Just-In-Time (JIT) admin access, and more into a single platform. It secures every access request by combining identity verification with real-time device posture checks, ensuring only verified users on compliant devices can access critical resources. With centralized user lifecycle management, automated provisioning, and unified policy controls. OneIdP simplifies onboarding, strengthens access governance, and reduces IT overhead, while delivering a consistent, secure login experience across enterprises. -
45
AuthN by IDEE
IDEE
Award winning, Enterprise-wide, Zero Trust Authentication as a Service. AuthN™ by IDEE eliminates all password based risks and reduces the cost of administrative overhead. Your fastest time to market for your transition to passwordless across the enterprise. AuthN™ is interoperable and can be deployed in addition to your existing SSO, hardware-token and password-management investments. Whether stand-alone or integrated, realize a tangible reduction of your risk exposure by completely removing the password. Insider threats and human errors are also reduced with no central credential databases of any kind. Our completely passwordless multi-factor authentication can keep your attackers at bay and keep you out of the headlines of tomorrow. Your favorite applications, SSO and password managers receive a plug & play security upgrade. AuthN™ supports open standards (e.g. RADIUS, SAML, OIDC) and offers custom plugins to help you leverage the additional benefits of AuthN™.Starting Price: €3 per user per month -
46
Stream Security
Stream Security
Stay ahead of exposure risks & threat actors with real-time detection of config change impacts and automated threat investigations fused to posture and all activities. Track all changes, and detect critical exposure and toxic combinations before attackers do. Leverage AI to effectively address and fix issues using your preferred methods. Utilize any of your preferred SOAR tools to respond in real time or use our suggested code snippets. Harden and prevent external exposure & lateral movement risks, focus on risks that are truly exploitable. Detect toxic combinations of posture and vulnerabilities. Detect gaps from segmentation intent and implement zero-trust. Answer any cloud-related question fast with context. Maintain compliance, and prevent deviation from taking hold. We integrate with your existing investment. We can share more about our security policies and work with your security teams to deliver any specific requirements for your organization.Starting Price: $8,000 per year -
47
Craftifact
SoluForge
Craftifact is a European artifact repository SaaS for software teams that need reliable package distribution together with supply-chain visibility. It provides hosted, proxy, and group repositories for Maven, npm, Python, OCI/Docker, and Go, with browser-based artifact metadata and repository management. CycloneDX SBOMs can be uploaded and, for selected hosted content, generated and linked to artifacts or OCI digests. Teams can inspect dependencies and review vulnerability, license, exposed-secret, and policy signals close to the affected artifact. Access is controlled through OIDC, RBAC, groups, robot accounts, and scoped tokens, with APIs for CI/CD and evidence workflows. Craftifact is operated in Europe by a German company under EU jurisdiction and includes managed updates, monitoring, backups within plan scope, and predictable non-seat-based pricing. It supports CRA-relevant technical preparation but does not replace legal or conformity assessment.Starting Price: €99/month -
48
Secure remote access to your ICS and OT assets, and easily enforce cybersecurity controls at scale with our zero-trust network access solution made for industrial networks and harsh environments. Securing remote access to operational technology assets has never been easier, or more scalable. Operate with better efficiency and get peace of mind with Cisco Secure Equipment Access. Empower your operations team, contractors, and OEMs to remotely maintain and troubleshoot ICS and OT assets with an easy-to-use industrial remote access solution. Configure least-privilege access based on identity and context policies. Enforce security controls such as schedules, device posture, single sign-on, and multifactor authentication. Stop struggling with complex firewalls and DMZ setups. Secure Equipment Access embeds ZTNA into your Cisco industrial switches and routers so you can reach more assets, reduce the attack surface, and deploy at scale.
-
49
Identity Confluence
Tech Prescient
Identity Confluence is an intelligent Identity Governance and Administration (IGA) platform designed to help IT and security teams manage access, automate identity lifecycles, and maintain continuous compliance across cloud and hybrid environments. Built for modern enterprises, Identity Confluence unifies identity lifecycle management, access control, and governance into a single, scalable platform. Automate Joiner-Mover-Leaver (JML) processes, enforce policy-based access controls (RBAC, ABAC, PBAC), and conduct real-time user access reviews—all from one intuitive interface. Key Features: Lifecycle Automation: Trigger real-time provisioning and deprovisioning across HR, IT, and business systems. Access Controls: Implement dynamic, fine-grained access policies using roles, attributes, and policies. App & Directory Integrations: Out-of-the-box connectors for AD, Azure AD, Okta, Workday, SAP, and more. Access Reviews: Automate certifications, enforce Segregation of Duties -
50
OpenText Hybrid Cloud Management X
OpenText
OpenText™ Hybrid Cloud Management X (HCMX) delivers total visibility and operational consistency across all your clouds. Now you can optimize cloud spend based on actionable insights, enable easy self-service that includes compliance guardrails, and orchestrate lifecycle management actions. Improve multicloud spend transparency, get smart cost-cutting recommendations, and prevent budget overruns with spend limits, alerts, and accurate allocations. Maintain a strong security and compliance posture—with policies, approval flows, and rules—while enabling flexible self-service provisioning for developers. Easily deploy hybrid cloud across your IT ecosystem—build private clouds, consolidate public cloud access—and gain on-demand agility with lifecycle automation.