Control plane · Identity · Access · HA · CDN · Security ops

One plane for people, machines, and every request

0Trust is the full stack: passkeys and OIDC, SCIM directory sync, policy-gated access and private mesh, anycast high availability with same-hostname rollover and no DNS surgery, a content CDN, Orchid logs and workflows, and SIEM/SOAR built into the same plane. One product instead of five.

OIDC issuerhttps://0trust.cloud·openid-configuration

The whole product

Identity, directory, access, high availability, content delivery, and security ops ship together as one product.

Identity

Passkeys, OIDC, DBSC sessions, tenants, and federation for humans and machines.

Directory

SCIM 2.0 Users and Groups, inbound and outbound, with a built-in application gallery.

Access

ZTNA proxy, mesh tunnels, policy engine, SSH and Kubernetes on the same identity.

Security ops

Orchid ingest and BM25 search, hot/cold logs, workflows, and built-in SIEM/SOAR. HA and CDN keep delivery online.

Hosted IdP
Sign up free
SCIM 2.0
Users + Groups
Anycast HA
No DNS surgery
Content CDN
0trust.social
SIEM / SOAR
Built in

Identity

Hosted issuer at 0trust.cloud. App faces at {app}.0trust.cloud. SDKs and app registration on 0trust.codes.

🔐

OIDC provider

Discovery, authorize, token, JWKS, revoke, userinfo. Authorization code + PKCE and refresh tokens.

🔑

Passkeys and enrollment

WebAuthn login. Invite enrollment with TOTP before policy grants activate.

📱

Device-bound sessions

DBSC after passkey: sessions tied to the device, not a cookie alone.

📦

Apps and clients

OIDC relying parties, IAM catalog, assignments, RBAC and ABAC policy grants.

🤝

Federation

Cross-product assertions and social or domain identity modes for apps.

🏢

Tenants

Company registration, approvals, member invites, tenant admin portal.

👩‍💻

Developer platform

0trust.codes: create apps, copy credentials, Go / JS / Python SDKs. Same issuer.

IAM console

Manage clients, grants, and catalog apps as an operator.

Directory and provisioning

SCIM 2.0 as infrastructure on your plane, not a paid add-on for each connector.

Bidirectional SCIM

Inbound /scim/v2 with Bearer auth for workforce IdPs and HRIS. Outbound provision when access is assigned.

👥

Users and Groups

Full User and Group CRUD, filters, and member patch for push-group style sync.

Application gallery

Built-in tiles for common identity sources, collaboration apps, cloud admin planes, and custom SCIM 2.0 endpoints.

🧭

SCIM console

Inbound tokens, gallery install, outbound endpoints, and provision audit at /scim.

📖

Migration guide

Dual-run cutover from paid directory brokers. Attribute maps and smoke tests.

Open SCIM

Sign in to enable inbound, install gallery tiles, and wire outbound apps.

Secure access and mesh

Protect localhost and mesh services with policy on every hop, without opening a flat network.

🛡️

ZTNA HTTP proxy

/access/{app} with the policy engine and allowed_roles on every request.

🔒

DBSC gate

Human paths require device-bound sessions before app traffic is proxied.

🕸️

Mesh access

0trust.services: peers, agent tunnels, DoH, and policy shell.

🚀

One-command deploy

Agent beside your app, subdomain routing, auto-provision, tunnel control.

⌨️

SSH and Kubernetes

Operator protocol paths on the same identity and policy stack.

🤖

Machine identity

Service keys, hardware proofs, mesh join, peer topology.

📜

PKI and DNS

ACME inventory, mesh CA, authoritative DNS, private TLDs and product zones.

Anycast HA + CDN

Same-hostname rollover without DNS surgery, and content delivery on 0trust.social.

📦

Self-host container

Run the full control plane from the container hub: images, registry, deploy.

High availability and content delivery

Stay on the same hostname when sites fail over. Deliver media from a first-party content plane.

Anycast HA

Edge and standby planes advertise the same service face. Clients keep one URL while traffic lands on a healthy site.

No DNS surgery

Same-hostname rollover restores barge state from upstream snapshots. Promote and demote without rewriting public DNS for each product.

Upstream snapshots

Product barges push data and full packs to the services plane so standby stays warm for cutover.

🌐

Content CDN

0trust.social serves content-addressed media at /c/{id}: hot blobs, cold archive, range requests for video, embed-ready delivery.

📦

Private object store

Per-user private buckets and CRDT-friendly paths on the social plane, with the public CDN for shareable media.

🛰

Standby plane

0trust.services is mesh access and the standby site for rollover. One operator model for primary and failover.

SIEM / SOAR on Orchid_Sync

Built into the control plane. Detections run on the same BM25 log index as identity, access, SCIM, and product shippers.

Realtime correlator

Every log write is evaluated. Match service, level, action, message, fields, and threshold windows with group-by.

📋

Incidents

Open cases with evidence document IDs. Coalesce repeats. Ack, investigate, contain, resolve, or mark false positive.

🤖

SOAR playbooks

Webhook notify, enqueue workflows, enrich via Orchid BM25, annotate the SIEM audit trail.

📦

Builtin detections

Auth failure bursts, ZTNA deny, SCIM abuse, privileged admin actions, ERROR spikes, workflow alerts.

🔗

Same plane as the rest

Identity, directory, access, and security ops share one operator surface. No separate SIEM product to wire.

Open SIEM console

Review rules, open incidents, test inject, and manage playbooks at /siem.

Observability and automation

Ship events once. Search them. Retain what matters. Automate. SIEM runs on this same index.

📥

Log ingest

API-key sources, bulk ingest, and product orchid_log shippers from every barge.

🔎

Orchid BM25 search

Okapi BM25 over hot storage for access, identity, SCIM, and product events.

🗄️

Hot and cold retention

Hot path for investigation, cold archive, purge, and repeat dedupe.

📡

Live tail

Operator tail while you debug access, deploy, or identity issues.

⚙️

Workflows

DAG pipelines, schedules, webhooks, secrets, multi-tenant automation.

🛡

SIEM / SOAR

Built-in realtime detection on the Orchid index: incidents, playbooks, enrich, and notify.

Logs explorer

Query and browse platform logs with the operator explorer.

Workflows console

Build and run ETL pipelines on the same plane.

Three paths to production

Hosted control plane, self-hosted container stack, or SDKs for the apps you ship.

🪪

Use 0Trust as your identity provider

Register your organization. Passkeys, OIDC apps, SCIM, access, logs, and SIEM/SOAR on the hosted plane without standing up infrastructure first.

Start registration
📦

Self-host as a container

Run the full control plane on your infrastructure: container images, registry, and deploy tooling via the hub.

Open the container hub
👩‍💻

Build with the developer platform

Integrate passkeys and OIDC in any language. Create applications, copy credentials, ship against the cloud issuer.

Visit 0trust.codesOpen console

Domains

0trust.cloud

  • OIDC issuer and operator plane
  • IAM, SCIM, ZTNA, SIEM/SOAR, logs, workflows
  • Anycast HA and same-hostname rollover
  • Company signup at /start

0trust.codes

  • Developer marketing and console
  • App registration wrappers
  • Go · JS · Python SDKs

0trust.services

  • Mesh access and DoH
  • Standby plane for rollover
  • Upstream snapshot store

0trust.social

  • Content CDN /c/{id}
  • Private user object buckets
  • Hot and cold media tiers

tunneltug.com/hub

  • Container self-host
  • Image registry and deploy
  • Public haul tooling

Stand up the full control plane

Adopt as your identity providerSelf-host as a containerBuild with our developer platformOperator sign in