0Trust is the full stack: passkeys and OIDC, SCIM directory sync, policy-gated access and private mesh, anycast high availability with same-hostname rollover and no DNS surgery, a content CDN, Orchid logs and workflows, and SIEM/SOAR built into the same plane. One product instead of five.
Identity, directory, access, high availability, content delivery, and security ops ship together as one product.
Passkeys, OIDC, DBSC sessions, tenants, and federation for humans and machines.
SCIM 2.0 Users and Groups, inbound and outbound, with a built-in application gallery.
ZTNA proxy, mesh tunnels, policy engine, SSH and Kubernetes on the same identity.
Orchid ingest and BM25 search, hot/cold logs, workflows, and built-in SIEM/SOAR. HA and CDN keep delivery online.
Hosted issuer at 0trust.cloud. App faces at {app}.0trust.cloud. SDKs and app registration on 0trust.codes.
Discovery, authorize, token, JWKS, revoke, userinfo. Authorization code + PKCE and refresh tokens.
WebAuthn login. Invite enrollment with TOTP before policy grants activate.
DBSC after passkey: sessions tied to the device, not a cookie alone.
OIDC relying parties, IAM catalog, assignments, RBAC and ABAC policy grants.
Cross-product assertions and social or domain identity modes for apps.
Company registration, approvals, member invites, tenant admin portal.
0trust.codes: create apps, copy credentials, Go / JS / Python SDKs. Same issuer.
Manage clients, grants, and catalog apps as an operator.
SCIM 2.0 as infrastructure on your plane, not a paid add-on for each connector.
Inbound /scim/v2 with Bearer auth for workforce IdPs and HRIS. Outbound provision when access is assigned.
Full User and Group CRUD, filters, and member patch for push-group style sync.
Built-in tiles for common identity sources, collaboration apps, cloud admin planes, and custom SCIM 2.0 endpoints.
Inbound tokens, gallery install, outbound endpoints, and provision audit at /scim.
Dual-run cutover from paid directory brokers. Attribute maps and smoke tests.
Sign in to enable inbound, install gallery tiles, and wire outbound apps.
Protect localhost and mesh services with policy on every hop, without opening a flat network.
/access/{app} with the policy engine and allowed_roles on every request.
Human paths require device-bound sessions before app traffic is proxied.
0trust.services: peers, agent tunnels, DoH, and policy shell.
Agent beside your app, subdomain routing, auto-provision, tunnel control.
Operator protocol paths on the same identity and policy stack.
Service keys, hardware proofs, mesh join, peer topology.
ACME inventory, mesh CA, authoritative DNS, private TLDs and product zones.
Same-hostname rollover without DNS surgery, and content delivery on 0trust.social.
Run the full control plane from the container hub: images, registry, deploy.
Stay on the same hostname when sites fail over. Deliver media from a first-party content plane.
Edge and standby planes advertise the same service face. Clients keep one URL while traffic lands on a healthy site.
Same-hostname rollover restores barge state from upstream snapshots. Promote and demote without rewriting public DNS for each product.
Product barges push data and full packs to the services plane so standby stays warm for cutover.
0trust.social serves content-addressed media at /c/{id}: hot blobs, cold archive, range requests for video, embed-ready delivery.
Per-user private buckets and CRDT-friendly paths on the social plane, with the public CDN for shareable media.
0trust.services is mesh access and the standby site for rollover. One operator model for primary and failover.
Built into the control plane. Detections run on the same BM25 log index as identity, access, SCIM, and product shippers.
Every log write is evaluated. Match service, level, action, message, fields, and threshold windows with group-by.
Open cases with evidence document IDs. Coalesce repeats. Ack, investigate, contain, resolve, or mark false positive.
Webhook notify, enqueue workflows, enrich via Orchid BM25, annotate the SIEM audit trail.
Auth failure bursts, ZTNA deny, SCIM abuse, privileged admin actions, ERROR spikes, workflow alerts.
Identity, directory, access, and security ops share one operator surface. No separate SIEM product to wire.
Review rules, open incidents, test inject, and manage playbooks at /siem.
Ship events once. Search them. Retain what matters. Automate. SIEM runs on this same index.
API-key sources, bulk ingest, and product orchid_log shippers from every barge.
Okapi BM25 over hot storage for access, identity, SCIM, and product events.
Hot path for investigation, cold archive, purge, and repeat dedupe.
Operator tail while you debug access, deploy, or identity issues.
DAG pipelines, schedules, webhooks, secrets, multi-tenant automation.
Built-in realtime detection on the Orchid index: incidents, playbooks, enrich, and notify.
Query and browse platform logs with the operator explorer.
Build and run ETL pipelines on the same plane.
Hosted control plane, self-hosted container stack, or SDKs for the apps you ship.
Register your organization. Passkeys, OIDC apps, SCIM, access, logs, and SIEM/SOAR on the hosted plane without standing up infrastructure first.
Start registrationRun the full control plane on your infrastructure: container images, registry, and deploy tooling via the hub.
Open the container hubIntegrate passkeys and OIDC in any language. Create applications, copy credentials, ship against the cloud issuer.