Access control you can set up without an IAM team.
At 20 to 100 people, security usually belongs to a founder or the first infrastructure engineer. Bastyx is designed so that one person can give everyone passwordless access to laptops, servers and apps, and take it back in one step.
Concept UI with sample data. The product is in development and details will change.
Where you probably are
Access grew faster than the process around it.
Contractors got SSH keys. Early engineers have admin everywhere. The password manager has a vault called “misc”. It worked when you were ten people. It won’t survive your first enterprise security questionnaire.
Passwordless from day one
New hires enroll a laptop and a passkey or security key. There’s no password to set, share or reset.
Servers without key sprawl
Engineers reach servers with a key touch. Nothing gets copied into authorized_keys.
Offboarding in one step
Laptops, SSH, cloud and apps, revoked together, with a record you can show.
Policies you can read
Start with a handful of team-based rules. Add step-up for production when you need it.
Works with what you have
Keep your identity provider. Bastyx is designed to sit alongside it.
Nothing to specialize in
Designed to be run by a busy CTO, not a dedicated identity team.
Security reviews
Better answers for your customers’ security questionnaires.
The questions enterprise buyers ask about access are predictable. Bastyx is designed to make the honest answer a good one.
Planned Capabilities described are planned.
- “Is multi-factor authentication enforced for all employees?”
- Passkeys and security keys are phishing-resistant by design, and they’re the only way in.
- “How do you remove access when someone leaves?”
- One offboarding action, with a record of every access path it closed.
- “Who has access to production, and how is it granted?”
- Policies you can show, with temporary access that expires and approvals on record.
- “How are SSH keys managed?”
- No long-lived keys on servers. Access is issued per session and logged.
Get access under control before it gets harder.
Early access is open to technical teams of 20–500 people. It takes a minute to apply.