0Trust.Cloud is the control plane for people, machines, and every request: passkeys and OIDC, SCIM directory, zero-trust access and mesh, log ingest and Orchid search, workflows, and built-in SIEM/SOAR — not a bolt-on afterthought.
Identity who connects. Control what they reach. See everything that happened — and act on it.
Passkeys, OIDC, SCIM directory, tenants, and federation for humans and machines. Hosted issuer on 0trust.cloud.
Zero-trust app proxy, VPN, Shield, policy engine, SSH and Kubernetes — same identity on every hop.
Log ingest from every barge, Orchid BM25 search, hot/cold retention, live tail, workflows, and SIEM/SOAR on the same index.
Hosted issuer at 0trust.cloud. App faces at {app}.0trust.cloud. SDKs and app registration on 0trust.codes.
Discovery, authorize, token, JWKS, revoke, userinfo. Authorization code + PKCE and refresh tokens.
WebAuthn login. Invite enrollment with TOTP before policy grants activate.
DBSC after passkey: sessions tied to the device, not a cookie alone.
OIDC relying parties, IAM catalog, assignments, RBAC and ABAC policy grants.
Cross-product assertions and social or domain identity modes for apps.
Company registration, approvals, member invites, tenant admin portal.
0trust.codes: create apps, copy credentials, Go / JS / Python SDKs. Same issuer.
Manage clients, grants, and catalog apps as an operator.
SCIM 2.0 as infrastructure on your plane, not a paid add-on for each connector.
Inbound /scim/v2 with Bearer auth for workforce IdPs and HRIS. Outbound provision when access is assigned.
Full User and Group CRUD, filters, and member patch for push-group style sync.
Built-in tiles for common identity sources, collaboration apps, cloud admin planes, and custom SCIM 2.0 endpoints.
Inbound tokens, gallery install, outbound endpoints, and provision audit at /scim.
Dual-run cutover from paid directory brokers. Attribute maps and smoke tests.
Sign in to enable inbound, install gallery tiles, and wire outbound apps.
Protect apps and services with policy on every hop — identity and device bind, not a flat network.
Proxy apps at /access/{app} with role and policy checks on every request.
Human paths require a passkey-bound session before traffic is proxied to the app.
Private L3 VPN and privacy DNS/egress on 0trust.services — dial-only, session gated.
Development to global haul is TunnelTug — fleets, anycast, and container hub.
Operator protocol paths on the same identity and policy stack.
Service keys, hardware proofs, mesh join, and peer topology.
ACME inventory, mesh CA, and certificates managed with the rest of the plane.
Multi-site high availability with same-hostname rollover to warm standby.
Run the full control plane from the container hub: images, registry, deploy.
Linux policy and provisioning agent that enforces mesh grants on the node.
VPN, Shield, and ZTNA — private access plane for the stack.
Stay online when a site fails. Deliver media from a first-party content plane.
Edge and standby planes share the same public hostnames. Clients keep one URL while traffic lands on a healthy site.
Promote and demote capacity from warm standby without a messy cutover. Snapshots keep product state ready.
Product services push data packs upstream so standby stays warm and restore is predictable.
0trust.social serves media at /c/{id}: hot blobs, cold archive, range requests for video, embed-ready delivery.
Per-user private buckets on the social plane, with the public CDN for shareable media.
0trust.services is VPN, Shield, and the standby site for rollover. One operator model for primary and failover.
Ingest once from every product barge. Search with Orchid BM25. Retain hot and cold. Automate with workflows. SIEM/SOAR runs on the same index — not a separate product to wire.
API-key sources, bulk ingest, and orchid_log shippers from every barge. Identity, access, SCIM, and product events land here.
Okapi BM25 over hot storage. Query access denials, auth spikes, SCIM changes, and product ERROR storms in one place.
Hot path for investigation, cold archive, purge, and repeat dedupe so volume stays usable.
Operator tail while you debug access, deploy, identity, or product issues.
DAG pipelines, schedules, webhooks, secrets, multi-tenant automation on the same plane.
No side SIEM stack. Operators use one surface for who, what, and what happened.
Query and browse platform logs with the operator explorer.
Ingest sources, search, and retention controls.
Build and run automation pipelines.
Built into the control plane. Every log write is evaluated. Detections, incidents, and playbooks share the same BM25 index as identity, access, SCIM, and product shippers.
Match service, level, action, message, fields, and threshold windows with group-by as events arrive.
Open cases with evidence document IDs. Coalesce repeats. Ack, investigate, contain, resolve, or mark false positive.
Webhook notify, enqueue workflows, enrich via Orchid BM25, annotate the SIEM audit trail.
Auth failure bursts, ZTNA deny, SCIM abuse, privileged admin actions, ERROR spikes, workflow alerts.
SIEM/SOAR ships with the plane. No separate product to license, wire, or federate later.
Review rules, open incidents, test inject, and manage playbooks at /siem.
Hosted control plane, self-hosted container stack, or SDKs for the apps you ship.
Register your organization. Passkeys, OIDC, SCIM, zero-trust access, log ingest, workflows, and SIEM/SOAR on the hosted plane without standing up a second stack.
Start registrationRun the full control plane on your infrastructure: container images, registry, and deploy tooling via the hub.
Open the container hubIntegrate passkeys and OIDC in any language. Create applications, copy credentials, ship against the cloud issuer.