About Authnull

The cloud login got solved. The infrastructure underneath didn't.

A decade of identity tooling poured into SSO and cloud-app MFA — and left the domain controller, the jump host, the firewall, and the database exactly where they were. Authnull exists to close that gap: phishing-resistant MFA, access control, and identity governance as one layer — for every identity that touches your infrastructure, human, service account, or AI agent.

Why we built it

Every audit fails in the same place.

Talk to anyone running security at a company with real infrastructure and the story rhymes: the cloud apps are federated and MFA-protected, the auditor signs off on that page in a minute — and then asks about Active Directory logon, RADIUS, RDP into the server estate, SSH to Linux. Silence.

Those paths can be covered by the incumbents — but only by installing a separate component for each, self-hosting a proxy, and climbing to a higher license tier to unlock the rest. The coverage exists on paper and falls apart in operations.

We thought the enforcement decision should be the same everywhere a credential is used — so we built one layer that treats AD, RADIUS, Windows, databases, and network gear as the same policy, with the governance to prove who has access to what at audit time. One plane, not five projects.

What we believe

Four principles that decide what we build — and what we refuse to.

One layer, not a patchwork

Every access path is the same enforcement decision from one policy plane. If covering a new protocol means a new agent to babysit, we’ve done it wrong.

Coexist before we replace

Nobody rips out working MFA on a Friday. We slot in where the gap is and let teams consolidate on their own timeline — never a forced cutover.

Every identity, not just people

Humans, service accounts, and AI agents all authenticate against the same infrastructure — so they all get the same MFA, the same policy, and the same access reviews. No blind spots for non-human identity.

Fast to value, flat to price

Close an audit finding in days, not a quarter. Flat per-band pricing with every protocol included — no seat-by-seat math, no tier to climb for the basics.

What that looks like in practice

One layer, across every path a credential travels.

Active Directory logon
Kerberos · NTLM
Windows & RDP
3389 · interactive
VPN & RADIUS
RADIUS · TACACS+
Databases
MySQL · PostgreSQL
Identity governance
Reviews · lifecycle
Conditional access
Device · risk · time
Where we sit

We're not trying to replace your identity provider. We're the MFA, access control, and governance layer that picks up exactly where it stops reaching — the on-prem, database, and infrastructure access your IdP was never built to cover.

That charter keeps the product sharp, the deployment fast, and the pricing honest — phishing-resistant MFA on every protocol, governance to prove it at audit, and clean coexistence with whatever you already run at the perimeter.

Want to see the gap in your own environment?

Twenty minutes, your real infrastructure, no slides — or start free and enforce MFA and governance on AD, RADIUS, Windows, and your databases this week.

Get in touchSee how we compare