Software Alternatives, Accelerators & Startups
Table of contents
  1. Comments
  2. Is it good?

โœ“
BastionXP

Cloud-Native Private CA and Device Identity Management Platform.

(0 reviews)
Pricing:
Platforms:
  • Linux
  • Apple
  • Windows
  • iOS
  • iPhone
  • iPad
  • Tablets
BastionXP

BastionXP Reviews and Details

This page is designed to help you find out whether BastionXP is good and if it is the right choice for you.

Screenshots and images

  • BastionXP
    Image date //
    2026-05-21

Features & Specs

  1. ACME Protocol Support

  2. ACME Device Attestation

  3. SCEP Gateway Server

  4. SSL Certificate Manager

  5. Certificate Authority

  6. Public Key Infrastructure

  7. Cloud Radius Server

  8. Auditing and Logging

  9. Cloud-Based Certificate Authority

Badges

Promote BastionXP. You can add any of these badges on your website.

SaaSHub badge
Show embed code

Questions & Answers

As answered by people managing BastionXP.
  1. How would you describe the primary audience of BastionXP?

    BastionXP is typically managed by IT Admins who also manage corporate devices and MDMs, Platform Engineering, DevOps, or SRE teams who need to provide "Security-as-a-Service" to the rest of the organization. It allows security teams to set the "guardrails" (policies) while letting developers automate their own certificate needs. It also serves enterprises using MDM platforms โ€” acting as a bridge between identity management systems like Microsoft Entra ID or Okta, MDM platforms like Microsoft Intune or Jamf Pro, and network infrastructure, enabling certificate-based authentication for Wi-Fi (EAP-TLS), ZTNA-VPN, and enterprise SaaS applications.

  2. What makes BastionXP unique?

    BastionXP is a cloud-native private CA (Certificate Authority) and device identity management platform that eliminates passwords and shared secrets by issuing hardware-attested certificates to mobile devices and laptops. What truly sets it apart is its philosophy of anchoring trust in physical hardware: it communicates directly with hardware security modules like Apple's Secure Enclave or Intel's TPM to verify a device's unique identity and boot integrity, requiring cryptographic proof before issuing any certificate. Additionally, it uses short-lived certificates that last only hours (e.g., 4 to 8 hours), automatically renewed via the ACME protocol โ€” and if a device fails a health check during renewal, its access is silently and automatically revoked.

  3. Why should a person choose BastionXP over its competitors?

    Traditional PKI is often heavy, requiring complex databases, Windows servers, and months of integration. BastionXP collapses this into a single, lightweight binary that is "DevOps-native," meaning it can be deployed in minutes and managed via JSON policies and standard APIs. Unlike legacy solutions, BastionXP replaces the weak "challenge passwords" of old SCEP-based systems with modern attestation โ€” verifying the device's unique hardware signature and security posture before issuing a certificate. It also provides detailed audit log trails for all user activities and certificate management actions, plus SSH session recording and replay to review every command executed by a user.

  4. What's the story behind BastionXP?

    BastionXP, part of Ampas Labs Inc., was founded in 2021. Ampas Labs is an agile startup focused on Cloud Security, IoT, and Edge Computing. The BastionXP team comprises professionals from Silicon Valley cloud and networking companies, with the team spread across the globe to better serve customers in different time zones. The company's mission centers on fixing fundamental flaws in device identity management: bridging the gap between physical silicon and digital identity to help organizations build unshakeable Zero Trust perimeters.

  5. Which are the primary technologies used for building BastionXP?

    BastionXP is built around several key open and modern security standards:

    1) PKI/CA automation for X.509 and SSL/TLS certificate creation, signing, distribution, rotation, and revocation, with certificates tied to device, host, workloads and end-user identity. The core of the BastionXP PKI CA stack is built using Google's Golang-based Open Standard Libraries for generating RSA and ECDSA certificates. 2) Implements ACME protocol with Device Attestation, Apple Managed Device Attestation (MDA), and Windows TPM attestation for hardware-level verification. 3) Integration with MDM providers such as Microsoft Intune, Jamf Pro, FleetDM for device certificate management. 4) Integration with Identity Providers (IdP) and/or OAuth/OIDC SSO providers such as GitHub, G-Suite, Microsoft Office, Okta, and Keycloak for end-user certificate management 5) Implements EAP-TLS authentication, Mutual-TLS Authentication, 802.1X Authentication, WPA2-Enterprise Wi-Fi Authentication, WPA3-Enterprise Wi-Fi Authentication, RADIUS Server Authentication.

  6. Who are some of the biggest customers of BastionXP?

    BastionXP is an early stage startup, with many high-profile customers who have shown keen-interest and are in their trial phases. BastionXP doesn't currently disclose its high-profile customers officially yet.

Videos

We don't have any videos for BastionXP yet.

Do you know an article comparing BastionXP to other products?
Suggest a link to a post with product alternatives.

Suggest an article

BastionXP discussion

Log in or Post with
Visit official website
bastionxp.com

Is BastionXP good? This is an informative page that will help you find out. Moreover, you can review and discuss BastionXP here. The primary details have been verified within the last quarter. So they could be considered up to date. If you think we are missing something, please use the means on this page to comment or suggest changes. All reviews and comments are highly encouranged and appreciated as they help everyone in the community to make an informed choice. Please always be kind and objective when evaluating a product and sharing your opinion.