
Accops HySecure
Zscaler Private Access
Twingate
Smallstep Certificates
Banyan Security
FerrumGate
Perimeter 81
Cloud-Native Private CA and Device Identity Management Platform

Website, pricing, platforms and company facts side by side.
|
|
|
|
|---|---|---|
| Website | bastionxp.com | codegres.org |
| Pricing | — | |
| Platforms | — | |
| Company | Startup from the United States · 2021 | — |
| Listed in |
In their own words, as submitted to SaaSHub.


BastionXP is a cloud-native private CA and device identity management platform that eliminates passwords and shared secrets by issuing hardware-attested certificates to mobile devices and laptops. Secure access to your Wi-Fi, VPN, and SaaS applications in your enterprise network. Replace legacy...
No description of Codegres.org yet.
What each product offers, as listed by its team.


Possible disadvantages
An editorial look at what each product does well and who it suits.


Overall verdict
Why this product is good
Recommended for
Overall verdict
Why this product is good
Recommended for
How often each product is chosen within a category, 0–100% relative to the other.


As answered by people managing BastionXP and Codegres.org.
BastionXP's answer
BastionXP is typically managed by IT Admins who also manage corporate devices and MDMs, Platform Engineering, DevOps, or SRE teams who need to provide "Security-as-a-Service" to the rest of the organization. It allows security teams to set the "guardrails" (policies) while letting developers automate their own certificate needs. It also serves enterprises using MDM platforms — acting as a bridge between identity management systems like Microsoft Entra ID or Okta, MDM platforms like Microsoft Intune or Jamf Pro, and network infrastructure, enabling certificate-based authentication for Wi-Fi (EAP-TLS), ZTNA-VPN, and enterprise SaaS applications.
BastionXP's answer
BastionXP is a cloud-native private CA (Certificate Authority) and device identity management platform that eliminates passwords and shared secrets by issuing hardware-attested certificates to mobile devices and laptops. What truly sets it apart is its philosophy of anchoring trust in physical hardware: it communicates directly with hardware security modules like Apple's Secure Enclave or Intel's TPM to verify a device's unique identity and boot integrity, requiring cryptographic proof before issuing any certificate. Additionally, it uses short-lived certificates that last only hours (e.g., 4 to 8 hours), automatically renewed via the ACME protocol — and if a device fails a health check during renewal, its access is silently and automatically revoked.
BastionXP's answer
Traditional PKI is often heavy, requiring complex databases, Windows servers, and months of integration. BastionXP collapses this into a single, lightweight binary that is "DevOps-native," meaning it can be deployed in minutes and managed via JSON policies and standard APIs. Unlike legacy solutions, BastionXP replaces the weak "challenge passwords" of old SCEP-based systems with modern attestation — verifying the device's unique hardware signature and security posture before issuing a certificate. It also provides detailed audit log trails for all user activities and certificate management actions, plus SSH session recording and replay to review every command executed by a user.
BastionXP's answer
BastionXP, part of Ampas Labs Inc., was founded in 2021. Ampas Labs is an agile startup focused on Cloud Security, IoT, and Edge Computing. The BastionXP team comprises professionals from Silicon Valley cloud and networking companies, with the team spread across the globe to better serve customers in different time zones. The company's mission centers on fixing fundamental flaws in device identity management: bridging the gap between physical silicon and digital identity to help organizations build unshakeable Zero Trust perimeters.
BastionXP's answer
BastionXP is built around several key open and modern security standards:
1) PKI/CA automation for X.509 and SSL/TLS certificate creation, signing, distribution, rotation, and revocation, with certificates tied to device, host, workloads and end-user identity. The core of the BastionXP PKI CA stack is built using Google's Golang-based Open Standard Libraries for generating RSA and ECDSA certificates. 2) Implements ACME protocol with Device Attestation, Apple Managed Device Attestation (MDA), and Windows TPM attestation for hardware-level verification. 3) Integration with MDM providers such as Microsoft Intune, Jamf Pro, FleetDM for device certificate management. 4) Integration with Identity Providers (IdP) and/or OAuth/OIDC SSO providers such as GitHub, G-Suite, Microsoft Office, Okta, and Keycloak for end-user certificate management 5) Implements EAP-TLS authentication, Mutual-TLS Authentication, 802.1X Authentication, WPA2-Enterprise Wi-Fi Authentication, WPA3-Enterprise Wi-Fi Authentication, RADIUS Server Authentication.
BastionXP's answer
BastionXP is an early stage startup, with many high-profile customers who have shown keen-interest and are in their trial phases. BastionXP doesn't currently disclose its high-profile customers officially yet.
Share your experience with using BastionXP and Codegres.org. For example, how are they different and which one is better?
When comparing BastionXP and Codegres.org, you can also consider the following products.

Secure Private Access Based on Zero Trust
Compare Accops HySecure to BastionXP or Codegres.org:

Zscaler Private Access (ZPA) provides zero trust network access (ZTNA) for your private apps—you no longer have to choose between user experience and security.
Compare Zscaler Private Access to BastionXP or Codegres.org:


A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.
Compare Smallstep Certificates to BastionXP or Codegres.org:

Banyan Security enforces real-time secure least-privileged access to applications and services, leveraging your existing enterprise identity and security tool investments.
Compare Banyan Security to BastionXP or Codegres.org:

Open Source Zero Trust Network Access (ZTNA)
Compare FerrumGate to BastionXP or Codegres.org: