
Accops HySecure
Zscaler Private Access
Twingate
Smallstep Certificates
Banyan Security
FerrumGate
Perimeter 81
Cloud-Native Private CA and Device Identity Management Platform

Website, pricing, platforms and company facts side by side.
|
|
|
|
|---|---|---|
| Website | codegres.org | bastionxp.com |
| Pricing | — | |
| Platforms | — | |
| Company | — | Startup from the United States · 2021 |
| Listed in |
In their own words, as submitted to SaaSHub.


No description of Codegres.org yet.
BastionXP is a cloud-native private CA and device identity management platform that eliminates passwords and shared secrets by issuing hardware-attested certificates to mobile devices and laptops. Secure access to your Wi-Fi, VPN, and SaaS applications in your enterprise network. Replace legacy...
What each product offers, as listed by its team.


Possible disadvantages
An editorial look at what each product does well and who it suits.


Overall verdict
Why this product is good
Recommended for
Overall verdict
Why this product is good
Recommended for
How often each product is chosen within a category, 0–100% relative to the other.


As answered by people managing Codegres.org and BastionXP.
BastionXP's answer:
BastionXP is typically managed by IT Admins who also manage corporate devices and MDMs, Platform Engineering, DevOps, or SRE teams who need to provide "Security-as-a-Service" to the rest of the organization. It allows security teams to set the "guardrails" (policies) while letting developers automate their own certificate needs. It also serves enterprises using MDM platforms — acting as a bridge between identity management systems like Microsoft Entra ID or Okta, MDM platforms like Microsoft Intune or Jamf Pro, and network infrastructure, enabling certificate-based authentication for Wi-Fi (EAP-TLS), ZTNA-VPN, and enterprise SaaS applications.
BastionXP's answer:
BastionXP is a cloud-native private CA (Certificate Authority) and device identity management platform that eliminates passwords and shared secrets by issuing hardware-attested certificates to mobile devices and laptops. What truly sets it apart is its philosophy of anchoring trust in physical hardware: it communicates directly with hardware security modules like Apple's Secure Enclave or Intel's TPM to verify a device's unique identity and boot integrity, requiring cryptographic proof before issuing any certificate. Additionally, it uses short-lived certificates that last only hours (e.g., 4 to 8 hours), automatically renewed via the ACME protocol — and if a device fails a health check during renewal, its access is silently and automatically revoked.
BastionXP's answer:
Traditional PKI is often heavy, requiring complex databases, Windows servers, and months of integration. BastionXP collapses this into a single, lightweight binary that is "DevOps-native," meaning it can be deployed in minutes and managed via JSON policies and standard APIs. Unlike legacy solutions, BastionXP replaces the weak "challenge passwords" of old SCEP-based systems with modern attestation — verifying the device's unique hardware signature and security posture before issuing a certificate. It also provides detailed audit log trails for all user activities and certificate management actions, plus SSH session recording and replay to review every command executed by a user.
BastionXP's answer:
BastionXP, part of Ampas Labs Inc., was founded in 2021. Ampas Labs is an agile startup focused on Cloud Security, IoT, and Edge Computing. The BastionXP team comprises professionals from Silicon Valley cloud and networking companies, with the team spread across the globe to better serve customers in different time zones. The company's mission centers on fixing fundamental flaws in device identity management: bridging the gap between physical silicon and digital identity to help organizations build unshakeable Zero Trust perimeters.
BastionXP's answer:
BastionXP is built around several key open and modern security standards:
1) PKI/CA automation for X.509 and SSL/TLS certificate creation, signing, distribution, rotation, and revocation, with certificates tied to device, host, workloads and end-user identity. The core of the BastionXP PKI CA stack is built using Google's Golang-based Open Standard Libraries for generating RSA and ECDSA certificates. 2) Implements ACME protocol with Device Attestation, Apple Managed Device Attestation (MDA), and Windows TPM attestation for hardware-level verification. 3) Integration with MDM providers such as Microsoft Intune, Jamf Pro, FleetDM for device certificate management. 4) Integration with Identity Providers (IdP) and/or OAuth/OIDC SSO providers such as GitHub, G-Suite, Microsoft Office, Okta, and Keycloak for end-user certificate management 5) Implements EAP-TLS authentication, Mutual-TLS Authentication, 802.1X Authentication, WPA2-Enterprise Wi-Fi Authentication, WPA3-Enterprise Wi-Fi Authentication, RADIUS Server Authentication.
BastionXP's answer:
BastionXP is an early stage startup, with many high-profile customers who have shown keen-interest and are in their trial phases. BastionXP doesn't currently disclose its high-profile customers officially yet.
Share your experience with using Codegres.org and BastionXP. For example, how are they different and which one is better?