BastionZero provides a Zero Trust infrastructure access platform that brokers SSH, RDP, Kubernetes, and database sessions using identity‑ and context‑based policies without requiring inbound firewall rules. It integrates with SAML, OIDC, and SCIM providers to issue short‑lived credentials and records every session for real‑time monitoring and immutable audit, supporting multi‑cloud and on‑premise environments.
Funding
$1.8M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

FPFounders
Product
Problem
Enterprises rely on legacy VPNs, static credentials, and perimeter‑based firewalls to protect privileged access to servers, Kubernetes clusters, databases, and remote desktops. These approaches expose high‑value assets to credential theft, lateral movement, and audit gaps, especially as workloads migrate to multi‑cloud and hybrid environments.
Solution
BastionZero delivers a Zero Trust infrastructure access platform that enforces identity‑ and context‑based policies for all privileged connections. By integrating with existing SSE/SASE stacks, the service brokers SSH, RDP, Kubernetes, and database sessions without exposing inbound network ports. Access is granted through short‑lived, cryptographically verified credentials tied to corporate identity providers, and every session is recorded for real‑time monitoring and immutable audit. The platform is now offered as Cloudflare Access for Infrastructure, providing a cloud‑native delivery model while maintaining support for legacy deployments.
Target Audience
The primary customers are security and operations teams in mid‑size to large enterprises that need to protect privileged access to cloud, on‑premise, and hybrid infrastructure, including DevOps engineers, IT administrators, and compliance officers.
Features
- Identity‑driven, policy‑centric access control for SSH, RDP, Kubernetes API, and major database protocols
- Seamless integration with SAML, OIDC, and SCIM identity providers for just‑in‑time credential issuance
- No inbound firewall rules required; connections are brokered through Cloudflare’s global edge network
- End‑to‑end session recording, real‑time activity monitoring, and tamper‑proof audit logs stored in immutable storage
- Granular, attribute‑based policies (device posture, geolocation, risk score) that can be consolidated into broader SSE/SASE frameworks
- OpenPubkey open‑source library for cryptographic key management and zero‑trust authentication workflows
- API and CLI tooling for automated provisioning, revocation, and integration with CI/CD pipelines
- Multi‑cloud support with native routing to AWS, Azure, GCP, and on‑premise environments