NetFoundry is a privately held, investor-backed cybersecurity company founded in 2019 and headquartered in Charlotte, North Carolina, focused on Zero Trust application connectivity and multicloud networking. In a market moving away from perimeter-based security toward identity-centric “never trust, always verify” models, the company positions itself as advancing Zero Trust by building “zero trust native network overlays” rather than merely adding Zero Trust Network Access (ZTNA) controls onto inherently insecure networks. Its platform is built on the open-source OpenZiti project and delivered through a commercial SaaS offering, with additional models including OEM/white-label and enterprise subscriptions.
The central innovation is application-centric enforcement: instead of securing the network, the approach secures the application by authenticating and authorizing each session before any packets flow. Connectivity can be embedded via agents, virtual appliances, or SDKs, enabling policy-driven, identity-first access across software, clouds, devices, and websites. Mutual TLS (mTLS) is used so endpoints remain effectively invisible and unreachable unless explicitly permitted. The platform is programmable through APIs and designed for DevOps/DevSecOps alignment, supporting policy-as-code, CI/CD integration, and orchestration for fast deployment without dependence on VPNs, firewalls, or SD-WAN.
Architecturally, it emphasizes decentralized mesh connectivity, self-healing routing paths, and infrastructure agnosticism, including support for hybrid and air-gapped environments. Strengths include developer enablement, scalability, and white-label embedding suited to OEMs and large enterprises across finance, industrial automation, and cloud services. Challenges include limited visibility due to white-labeled deployments, the need for developer training for embedded implementations, and less emphasis on traditional network functions like traffic analytics and deep packet inspection. The analyst view frames NetFoundry as representative of a broader shift toward contextual, developer-centric Zero Trust enforcement.
See All Locations
See All Locations