Simple to set up. Here’s every step.
Bastyx is designed so one engineer can roll it out in stages, without an IAM team, new hardware or a migration weekend. Existing access keeps working until you switch it off.
What you won’t need
- No IAM team
- No proprietary hardware
- No application rewrites
- No new SSH client
- No big-bang cutover
- No identity provider migration
Seven steps, from first call to zero passwords.
Planned Describes the planned rollout.
- 1
Tell us what you’re securing
Fill in the short early-access form. If Bastyx fits, an engineer walks through your laptops, servers, apps, AI agents and identity provider with you, and you agree a small pilot scope together.
- You’ll need
- A rough picture of your team, operating systems, servers and key apps.
- Your team notices
- Nothing yet.
- 2
Choose cloud or on-premises
Bastyx Cloud is the fastest start, with nothing to operate. On-premises runs the control plane in your own data center or cloud account when policy or regulation requires it. Policies, enrollment and the admin console work the same way in both.
- You’ll need
- For on-premises, somewhere to run it. Requirements are published before it’s available.
- Your team notices
- Nothing.
- 3
Connect your people
Bastyx is designed to read people, teams and roles from the identity provider you already use. Smaller teams without one can manage people in Bastyx.
- You’ll need
- Admin access to your identity provider, or a list of people and teams.
- Your team notices
- Nothing.
- 4
Enroll a pilot team
Pick one team. Each person enrolls their laptop and registers two authenticators, such as a passkey on their laptop and a hardware security key. There’s no password to set, and nobody outside the pilot changes anything.
- You’ll need
- The laptops and phones people already have. Security keys are optional and standard FIDO2.
- Your team notices
- A few prompts, once. After that, a touch or a fingerprint instead of a password.
- 5
Protect your first servers and apps
Put a first set of resources behind Bastyx: a server group, an app that supports SSO and a legacy app through the access proxy or a vaulted credential. The old way in keeps working in parallel while the pilot proves out.
- You’ll need
- An owner for each resource you start with.
- Your team notices
- The pilot team signs in the new way. Everyone else is unaffected.
- 6
Give AI agents their own identities
Agents that touch your infrastructure stop borrowing people’s tokens. Each one gets its own identity, a named owner, a policy and short-lived credentials, with the owner’s approval required for anything sensitive.
- You’ll need
- A list of the agents and automations that use personal or shared credentials today.
- Your team notices
- Agent owners approve sensitive actions with a touch of their key.
- 7
Switch off passwords and expand
When the pilot is solid, disable password and static-key login on the protected resources, and let Bastyx rotate any password a legacy app still needs into the vault. Add teams and resources by policy. From then on, offboarding is one action.
- You’ll need
- Nothing new.
- Your team notices
- No passwords to remember, reset or share.
Deployment
Cloud or on-premises.
Same policies, same console, same sign-in for people. The difference is who runs it and where your data lives.
Planned Both options are planned.
| Bastyx Cloud | On-premises | |
|---|---|---|
| Who operates it | Bastyx | Your team, with our support |
| Where the control plane runs | Bastyx Cloud | Your data center or cloud account |
| Directory and audit data | Stored by Bastyx | Stays in your environment |
| Legacy-app proxies and vaults | Next to your apps | Next to your apps |
| Updates | Applied by us | Applied on your schedule |
| Best for | The fastest start | When policy or regulation requires it |
Who operates it
- Bastyx Cloud
- Bastyx
- On-premises
- Your team, with our support
Where the control plane runs
- Bastyx Cloud
- Bastyx Cloud
- On-premises
- Your data center or cloud account
Directory and audit data
- Bastyx Cloud
- Stored by Bastyx
- On-premises
- Stays in your environment
Legacy-app proxies and vaults
- Bastyx Cloud
- Next to your apps
- On-premises
- Next to your apps
Updates
- Bastyx Cloud
- Applied by us
- On-premises
- Applied on your schedule
Best for
- Bastyx Cloud
- The fastest start
- On-premises
- When policy or regulation requires it
To be published
Go deeper
Guides for what you’ll protect
FAQ
Setup questions
How long does a pilot take?
It depends on what you start with, so we agree the scope together on the first call. The pilot is deliberately small: one team, one server group and a couple of apps.
Will anything break during the rollout?
It shouldn’t. Existing access keeps working in parallel, and each resource switches over only when you turn off its old login.
Who needs to be involved?
One engineer to run the rollout, an owner for each resource you protect, and the pilot team. Bastyx is designed not to need an IAM team or outside consultants.
Do we need to buy hardware?
No. Passkeys work on the laptops and phones people already have, and standard FIDO2 security keys work if you want them. We recommend hardware keys for admins and production access.
Can we run Bastyx on-premises?
That’s planned. The control plane runs in your own data center or cloud account, with the same policies, enrollment and console as Bastyx Cloud. We’ll publish the requirements before it’s available.
Start with one team.
Tell us what you’re securing. If Bastyx fits, we’ll plan the pilot with you.