Skip to content
Bastyx
Setup guide

Simple to set up. Here’s every step.

Bastyx is designed so one engineer can roll it out in stages, without an IAM team, new hardware or a migration weekend. Existing access keeps working until you switch it off.

What you won’t need

  • No IAM team
  • No proprietary hardware
  • No application rewrites
  • No new SSH client
  • No big-bang cutover
  • No identity provider migration

Seven steps, from first call to zero passwords.

Planned Describes the planned rollout.

  1. 1

    Tell us what you’re securing

    Fill in the short early-access form. If Bastyx fits, an engineer walks through your laptops, servers, apps, AI agents and identity provider with you, and you agree a small pilot scope together.

    You’ll need
    A rough picture of your team, operating systems, servers and key apps.
    Your team notices
    Nothing yet.
  2. 2

    Choose cloud or on-premises

    Bastyx Cloud is the fastest start, with nothing to operate. On-premises runs the control plane in your own data center or cloud account when policy or regulation requires it. Policies, enrollment and the admin console work the same way in both.

    You’ll need
    For on-premises, somewhere to run it. Requirements are published before it’s available.
    Your team notices
    Nothing.
  3. 3

    Connect your people

    Bastyx is designed to read people, teams and roles from the identity provider you already use. Smaller teams without one can manage people in Bastyx.

    You’ll need
    Admin access to your identity provider, or a list of people and teams.
    Your team notices
    Nothing.
  4. 4

    Enroll a pilot team

    Pick one team. Each person enrolls their laptop and registers two authenticators, such as a passkey on their laptop and a hardware security key. There’s no password to set, and nobody outside the pilot changes anything.

    You’ll need
    The laptops and phones people already have. Security keys are optional and standard FIDO2.
    Your team notices
    A few prompts, once. After that, a touch or a fingerprint instead of a password.
  5. 5

    Protect your first servers and apps

    Put a first set of resources behind Bastyx: a server group, an app that supports SSO and a legacy app through the access proxy or a vaulted credential. The old way in keeps working in parallel while the pilot proves out.

    You’ll need
    An owner for each resource you start with.
    Your team notices
    The pilot team signs in the new way. Everyone else is unaffected.
  6. 6

    Give AI agents their own identities

    Agents that touch your infrastructure stop borrowing people’s tokens. Each one gets its own identity, a named owner, a policy and short-lived credentials, with the owner’s approval required for anything sensitive.

    You’ll need
    A list of the agents and automations that use personal or shared credentials today.
    Your team notices
    Agent owners approve sensitive actions with a touch of their key.
  7. 7

    Switch off passwords and expand

    When the pilot is solid, disable password and static-key login on the protected resources, and let Bastyx rotate any password a legacy app still needs into the vault. Add teams and resources by policy. From then on, offboarding is one action.

    You’ll need
    Nothing new.
    Your team notices
    No passwords to remember, reset or share.

Deployment

Cloud or on-premises.

Same policies, same console, same sign-in for people. The difference is who runs it and where your data lives.

Planned Both options are planned.

  • Who operates it

    Bastyx Cloud
    Bastyx
    On-premises
    Your team, with our support
  • Where the control plane runs

    Bastyx Cloud
    Bastyx Cloud
    On-premises
    Your data center or cloud account
  • Directory and audit data

    Bastyx Cloud
    Stored by Bastyx
    On-premises
    Stays in your environment
  • Legacy-app proxies and vaults

    Bastyx Cloud
    Next to your apps
    On-premises
    Next to your apps
  • Updates

    Bastyx Cloud
    Applied by us
    On-premises
    Applied on your schedule
  • Best for

    Bastyx Cloud
    The fastest start
    On-premises
    When policy or regulation requires it

To be published

On-premises requirements: supported platforms, sizing, network dependencies, the update process, and exactly what, if anything, connects back to Bastyx. Published before the on-premises option is available.

Go deeper

Guides for what you’ll protect

FAQ

Setup questions

How long does a pilot take?

It depends on what you start with, so we agree the scope together on the first call. The pilot is deliberately small: one team, one server group and a couple of apps.

Will anything break during the rollout?

It shouldn’t. Existing access keeps working in parallel, and each resource switches over only when you turn off its old login.

Who needs to be involved?

One engineer to run the rollout, an owner for each resource you protect, and the pilot team. Bastyx is designed not to need an IAM team or outside consultants.

Do we need to buy hardware?

No. Passkeys work on the laptops and phones people already have, and standard FIDO2 security keys work if you want them. We recommend hardware keys for admins and production access.

Can we run Bastyx on-premises?

That’s planned. The control plane runs in your own data center or cloud account, with the same policies, enrollment and console as Bastyx Cloud. We’ll publish the requirements before it’s available.

Start with one team.

Tell us what you’re securing. If Bastyx fits, we’ll plan the pilot with you.