SAML 2.0
The assertion most business SaaS speaks. InstaSafe runs it in both directions — as your identity provider, or as a service provider federating to the one you already have.
IdP and SP initiatedOne set of credentials, one dashboard, every provisioned application — with MFA and device checks built into that single login.
Single sign-on
Instead of a password per app — remembered, reused, written down, phished — the user authenticates once to an identity provider, which then vouches for them to each application using a cryptographic assertion, most commonly SAML.
Sign in to a few apps the old way — watch the mood drop.
Sign in to a few apps — watch the mood drop.
Users reuse; attackers know. One leaked password becomes access attempts everywhere.
Every leaver means manual revocation across every app. One missed console is a live account owned by someone who no longer works for you.
Without a central login point, nobody can answer “which apps did this user reach last quarter?” — an audit question that will be asked.
Six app logins, timed side by side — with a password-reset detour thrown in for realism.
One login is the surface. Underneath it are the protocols your estate already speaks, the checks that login carries, and the record it leaves behind.
The assertion most business SaaS speaks. InstaSafe runs it in both directions — as your identity provider, or as a service provider federating to the one you already have.
IdP and SP initiatedAuthorises an application to act with a scoped token instead of handing it a password. The scope is the point: an integration gets what it needs and nothing adjacent.
Scoped tokensOAuth with an identity claim on top, which is what modern applications actually ask for. Same single login, expressed in the format the newer half of your estate expects.
ID tokens on OAuthThe protocol your switches, wireless controllers and older VPN concentrators already talk. It means the network gear can ask the same identity a browser does.
Network device authSeparates authentication from authorisation and accounting, which is why network teams keep it for administrative logins to routers and firewalls.
Per-command controlThe Windows domain login your people already completed this morning. Desktop SSO means that ticket carries into the portal — no second prompt at the start of the day.
Domain ticket reuseHardware keys and platform biometrics, bound to the origin. A credential that cannot be replayed on a lookalike domain, because the browser refuses to offer it there.
Hardware-backed factorReads the groups you already maintain in Active Directory or an LDAP server, so entitlement stays where your joiners-movers-leavers process already lives.
Group source of truthHover any card to watch it happen. Nothing here needs a second portal, a second password, or a ticket queue.
The single login carries the strong factors — 6 methods, and which ones are required is decided by the group.
Optionally require an approved device even with perfect credentials.
One action removes a leaver from every application, every device and every session already open.
Every authentication through the portal is an event, and every event rolls up. Reportable in the console, exportable to your SIEM in the format it already ingests.
Top apps, devices, users and locations rolled up from every access event — and exportable to your SIEM.
Learn moreFlip the switch to watch the same person work without it: three apps, three sign-ins, and a reset link somewhere in every one of them.
With InstaSafe: one login at 08:59. Everything after it is work, not authentication.
The logos moving alongside are the ones we are asked about most, not the limit of what we support. Support is a protocol question: anything speaking SAML 2.0, OAuth or OpenID Connect can sit behind this login, which in practice is over 800 business applications.
The ones with their own integration page are simply the ones where setup has a wrinkle worth writing down — a non-standard assertion, a desktop client, a legacy console that never learned SAML at all.
Fifty logins collapse into one, and that one is the login you can afford to defend properly.
Defend one login properly instead of fifty badly. Reuse stops mattering when there is nothing left to reuse it across.
Group membership is provisioning. Disabling the user is offboarding — for every application at once.
Every application login is one line in one log, so the audit question is a report rather than an investigation.
Tick what your evaluation actually needs and copy the shortlist straight into your ticket. Filtering hides rows; it never clears a tick.
11 specs · none selected
Tap a question — our assistant answers on the spot. Still curious? A real human is one click away.
Talk to us//Ready when you are//
SSO with MFA and device trust layered into the login itself. See it running on your own applications in 30 minutes.
Already have an IdP? InstaSafe runs as SP behind it