Skip to content
Global cloud infrastructure network

Live in private pilot · Public launch October 2026

Altuur Secure IngressThe identity-aware edge cloud
that replaces 80% of your architecture.

Altuur Secure Ingress turns secure internet delivery into one repeatable layer. Workloads connect outward through Warpgate, while routing, TLS, authentication, and edge security are handled at the edge. One platform instead of ten vendors.

Deployment model

One outbound connector

Warpgate opens outbound mTLS sessions so workloads do not need public inbound ports.

Security posture

Identity stays at the edge

Requests on protected routes are authenticated before they reach your workload. Your application reads verified identity from two plain headers.

Operational outcome

Less stack assembly

Secure Ingress collapses the ingress, auth, and edge-security boilerplate that slows teams down.

Explore Secure Ingress

Overview

Capabilities, the request lifecycle, and how Secure Ingress compares with the stack it replaces.

Warpgate

The outbound connector you deploy beside your workload.

Console

Routes, identity, protections, and dashboards in one place.

Capabilities

Connectivity, identity, and protection services, built in or as add-ons.

Altuur Edge

The managed edge that terminates TLS and enforces identity before traffic reaches you.

Documentation

Getting started, concepts, security, and use-case walkthroughs.

Yes, you could assemble this yourself

Every capability in Secure Ingress exists somewhere else, as a separate product you evaluate, integrate, operate, and pay for. The bundle is the product: one identity-aware layer with fewer components to run and less integration and operations work than the stack it replaces. The three objections we hear most:

“Isn’t this just Cloudflare?”

With Cloudflare you assemble Tunnel for outbound connectivity, Access for identity, a separate identity provider or user directory, and your own route-level authorization and session handling on every service. Secure Ingress ships the connector, the edge, end-user directories, per-route authorization, sessions, and the Console as one product with one configuration surface.

Credit where due: Cloudflare operates a far larger network today. Secure Ingress replaces the stack you would still be assembling behind it.

“AWS already has all of this.”

It does: as ALB, API Gateway, Cognito, WAF, Shield, ACM, and Route 53, seven services you configure, connect, secure, and bill separately. Secure Ingress is that stack as one product with one configuration surface. Keep your compute on AWS; Warpgate connects outward from wherever your workload runs.

If your platform team enjoys wiring managed services together, AWS gives you every knob. Most teams have better uses for that quarter.

“A tunnel plus Auth0 gets me there.”

A tunnel with edge auth can check a token or an SSO login at the boundary, but the users themselves still live somewhere else: a separate directory, a separate lifecycle, and your own per-route rules and dashboards on every service. Secure Ingress includes native user directories and identity lifecycle, per-route authorization with identity delivered to your app as two headers, operational dashboards, and one configuration surface for all of it.

ngrok is a great developer tool with a strong community. Secure Ingress is built as a production front door: user directories, OAuth 2.1, per-route authorization, and operational dashboards included.

One platform, one bill, one repeatable pattern: simpler than six consoles, faster than six integration projects, and less to integrate and operate than six vendor relationships plus the engineering time that glues them together.

From ten moving parts to three boxes

The ingress work does not disappear; it moves into one identity-aware layer that Secure Ingress operates for you. What remains in your diagram is your product.

Exposing one workload today

DNS TLS certificates + renewal CDN + DDoS protection WAF Load balancer API gateway Reverse proxy Auth provider + user store Firewall rules Your workload

6 to 10 vendors, each with its own configuration, dashboard, failure modes, and bill.

With Secure Ingress

Altuur Edge
Warpgate
Your Workload

You deploy the bottom two. Secure Ingress runs the edge, and you configure everything from one Console.

Running in the private pilot today

Outbound-only ingress End-user authentication Automatic HTTPS endpoints Edge rate limiting and abuse controls Usage and status dashboards Identity checks on every deployment

Public launch is October 2026. Pilot teams run real traffic through the platform today; read the July 2026 product update for what shipped last quarter.

One pattern, every service

Deploy your workload anywhere, run Warpgate beside it, and configure routes, identity, and protections from the Console. The pattern is identical from prototype to production, on any cloud.

1

Deploy anywhere

Any cloud, VM, container, or on-prem.

2

Run Warpgate

Outbound TLS 1.3 (mTLS) connector.

3

Configure in the Console

Routes, identity, TLS, and protections.

End Users
HTTPS
Altuur Edge
TLSIdentityWAFRouting
mTLS tunnel (origin connects outbound)
Warpgate
Your Workload
No inbound ports

Identity and traffic policy are enforced at the edge before requests reach your infrastructure.

Who Secure Ingress is built for

Secure Ingress works best when the architecture pain is already visible and the team wants a simpler control plane, not just another point solution.

API and SaaS teams

Teams publishing customer or partner APIs that need strong identity controls and less ingress complexity.

Regulated platforms

Fintech, identity, and enterprise platforms that need cleaner boundaries around authentication, routing, and exposure.

AI and machine-facing services

Products exposing agents, workflows, or internal services where machine identity becomes part of the perimeter.

Recognize your team? See a step-by-step pilot deployment in the docs, from one compose file to authenticated partner traffic.

We have built this stack before, too many times

Altuur’s founding team spent their careers on both halves of this problem: leading engineering at an OAuth and identity platform, and running CDN, edge delivery, and production infrastructure at global scale. Every company around them assembled the same ingress, auth, and security stack from parts. Secure Ingress is that stack built once, as a product, by people who know exactly where it hurts. Read why we built Secure Ingress.

How a pilot runs

Bring one service; the platform does the rest. The pilot is designed so a first service routes through the edge in minutes, with authentication one toggle away.

One service, zero code changes

Pick an app, API, or internal tool you already run. Warpgate runs beside it as a lightweight container; your code, framework, cloud, and deployment pipeline stay exactly as they are.

First traffic in minutes

Create a project in the Console, generate a Warpgate token, and start in echo mode (--echo) to watch requests flow through the edge before your service is even wired. Swap in your upstream URL and real traffic follows the same path.

Measured like production

Usage and status views show requests, sign-ins, connector and route health, and whether a failure originated on our platform or in your service. Warpgate can expose a Prometheus endpoint, so your telemetry lands in your own monitoring stack.

The exit stays in your hands: keep your routes running toward the October 2026 launch, or stop the connector and your stack is exactly as it was. Prefer to scope a pilot together first? Write to hello@mezusphere.com.

Stop assembling; start shipping

Secure Ingress is live in pilot today and launches publicly in October 2026. Request priority access for your team.