
Live in private pilot · Public launch October 2026
Altuur Secure IngressThe identity-aware edge cloud
that replaces 80% of your architecture.
Altuur Secure Ingress turns secure internet delivery into one repeatable layer. Workloads connect outward through Warpgate, while routing, TLS, authentication, and edge security are handled at the edge. One platform instead of ten vendors.
Deployment model
One outbound connector
Warpgate opens outbound mTLS sessions so workloads do not need public inbound ports.
Security posture
Identity stays at the edge
Requests on protected routes are authenticated before they reach your workload. Your application reads verified identity from two plain headers.
Operational outcome
Less stack assembly
Secure Ingress collapses the ingress, auth, and edge-security boilerplate that slows teams down.
Explore Secure Ingress
Overview
Capabilities, the request lifecycle, and how Secure Ingress compares with the stack it replaces.
Warpgate
The outbound connector you deploy beside your workload.
Console
Routes, identity, protections, and dashboards in one place.
Capabilities
Connectivity, identity, and protection services, built in or as add-ons.
Altuur Edge
The managed edge that terminates TLS and enforces identity before traffic reaches you.
Documentation
Getting started, concepts, security, and use-case walkthroughs.
Yes, you could assemble this yourself
Every capability in Secure Ingress exists somewhere else, as a separate product you evaluate, integrate, operate, and pay for. The bundle is the product: one identity-aware layer with fewer components to run and less integration and operations work than the stack it replaces. The three objections we hear most:
“Isn’t this just Cloudflare?”
With Cloudflare you assemble Tunnel for outbound connectivity, Access for identity, a separate identity provider or user directory, and your own route-level authorization and session handling on every service. Secure Ingress ships the connector, the edge, end-user directories, per-route authorization, sessions, and the Console as one product with one configuration surface.
Credit where due: Cloudflare operates a far larger network today. Secure Ingress replaces the stack you would still be assembling behind it.
“AWS already has all of this.”
It does: as ALB, API Gateway, Cognito, WAF, Shield, ACM, and Route 53, seven services you configure, connect, secure, and bill separately. Secure Ingress is that stack as one product with one configuration surface. Keep your compute on AWS; Warpgate connects outward from wherever your workload runs.
If your platform team enjoys wiring managed services together, AWS gives you every knob. Most teams have better uses for that quarter.
“A tunnel plus Auth0 gets me there.”
A tunnel with edge auth can check a token or an SSO login at the boundary, but the users themselves still live somewhere else: a separate directory, a separate lifecycle, and your own per-route rules and dashboards on every service. Secure Ingress includes native user directories and identity lifecycle, per-route authorization with identity delivered to your app as two headers, operational dashboards, and one configuration surface for all of it.
ngrok is a great developer tool with a strong community. Secure Ingress is built as a production front door: user directories, OAuth 2.1, per-route authorization, and operational dashboards included.
One platform, one bill, one repeatable pattern: simpler than six consoles, faster than six integration projects, and less to integrate and operate than six vendor relationships plus the engineering time that glues them together.
From ten moving parts to three boxes
The ingress work does not disappear; it moves into one identity-aware layer that Secure Ingress operates for you. What remains in your diagram is your product.
Exposing one workload today
6 to 10 vendors, each with its own configuration, dashboard, failure modes, and bill.
With Secure Ingress
You deploy the bottom two. Secure Ingress runs the edge, and you configure everything from one Console.
Running in the private pilot today
Public launch is October 2026. Pilot teams run real traffic through the platform today; read the July 2026 product update for what shipped last quarter.
One pattern, every service
Deploy your workload anywhere, run Warpgate beside it, and configure routes, identity, and protections from the Console. The pattern is identical from prototype to production, on any cloud.
Deploy anywhere
Any cloud, VM, container, or on-prem.
Run Warpgate
Outbound TLS 1.3 (mTLS) connector.
Configure in the Console
Routes, identity, TLS, and protections.
Identity and traffic policy are enforced at the edge before requests reach your infrastructure.
Who Secure Ingress is built for
Secure Ingress works best when the architecture pain is already visible and the team wants a simpler control plane, not just another point solution.
API and SaaS teams
Teams publishing customer or partner APIs that need strong identity controls and less ingress complexity.
Regulated platforms
Fintech, identity, and enterprise platforms that need cleaner boundaries around authentication, routing, and exposure.
AI and machine-facing services
Products exposing agents, workflows, or internal services where machine identity becomes part of the perimeter.
Recognize your team? See a step-by-step pilot deployment in the docs, from one compose file to authenticated partner traffic.
We have built this stack before, too many times
Altuur’s founding team spent their careers on both halves of this problem: leading engineering at an OAuth and identity platform, and running CDN, edge delivery, and production infrastructure at global scale. Every company around them assembled the same ingress, auth, and security stack from parts. Secure Ingress is that stack built once, as a product, by people who know exactly where it hurts. Read why we built Secure Ingress.
How a pilot runs
Bring one service; the platform does the rest. The pilot is designed so a first service routes through the edge in minutes, with authentication one toggle away.
One service, zero code changes
Pick an app, API, or internal tool you already run. Warpgate runs beside it as a lightweight container; your code, framework, cloud, and deployment pipeline stay exactly as they are.
First traffic in minutes
Create a project in the Console, generate a Warpgate token, and start in echo mode (--echo) to watch requests flow through the edge before your service is even wired. Swap in your upstream URL and real traffic follows the same path.
Measured like production
Usage and status views show requests, sign-ins, connector and route health, and whether a failure originated on our platform or in your service. Warpgate can expose a Prometheus endpoint, so your telemetry lands in your own monitoring stack.
The exit stays in your hands: keep your routes running toward the October 2026 launch, or stop the connector and your stack is exactly as it was. Prefer to scope a pilot together first? Write to hello@mezusphere.com.
Stop assembling; start shipping
Secure Ingress is live in pilot today and launches publicly in October 2026. Request priority access for your team.