
Live in private pilot · Public launch October 2026
One platform. Zero infrastructure boilerplate.
Altuur Secure Ingress unifies traffic ingress, authentication, authorization, and routing into a single software layer. Your workloads connect outward via Warpgate, with no inbound networking, no reverse proxies, no API gateways.
Warpgate (inverted ingress)
Warpgate is the lightweight connector that links your workload to Altuur’s global edge. Your service never accepts inbound connections; Warpgate connects outward over mTLS.
Secure Ingress terminates TLS, enforces authentication and traffic policy, and routes traffic at the edge before forwarding requests securely to your Warpgate.
What happens to a request
- A request arrives. A user, device, or AI agent calls your endpoint on Altuur’s global edge over HTTPS.
- The edge terminates TLS 1.3 and applies traffic protections: rate limiting, abuse controls, and WAF rules.
- Identity is enforced. Protected routes require a valid session or token; credentials are verified and stripped at the edge before anything moves further.
- Routing picks your service. The request travels to your Warpgate over the outbound mTLS tunnel it already holds open.
- Your workload answers. Warpgate hands the request to your upstream with verified identity in two plain headers.
- The response returns the same way. Your origin never accepted an inbound connection.
No inbound ports
Warpgate connects outward over mTLS, so your service never needs a public inbound listener.
- Deployment footprint: your workload plus Warpgate.
- Origin stays private: no public IP, no inbound firewall openings, no exposed load balancer.
Identity stays at the edge
Authentication and authorization are enforced before requests reach your infrastructure, and the credentials Secure Ingress issues never travel past the edge.
- Security model: outbound TLS 1.3 with mutual auth (mTLS); identity and traffic policy enforced at the edge before forwarding to Warpgate.
- Built in: passkeys, TOTP MFA, OAuth 2.1 + OpenID Connect, user directories, and per-route authorization; no external identity provider.
- The guarantee: tokens are stripped at the edge and verified identity arrives as two plain headers,
Mz-User-IdandMz-User-Email, that inbound traffic can never spoof. An automated check proves it on every deployment.
One repeatable layer
The pattern stays the same across clouds: workload + Warpgate, configured from the Console.
- Included at launch: routing, automatic TLS and hostnames, DDoS protection, WAF, usage metering, and spend cutoffs.
- One control plane: manage routes, auth, users, and spend controls in the Console.
Core platform capabilities
Security and performance are not afterthoughts. These capabilities are built into every Secure Ingress deployment. See all capabilities → and explore the plugin ecosystem →
Automatic TLS + DNS
Public HTTPS certificates and hostnames out of the box, so you stop wiring cert managers and DNS glue.
Routing & traffic policy
Path-based routing, redirects, and CORS live at the edge with the same control plane as auth.
Authentication built in
Passkeys, TOTP MFA, OAuth 2.1 + OpenID Connect, user directories, and per-route authorization as first-class primitives; no external identity provider required.
Edge security
DDoS protection, WAF, and bot/scraper controls enforced before traffic reaches your workload.
Performance primitives
Modern HTTP handling and TLS 1.3 termination at the edge.
Usage & operational visibility
Per-tenant usage metering, connector and route health, and platform-vs-you fault attribution in the Console. Spend controls finalize with pricing.
Built-in certificate authority
Every connection inside Secure Ingress is mutually authenticated TLS 1.3, backed by a private certificate authority built into the platform. Certificates renew automatically and revoke across the edge in seconds; you provision nothing and rotate nothing.
Verifiable by design
Every deployment runs a live check that credentials never pass the edge. Failure drills against the platform fleet gate each release, and every shipped image carries a software bill of materials.
What it replaces
Most teams assemble 6–10 services and vendors just to expose one workload. Secure Ingress keeps that footprint to one outbound connector.
View the detailed stack comparison
| Capability | Traditional | Secure Ingress |
|---|---|---|
| TLS certificates | AWS ACM / Let's Encrypt + cert-manager | Automatic |
| DNS | Route53 / Cloudflare DNS | Automatic |
| Load balancing | ALB / NGINX / HAProxy | Automatic |
| API gateway | Kong / API Gateway / Traefik | Built in |
| DDoS protection | Cloudflare / AWS Shield | Built in |
| Authentication | Auth0 / Cognito / Keycloak | Built in |
| CDN / caching | CloudFront / Fastly / Akamai | Roadmap |
| WAF | AWS WAF / Cloudflare WAF | Built in |
| Total services to configure | 6–10+ | Warpgate |
Common comparisons include Cloudflare Tunnel and ngrok. The difference is not the tunnel; it's everything around it. A tunnel moves traffic, while Secure Ingress is the delivery layer built around inverted ingress: identity, routing, TLS, protections, and operations in one operating model.
To be clear about where incumbents are ahead today: Cloudflare and Akamai operate far larger edge networks, Auth0 ships SDKs for nearly every language, and ngrok has a large developer community. Altuur's bet is structural, not feature-count: one layer, no inbound exposure, and identity that never leaves the edge.
Ready to replace your infrastructure boilerplate?
Deploy your code, add a Warpgate, configure in the Console. One layer replaces your CDN, load balancer, API gateway, auth provider, WAF, and DDoS protection. Secure Ingress is live in private pilot today and launches publicly in October 2026: request pilot access , read the docs, or write to hello@mezusphere.com.