Skip to content
Modern data center infrastructure

Live in private pilot · Public launch October 2026

One platform. Zero infrastructure boilerplate.

Altuur Secure Ingress unifies traffic ingress, authentication, authorization, and routing into a single software layer. Your workloads connect outward via Warpgate, with no inbound networking, no reverse proxies, no API gateways.

Warpgate (inverted ingress)

Warpgate is the lightweight connector that links your workload to Altuur’s global edge. Your service never accepts inbound connections; Warpgate connects outward over mTLS.

Secure Ingress terminates TLS, enforces authentication and traffic policy, and routes traffic at the edge before forwarding requests securely to your Warpgate.

Your Workload
+
Warpgate
Outbound TLS 1.3 (mTLS)
Altuur Edge
TLSAuthDDoSRouting
HTTPS
End Users

What happens to a request

  1. A request arrives. A user, device, or AI agent calls your endpoint on Altuur’s global edge over HTTPS.
  2. The edge terminates TLS 1.3 and applies traffic protections: rate limiting, abuse controls, and WAF rules.
  3. Identity is enforced. Protected routes require a valid session or token; credentials are verified and stripped at the edge before anything moves further.
  4. Routing picks your service. The request travels to your Warpgate over the outbound mTLS tunnel it already holds open.
  5. Your workload answers. Warpgate hands the request to your upstream with verified identity in two plain headers.
  6. The response returns the same way. Your origin never accepted an inbound connection.

No inbound ports

Warpgate connects outward over mTLS, so your service never needs a public inbound listener.

  • Deployment footprint: your workload plus Warpgate.
  • Origin stays private: no public IP, no inbound firewall openings, no exposed load balancer.

Identity stays at the edge

Authentication and authorization are enforced before requests reach your infrastructure, and the credentials Secure Ingress issues never travel past the edge.

  • Security model: outbound TLS 1.3 with mutual auth (mTLS); identity and traffic policy enforced at the edge before forwarding to Warpgate.
  • Built in: passkeys, TOTP MFA, OAuth 2.1 + OpenID Connect, user directories, and per-route authorization; no external identity provider.
  • The guarantee: tokens are stripped at the edge and verified identity arrives as two plain headers, Mz-User-Id and Mz-User-Email, that inbound traffic can never spoof. An automated check proves it on every deployment.

One repeatable layer

The pattern stays the same across clouds: workload + Warpgate, configured from the Console.

  • Included at launch: routing, automatic TLS and hostnames, DDoS protection, WAF, usage metering, and spend cutoffs.
  • One control plane: manage routes, auth, users, and spend controls in the Console.

Warpgate deep dive → · Getting started docs →

Core platform capabilities

Security and performance are not afterthoughts. These capabilities are built into every Secure Ingress deployment. See all capabilities → and explore the plugin ecosystem →

Automatic TLS + DNS

Public HTTPS certificates and hostnames out of the box, so you stop wiring cert managers and DNS glue.

Routing & traffic policy

Path-based routing, redirects, and CORS live at the edge with the same control plane as auth.

Authentication built in

Passkeys, TOTP MFA, OAuth 2.1 + OpenID Connect, user directories, and per-route authorization as first-class primitives; no external identity provider required.

Edge security

DDoS protection, WAF, and bot/scraper controls enforced before traffic reaches your workload.

Performance primitives

Modern HTTP handling and TLS 1.3 termination at the edge.

Usage & operational visibility

Per-tenant usage metering, connector and route health, and platform-vs-you fault attribution in the Console. Spend controls finalize with pricing.

Built-in certificate authority

Every connection inside Secure Ingress is mutually authenticated TLS 1.3, backed by a private certificate authority built into the platform. Certificates renew automatically and revoke across the edge in seconds; you provision nothing and rotate nothing.

Verifiable by design

Every deployment runs a live check that credentials never pass the edge. Failure drills against the platform fleet gate each release, and every shipped image carries a software bill of materials.

What it replaces

Most teams assemble 6–10 services and vendors just to expose one workload. Secure Ingress keeps that footprint to one outbound connector.

View the detailed stack comparison
CapabilityTraditionalSecure Ingress
TLS certificatesAWS ACM / Let's Encrypt + cert-managerAutomatic
DNSRoute53 / Cloudflare DNSAutomatic
Load balancingALB / NGINX / HAProxyAutomatic
API gatewayKong / API Gateway / TraefikBuilt in
DDoS protectionCloudflare / AWS ShieldBuilt in
AuthenticationAuth0 / Cognito / KeycloakBuilt in
CDN / cachingCloudFront / Fastly / AkamaiRoadmap
WAFAWS WAF / Cloudflare WAFBuilt in
Total services to configure6–10+Warpgate

Common comparisons include Cloudflare Tunnel and ngrok. The difference is not the tunnel; it's everything around it. A tunnel moves traffic, while Secure Ingress is the delivery layer built around inverted ingress: identity, routing, TLS, protections, and operations in one operating model.

To be clear about where incumbents are ahead today: Cloudflare and Akamai operate far larger edge networks, Auth0 ships SDKs for nearly every language, and ngrok has a large developer community. Altuur's bet is structural, not feature-count: one layer, no inbound exposure, and identity that never leaves the edge.

Ready to replace your infrastructure boilerplate?

Deploy your code, add a Warpgate, configure in the Console. One layer replaces your CDN, load balancer, API gateway, auth provider, WAF, and DDoS protection. Secure Ingress is live in private pilot today and launches publicly in October 2026: request pilot access , read the docs, or write to hello@mezusphere.com.