Skip to main content
Nauthilus 4.0 is here: see what's newNauthilus

One central policy engine
for authentication and authorization.

Mail servers, web applications, identity flows and APIs no longer decide alone. Nauthilus collects the facts behind every request (identity, network, reputation, brute-force history, MFA state) and returns one consistent decision, with the obligations to enforce it.

Nauthilus in 76 seconds

Who decides?

Today every service decides alone: different lockouts, different MFA rules, different blind spots. Here is what changes when one engine makes the call.

How it works

Facts in. Decision out.

Declarative policies evaluate the facts at each checkpoint of a request and answer with a clear verdict and the obligations that go with it. Try new rules in observe mode first, then enforce them once you trust them.

  • user@corp.example
  • IP · geo · ASN
  • brute-force history
  • blocklists (RBL)
  • LDAP attributes
  • MFA state
Policy engine
  • DecisionALLOW+ step-up MFA · audit
  • DecisionDENY+ rate-limit source · audit
  • DecisionTEMPFAIL+ retry later · backend degraded

Same rules. Every service. Every time.

Running it in production?

Enterprise support. Directly from the maintainer.

  • Architecture
  • Integration
  • Customization
  • Troubleshooting

Nauthilus is open source under the GPLv3, written in Go. You can also sponsor its development.