● Twingate / The smaller door into the network● 2019 / Founded in Redwood City● 2020 / VPN replacement launches● 2026 / Identity-based SSH access● Twingate / The smaller door into the network● 2019 / Founded in Redwood City● 2020 / VPN replacement launches● 2026 / Identity-based SSH access

Company profile / Cybersecurity

The VPN Had a Front Door. Twingate Brought a Guest List.

A pair of former Dropbox colleagues saw the same old problem inside the corporate network: access was too broad, too awkward, and too easy to leave on. Their company now sells a quieter way in - one resource, one identity, one decision at a time.

The trouble with the corporate VPN was never simply that people disliked it. A key could be misplaced; a connection could drop at the wrong moment; the help desk could be asked, again, why a laptop had access yesterday and not today. But the more consequential question came after a successful login. Once inside, how much of the network could that person see?

Tony Huie and Alex Marshall had met another kind of old machinery while helping Dropbox sell to businesses. Simple software had changed the way people dealt with file servers. In 2019, they joined Lior Rozner to work on a more stubborn relic: remote access. Their premise was almost impolite in the security trade. If the safe tool was awkward, people would route around it. If it was easy, they might actually use it.

The short version

  • Twingate grants access to named private resources according to identity, device and policy.
  • Its client and outbound-only connector replace the public gateway and broad network access of a typical VPN deployment.
  • The company sells a free tier and paid per-user plans to IT, security and platform teams.
  • Published customer cases report fewer tickets and faster deployment; those are customer-specific results, not universal promises.
Twingate co-founders Alex Marshall, Tony Huie and Lior Rozner standing together outdoors
The foundersAlex Marshall, Tony Huie and Lior Rozner went looking for a better lock. First they had to make the door less irritating.

One door, many rooms

A VPN traditionally places a user on a private network. Twingate’s zero trust network access product starts with a smaller unit: a resource, such as a database, server, internal app or Kubernetes endpoint. An administrator defines who may reach it and under which conditions. A client on the user’s device checks identity and policy, then connects through a connector deployed near the resource. The connector initiates outbound connections, so the organization need not expose a public inbound VPN gateway for that route.

That is the company’s distinction in plain English. You can be allowed into the archive without being handed a map of the entire building. The product integrates with identity providers such as Okta and Microsoft Entra ID and can check device posture, including operating-system requirements. Policies can expire, lock after disuse, or narrow access by location. For workers, approved resources can be available in the background; for administrators, the point is to see and change permissions in one place.

This is useful for a contractor who needs one dashboard, an engineer who needs a production database for an hour, or a developer working from home who needs a private Kubernetes cluster. It is also useful for the person who must revoke all of those permissions on a Friday afternoon. The access map still requires care: an administrator must identify resources, assign groups and test policies. Twingate makes those decisions manageable; it cannot decide what a person ought to see.

The expensive free VPN

Criteria, an employment-assessment company, had a firewall VPN that was nominally free. Its team still had to onboard people, answer access calls and explain why engineers needed narrower privileges than everyone else. In Twingate’s published case study, Criteria says onboarding time fell by 83 percent and access-related support tickets dropped from as many as 20 per month to roughly one. Its manager acknowledged paying more for Twingate, then argued that less downtime and easier administration covered the bill. That is a more candid sales argument than pretending software has no price.

“Obviously, we spent more money on Twingate. But the overall ease of training and use, deployment simplicity, and reduced employee downtime more than pays for itself.”CRITERIA CUSTOMER CASE

Homebase gives the deployment version of the same story. Its three-person platform team was operating a public VPN gateway for globally distributed developers. The company says a previous VPN setup took more than a week; Twingate was deployed in less than a day. Its published case credits the switch with an 85 percent reduction in system deployment time and a 90 percent cut in client setup time. Pango, in an earlier account, reported moving more than 300 employees on three continents in 24 hours and estimated over $70,000 in annual savings. Each number belongs to the organization that reported it, with its own starting point.

95%fewer access tickets reported by Criteria
85%less system deployment time reported by Homebase
300+Pango staff moved across three continents

ConsumerAffairs offers a less spectacular but wonderfully recognizable measure. Its security director says deprovisioning once required touching eight OpenVPN systems; with Twingate, the team could deactivate the account centrally. TechOps went from two or three VPN tickets a month to “practically zero.” The story is really about reclaimed attention. A support desk need not be heroic if the routine job becomes routine.

The product follows the permission

Twingate launched publicly in May 2020 and raised a $17 million Series A that October. A $42 million Series B followed in April 2022, led by BOND, with WndrCo, 8VC and SignalFire participating. The company used that announcement to introduce a free Starter tier and a partner alliance for managed service providers and resellers. Today, the published price page lists Starter for up to five users, Teams from $5 per user monthly, Business from $10, and custom Enterprise pricing. The comparison with a legacy VPN depends on labor, downtime, security requirements and the number of people who need access, not only the line item on an invoice.

The company has extended the same logic past network entry. Internet Security adds DNS encryption and filtering. Resource tagging and an API let administrators organize and automate access. Terraform, Pulumi and an open-source Kubernetes operator make policy part of infrastructure workflows. Privileged Access for Kubernetes, introduced in early access in 2025, moves checks into cluster operations. In April 2026, an early-access SSH product offered identity-provider credentials in place of distributed SSH keys, with sessions tied to users and recorded.

The direction is coherent: the closer Twingate can put a decision to the action being taken, the less a single successful login must imply. That still leaves difficult choices. Teams with unusual legacy protocols need to validate compatibility. Direct or relayed connection performance depends on their network conditions. An identity provider outage, a misconfigured policy, or a sick connector can affect access. The company’s architecture reduces one class of exposure; it does not exempt a company from operating its identity and endpoint systems well.

A design lesson disguised as a firewall rule

Twingate’s market includes old VPN appliances and newer zero trust and mesh-network services such as Cloudflare Zero Trust, Zscaler Private Access and Tailscale. They all invite some version of a narrower access conversation, though their architecture, scope and pricing differ. Twingate’s particular claim is that a small team can deploy the connector, connect an identity provider, name its resources and improve the experience without rebuilding every application.

There is a practical idea to copy even without buying the product. List the private resources people actually use. For each one, ask who needs access, from which devices, for how long, and who notices when that need ends. Start with a low-risk group; keep existing access during the first migration; then tighten permissions once the route is proven. Cherry, a Twingate customer, describes doing exactly that: moving Engineering and Product first, preserving its initial access model, then refining group-to-resource mappings over time.

The first thing that failed was a habit: treating arrival on the network as evidence that a person belonged everywhere inside it. Twingate’s founders saw that the habit endured partly because alternatives were painful to use. Their answer is neither glamorous nor theatrical. It is a guest list, checked at each door. In security, that may be enough of a plot twist.