Skip to content
BehindGate
Private publishing, set up once

Your teams build with AI. Keep what they publish inside your company.

Dashboards, prototypes, reports, and internal docs should be easy to share — without making them public.

BehindGate lets authorized teams publish static sites on your company domain. IT controls who can publish, and setup takes about 15 minutes. Every site stays behind your existing SSO, so colleagues sign in with their work accounts and everyone else stays out.

14-day free trial. No credit card required.

  • EU-hosted
  • GDPR-compliant
  • Gated by your own identity provider
$ bg-deploy ./dist
 uploaded 142 files
 published release v7

  Live at docs.acme.com
  Gated by Microsoft Entra ID
  1. 1 Point one CNAME at BehindGate, with no nameserver move.
  2. 2 Pick auth: email now, Entra or Google SSO when ready.
  3. 3 Deploy your static build via CLI, CI, or your AI agent.

Building it is easy now. Deciding who gets to see it is the hard part.

A business team can generate a working dashboard in an afternoon. Most of what they build is static: a front end with the data already embedded, with no server or database to manage.

It does not need a complex platform. It must stay inside your company.

Without a sanctioned way to publish it, teams are left with poor options:

Build your own auth proxy

Run and maintain oauth2-proxy, Pomerium, or Authelia yourself. Now you own a security-critical service to patch, monitor, and stay on call for. All to protect a docs site.

Rely on an unguessable URL

Ship it to a public link and hope nobody shares it. Your internal numbers and roadmap are one forwarded message away from the open internet.

Adopt an enterprise platform

Migrate your DNS to a zero-trust vendor or buy a per-seat plan and learn its console, a heavy commitment just to protect a single site.

BehindGate is the layer in between: one place to publish static sites, set up in about 15 minutes, with access controlled by the identity provider you already trust and use.

How it works

You do the setup once. Publishing carries on without you.

IT connects the domain and your identity provider once, and decides which teams can publish. From then on those teams publish on their own, as often as they like, without another ticket.

One-time setup

About 15 minutes
  1. 1

    Point one CNAME

    Add a single CNAME for your domain, like docs.acme.com, and TLS is provisioned automatically. You keep your registrar, your zone, and every other record exactly as they are. No nameserver migration.

  2. 2

    Connect your identity provider

    Microsoft Entra ID, Google Workspace, or your own OIDC provider. Your MFA, conditional access, and group rules carry straight over. Or start on email one-time codes in seconds and connect SSO later.

Every time after

Seconds, by your teams
  1. Publish

    Drag a zip into the dashboard, run the CLI, or publish straight from CI or your AI agent over MCP. No ticket, no review queue, no infrastructure to stand up for a static site.

  2. It's already private

    Every release inherits the access you set up once, so a new site is never public, not even briefly. Each deploy is an immutable release you can roll back in seconds.

The same result, without the parts you don't want to own

There's more than one way to keep a site inside the company. You can build the gate yourself or adopt a zero-trust platform. Here's the honest trade-off against publishing it with BehindGate.

Build it yourself BehindGate
Use your own domain Yes Yes
Gate with your existing SSO Yes Yes
No DNS migration Yes Yes
No per-seat fees Yes Yes
Automatic TLS certificates Build it Yes
Global CDN and DDoS protection Build it Yes
Email one-time codes built in Build it Yes
SSO login flow built in Build it Yes
Atomic deploys and instant rollback Build it Yes
Access and audit logs Build it Yes
Fail-closed access, security-reviewed On you Yes
Manageable by anyone on the team On you Yes
Nothing to patch or maintain On you Yes
Time to live Hours to days Minutes

Access & trust

Your identity provider, not ours

Who counts as "your company"? Whoever your identity provider says. Access is delegated to the provider you already run, so we never store your user directory or your users' passwords. You connect it once, and it governs every site published afterwards.

  • Your MFA, conditional access, and group rules apply, exactly as they do everywhere else.
  • Offboarding is instant: remove someone in your IdP and their access here ends with it.
  • Start on email one-time codes in seconds, with no admin, and connect SSO when you're ready.
  • Your content is never public. It's protected from the very first view.
  • Fail-closed by design: if access can't be verified, the request is denied.
  • Hosted in the EU and GDPR-compliant, with a signed DPA on Business and Enterprise.
Microsoft Entra ID
Google Workspace
Custom OIDC

Who it's for

Whoever builds it, only your company sees it

AI-built dashboards

The business built it with Claude. IT keeps it inside the company.

Claude, v0, and Lovable turn a prompt into a working internal app: a static front-end with no backend, and no login. Give every department one sanctioned place to publish theirs. Each deploy goes behind your company's SSO, so the numbers stay inside the company and nobody builds authentication for a throwaway app.

Metrics dashboardsScheduled reportsData apps
Prototypes & previews

Show the prototype to stakeholders — not to competitors.

A product manager turns an idea into a clickable prototype in an afternoon. It needs feedback from stakeholders and pilot users, but it's also your roadmap, rendered. Publish it behind your SSO and share the link freely: inside the company it just opens, and a forwarded URL shows outsiders a login screen — not your next release.

Clickable prototypesConcept demosFeature previewsStakeholder reviews
Developer portals & docs

The portal is for your developers, not for the internet.

Keep Confluence for the pages people write. It's the generated output that has nowhere to go: a Docusaurus site, your OpenAPI documentation rendered with Redoc or Swagger UI, the coverage report from every CI run. Those are build artifacts, not wiki pages. Publish them as the sites they are: point developers.acme.com at BehindGate and gate it with Entra or Google. Colleagues get in with their normal company login; nobody else does.

OpenAPI docsStorybookSDK referenceCoverage reports

Predictable pricing that doesn't grow with your headcount

Pick a plan for the features you need, then add apps as you grow. Viewers are never charged per seat: the price is the same whether 10 teammates or 10,000 employees sign in. Every plan starts with a 14-day trial, no credit card required.

Billing period

Starter

Get one site private, instantly.

$29 /mo

Billed monthly.

$290 /yr

2 months free, about $24 a month.

  • 1 site
  • 1 app No extra apps on this plan. Upgrade to add more.
  • Email one-time-code authentication
  • Custom domains
  • Unlimited viewers

Pro

Most popular

Full SSO for your workforce.

$99 /mo

Billed monthly.

$990 /yr

2 months free, about $83 a month.

Everything in Starter, plus:

  • 5 apps included Extra apps $15 each a month.
  • Google or Microsoft SSO

Business

Built for compliance reviews.

$299 /mo

Billed monthly.

$2,990 /yr

2 months free, about $249 a month.

Everything in Pro, plus:

  • 3 sites
  • 15 apps included Extra apps $12 each a month.
  • Custom SSO (OIDC)
  • Access logs (30 days)
  • Audit logs (30 days)

Enterprise

Custom terms at any scale.

Custom

Priced to your volume.

Everything in Business, plus:

  • Any number of sites
  • Any number of apps
  • Access logs (365 days)
  • Audit logs (365 days)
  • SIEM export

Prices exclude VAT. VAT is added where applicable.

Frequently asked questions

Couldn't I just build this myself?

You could, but why build something custom that you have to design and, more importantly, maintain? An auth gate is a security-critical service: every patch, provider change, and incident is yours for as long as the site exists, and none of it is the work that actually brings you value. BehindGate is that service, already built and looked after, live in under 15 minutes. Spend the time on your real job instead.

Is email one-time-code access secure enough?

Email codes are a fast way to get started, not the final security tier. They let you go live without waiting on an admin. For anything sensitive, upgrade the site to Entra, Google, or your own OIDC provider. Once SSO is on, email access is turned off, so there's no weaker way in. The Business plan requires SSO outright.

Do you store our users or directory?

No. Access is delegated to your identity provider, and we never hold your user list. Your provider's MFA, conditional access, group membership, and offboarding govern who gets in, and removing someone there removes their access here.

Can I host an AI-generated dashboard or app?

Yes. Anything that builds to a static front-end works (data baked in or fetched client-side). Deploy the output from your AI agent, CI, or the CLI. We host static sites; we don't run a backend for you.

What happens when the trial ends?

Your content stays private. It's never moved to a BehindGate-owned URL or made public. Visitors see a trial-ended page on your own domain until you choose a plan, and you can extend the trial yourself a couple of times if setup ran long.

Fifteen minutes of setup. Years of publishing.

Point one CNAME, connect the SSO you already run, and you're done. Every site published after that is private to your company by default, whether you set it up for your own team or for everyone else's.

14-day trial · no credit card required