Your teams build with AI. Keep what they publish inside your company.
Dashboards, prototypes, reports, and internal docs should be easy to share — without making them public.
BehindGate lets authorized teams publish static sites on your company domain. IT controls who can publish, and setup takes about 15 minutes. Every site stays behind your existing SSO, so colleagues sign in with their work accounts and everyone else stays out.
14-day free trial. No credit card required.
- EU-hosted
- GDPR-compliant
- Gated by your own identity provider
$ bg-deploy ./dist
✓ uploaded 142 files
✓ published release v7
Live at docs.acme.com
Gated by Microsoft Entra ID - 1 Point one CNAME at BehindGate, with no nameserver move.
- 2 Pick auth: email now, Entra or Google SSO when ready.
- 3 Deploy your static build via CLI, CI, or your AI agent.
Building it is easy now. Deciding who gets to see it is the hard part.
A business team can generate a working dashboard in an afternoon. Most of what they build is static: a front end with the data already embedded, with no server or database to manage.
It does not need a complex platform. It must stay inside your company.
Without a sanctioned way to publish it, teams are left with poor options:
Build your own auth proxy
Run and maintain oauth2-proxy, Pomerium, or Authelia yourself. Now you own a security-critical service to patch, monitor, and stay on call for. All to protect a docs site.
Rely on an unguessable URL
Ship it to a public link and hope nobody shares it. Your internal numbers and roadmap are one forwarded message away from the open internet.
Adopt an enterprise platform
Migrate your DNS to a zero-trust vendor or buy a per-seat plan and learn its console, a heavy commitment just to protect a single site.
BehindGate is the layer in between: one place to publish static sites, set up in about 15 minutes, with access controlled by the identity provider you already trust and use.
How it works
You do the setup once. Publishing carries on without you.
IT connects the domain and your identity provider once, and decides which teams can publish. From then on those teams publish on their own, as often as they like, without another ticket.
One-time setup
About 15 minutes- 1
Point one CNAME
Add a single CNAME for your domain, like docs.acme.com, and TLS is provisioned automatically. You keep your registrar, your zone, and every other record exactly as they are. No nameserver migration.
- 2
Connect your identity provider
Microsoft Entra ID, Google Workspace, or your own OIDC provider. Your MFA, conditional access, and group rules carry straight over. Or start on email one-time codes in seconds and connect SSO later.
Every time after
Seconds, by your teams-
Publish
Drag a zip into the dashboard, run the CLI, or publish straight from CI or your AI agent over MCP. No ticket, no review queue, no infrastructure to stand up for a static site.
-
It's already private
Every release inherits the access you set up once, so a new site is never public, not even briefly. Each deploy is an immutable release you can roll back in seconds.
The same result, without the parts you don't want to own
There's more than one way to keep a site inside the company. You can build the gate yourself or adopt a zero-trust platform. Here's the honest trade-off against publishing it with BehindGate.
| Build it yourself | BehindGate | |
|---|---|---|
| Use your own domain | Yes | Yes |
| Gate with your existing SSO | Yes | Yes |
| No DNS migration | Yes | Yes |
| No per-seat fees | Yes | Yes |
| Automatic TLS certificates | Build it | Yes |
| Global CDN and DDoS protection | Build it | Yes |
| Email one-time codes built in | Build it | Yes |
| SSO login flow built in | Build it | Yes |
| Atomic deploys and instant rollback | Build it | Yes |
| Access and audit logs | Build it | Yes |
| Fail-closed access, security-reviewed | On you | Yes |
| Manageable by anyone on the team | On you | Yes |
| Nothing to patch or maintain | On you | Yes |
| Time to live | Hours to days | Minutes |
Access & trust
Your identity provider, not ours
Who counts as "your company"? Whoever your identity provider says. Access is delegated to the provider you already run, so we never store your user directory or your users' passwords. You connect it once, and it governs every site published afterwards.
- Your MFA, conditional access, and group rules apply, exactly as they do everywhere else.
- Offboarding is instant: remove someone in your IdP and their access here ends with it.
- Start on email one-time codes in seconds, with no admin, and connect SSO when you're ready.
- Your content is never public. It's protected from the very first view.
- Fail-closed by design: if access can't be verified, the request is denied.
- Hosted in the EU and GDPR-compliant, with a signed DPA on Business and Enterprise.
Who it's for
Whoever builds it, only your company sees it
The business built it with Claude. IT keeps it inside the company.
Claude, v0, and Lovable turn a prompt into a working internal app: a static front-end with no backend, and no login. Give every department one sanctioned place to publish theirs. Each deploy goes behind your company's SSO, so the numbers stay inside the company and nobody builds authentication for a throwaway app.
Show the prototype to stakeholders — not to competitors.
A product manager turns an idea into a clickable prototype in an afternoon. It needs feedback from stakeholders and pilot users, but it's also your roadmap, rendered. Publish it behind your SSO and share the link freely: inside the company it just opens, and a forwarded URL shows outsiders a login screen — not your next release.
The portal is for your developers, not for the internet.
Keep Confluence for the pages people write. It's the generated output that has nowhere to go: a Docusaurus site, your OpenAPI documentation rendered with Redoc or Swagger UI, the coverage report from every CI run. Those are build artifacts, not wiki pages. Publish them as the sites they are: point developers.acme.com at BehindGate and gate it with Entra or Google. Colleagues get in with their normal company login; nobody else does.
Predictable pricing that doesn't grow with your headcount
Pick a plan for the features you need, then add apps as you grow. Viewers are never charged per seat: the price is the same whether 10 teammates or 10,000 employees sign in. Every plan starts with a 14-day trial, no credit card required.
Starter
Get one site private, instantly.
$29 /mo
Billed monthly.
$290 /yr
2 months free, about $24 a month.
- 1 site
- 1 app No extra apps on this plan. Upgrade to add more.
- Email one-time-code authentication
- Custom domains
- Unlimited viewers
Pro
Most popularFull SSO for your workforce.
$99 /mo
Billed monthly.
$990 /yr
2 months free, about $83 a month.
Everything in Starter, plus:
- 5 apps included Extra apps $15 each a month.
- Google or Microsoft SSO
Business
Built for compliance reviews.
$299 /mo
Billed monthly.
$2,990 /yr
2 months free, about $249 a month.
Everything in Pro, plus:
- 3 sites
- 15 apps included Extra apps $12 each a month.
- Custom SSO (OIDC)
- Access logs (30 days)
- Audit logs (30 days)
Enterprise
Custom terms at any scale.
Custom
Priced to your volume.
Everything in Business, plus:
- Any number of sites
- Any number of apps
- Access logs (365 days)
- Audit logs (365 days)
- SIEM export
Prices exclude VAT. VAT is added where applicable.
Frequently asked questions
Couldn't I just build this myself?
You could, but why build something custom that you have to design and, more importantly, maintain? An auth gate is a security-critical service: every patch, provider change, and incident is yours for as long as the site exists, and none of it is the work that actually brings you value. BehindGate is that service, already built and looked after, live in under 15 minutes. Spend the time on your real job instead.
Is email one-time-code access secure enough?
Email codes are a fast way to get started, not the final security tier. They let you go live without waiting on an admin. For anything sensitive, upgrade the site to Entra, Google, or your own OIDC provider. Once SSO is on, email access is turned off, so there's no weaker way in. The Business plan requires SSO outright.
Do you store our users or directory?
No. Access is delegated to your identity provider, and we never hold your user list. Your provider's MFA, conditional access, group membership, and offboarding govern who gets in, and removing someone there removes their access here.
Can I host an AI-generated dashboard or app?
Yes. Anything that builds to a static front-end works (data baked in or fetched client-side). Deploy the output from your AI agent, CI, or the CLI. We host static sites; we don't run a backend for you.
What happens when the trial ends?
Your content stays private. It's never moved to a BehindGate-owned URL or made public. Visitors see a trial-ended page on your own domain until you choose a plan, and you can extend the trial yourself a couple of times if setup ran long.
Fifteen minutes of setup. Years of publishing.
Point one CNAME, connect the SSO you already run, and you're done. Every site published after that is private to your company by default, whether you set it up for your own team or for everyone else's.
14-day trial · no credit card required