It is officially spooky season! 👻 From your internship days until now, what's the scariest security or password sharing method you've ever seen (or heard about)? The Wi-Fi password on a sticky note? The shared admin login saved in a spreadsheet called "passwords_FINAL"? The SSH key someone sent over Slack "just this once"? 👀 We've definitely heard of a few horror stories over the years, and we know you've got your own too. Drop yours in the comments below! No names needed, and no judgment... okay, maybe a little judgment. 👇🏼
Smallstep
Computer and Network Security
San Francisco, CA 2,519 followers
Ensure that access to corporate resources is only possible from trusted infrastructure with Smallstep Device Identity
About us
Ensure that only company-owned devices can access financial data, code repositories, PII, SaaS apps, and other sensitive resources with hardware-bound credentials.
- Website
-
https://smallstep.com/
External link for Smallstep
- Industry
- Computer and Network Security
- Company size
- 11-50 employees
- Headquarters
- San Francisco, CA
- Type
- Privately Held
- Founded
- 2016
- Specialties
- Identity, Security, mTLS, PKI, open-source, SSH, certificate management, and Zero Trust
Employees at Smallstep
Locations
-
Primary
Get directions
San Francisco, CA 94110, US
Updates
-
If your Wi-Fi still asks for a username and password, there's a good chance it's running on PEAP and MS-CHAPv2 under the hood. 📶 With Microsoft deprecating NTLM, a lot of the IT teams we talk to are finally using that as the push to move their Wi-Fi to certificates. It's become one of the most requested things we hear about on calls! The reason is simple. When a laptop gets stolen, you revoke its certificate and it's off the network. An IT director at a university told us that was the whole reason for switching, since nobody has to touch the user's Active Directory account to lock a device out. So why hasn't everyone done it already? Running your own CA and RADIUS server is a lot of work, and that's the part we take off your plate. Smallstep hosts both, so you point your access points at our RADIUS, push the Wi-Fi profile through your MDM, and only devices that can prove who they are get on the network. (And no, hiding your SSID doesn't count as security. 🙃) 👉 Learn how certificate-based Wi-Fi works with Smallstep here! https://hubs.ly/Q04yBLmn0
-
-
"We'd like to move off AD CS." We hear this on almost every call lately, and the very next question is usually the hardest one: what is it actually doing for you today? 😅 Most AD CS environments were set up years ago by someone who has since moved on. The certificate templates aren't documented, NDES is running on a server nobody wants to touch, and every Intune-managed device depends on it working. That's exactly why we don't start by ripping it out. Smallstep can take over what NDES does today, so your Windows devices keep getting certificates without anyone noticing a change. Once that's in place, you can start moving devices to ACME Device Attestation, where the certificate is bound to the device's TPM and can't be copied off the machine. No big-bang migration. No weekend outage. Just a way off AD CS that you can actually plan for! 🛠️ 👉 See how Smallstep replaces AD CS here! https://hubs.ly/Q04yBB020 👉AD CS vs Smallstep PKI ROI Calculator https://hubs.ly/Q04yBzWc0
-
-
Last night’s after party was the perfect cherry on top of an incredible few days in Kansas City. From cocktail hour to conversations with Jamf customers, partners, and friends, it was one of those nights that reminded us why we love being part of this community. A huge thank you to Jamf for bringing everyone together and putting on another amazing JNUC. We’re heading home with new connections, great conversations, and already looking forward to the next one! 💪 Until next year, JNUC! 👋🍎 #JNUC2026 #Jamf #MacAdmins #Smallstep
-
-
Day 2 of JNUC and we’re feeling right at home in Kansas City! ❤️ There’s something special about getting the Jamf community together in one place. We’re proud to be here for our second year sponsoring JNUC, supporting our partners at Jamf and spending time with the customers and teams we get to work alongside all year. And tonight, the fun continues at the JNUC After Party at CPKC Stadium! ⚽🎉 Last year’s party was LIT🔥, so we already know Jamf knows how to throw one. We can’t wait to get out of the booth, catch up with Jamf customers, and enjoy another night with this amazing community! If you’re at JNUC, come say hi at Booth #115 and snag a limited edition Kansas City hat! We can't wait to see you at the stadium tonight! 🍻 #JNUC2026 #Jamf #MacAdmins #KansasCity #Smallstep
-
-
Are you in Kansas City? 👀 Because we have plans for you today. JNUC Day 1 is officially on, and if you’re wandering the show floor, make Booth #115 one of your stops. Come for the limited-edition hats. Stay to see how we’re killing Wi-Fi passwords, putting hardware-backed identity behind your Apple fleet, and tackling the question everyone suddenly has: what happens to your identity strategy when AI agents start doing the work? 🤖 And at 4:20 PM today, our CTO Josh Drake is taking the Spotlight Theater stage for More Lessons from the Titans of Tech — going from Device Identity to Agentic Identity in less than 15 minutes. ⏰ We’ve got demos. We’ve got short-lived stickers. We’ve got opinions about passwords. 👀 Come hang out with us at booth 115! 🍎 #JNUC2026 #Jamf #MacAdmins #DeviceIdentity #AgenticAI
-
-
If you’re in Kansas City this week, stop by booth 115 to see the team and grab some swag!
JNUC week is officially here! 🍎🎉 The Smallstep team is heading to Kansas City for JNUC 2026, and we’re excited to be back for our second year sponsoring and supporting our partners at Jamf. Come find us at Booth #115 to: 🔐 Talk all things Device Identity, passwordless Wi-Fi, and hardware-backed access 🤖 See how we’re extending identity from devices to workloads and AI agents 🧢 Grab one of our limited-edition hats + short-lived stickers while they last 🎙️ Catch Josh Drake, CTO at Smallstep, on stage for More Lessons from the Titans of Tech: A Proprietor’s Guide to Device and Agentic Identity We’ll be there September 23–25. Come say hi, see what we’ve been building, and talk Device Identity with us! See you in Kansas City! 🍎🔥 #JNUC2026 #Jamf #DeviceIdentity #MacAdmins #AppleIT #AgenticAI
-
-
JNUC week is officially here! 🍎🎉 The Smallstep team is heading to Kansas City for JNUC 2026, and we’re excited to be back for our second year sponsoring and supporting our partners at Jamf. Come find us at Booth #115 to: 🔐 Talk all things Device Identity, passwordless Wi-Fi, and hardware-backed access 🤖 See how we’re extending identity from devices to workloads and AI agents 🧢 Grab one of our limited-edition hats + short-lived stickers while they last 🎙️ Catch Josh Drake, CTO at Smallstep, on stage for More Lessons from the Titans of Tech: A Proprietor’s Guide to Device and Agentic Identity We’ll be there September 23–25. Come say hi, see what we’ve been building, and talk Device Identity with us! See you in Kansas City! 🍎🔥 #JNUC2026 #Jamf #DeviceIdentity #MacAdmins #AppleIT #AgenticAI
-
-
AI agents are getting access to more than just information. They’re accessing APIs, calling tools, and taking action. 🤖 But as AI gets more access, there’s a fundamental identity question we need to answer: How do you prove what’s actually executing the request? Join J. Hunter Hawke, Sr. Solutions Architect, and Josh Drake, CTO at Smallstep, on September 29th at 9am PT / 12pm ET for our next webinar: Moving AI Agents Beyond OAuth Tokens with Hardware-Bound Identity! We’ll dig into why OAuth tokens and API keys alone aren’t enough for autonomous systems, how hardware-bound identity can secure AI agents and MCP servers, and demo what this looks like in a real AI workflow. Plus, we’ll share what we’ve learned from dogfooding this approach with Tsunami, Smallstep’s own internal AI fleet. 👀 💬 Have a question about AI agents, MCP, OAuth, or hardware-bound identity? Drop it in the comments! Josh and Hunter will review your questions and tackle some of them live during the webinar. Register now! 👇 https://hubs.ly/Q04x8_xt0.. #AgenticAI #AISecurity #DeviceIdentity #MCP #IdentitySecurity
-
-
#JNUC, we’re taking Device Identity into the age of AI. 🍎🤖 Last year, we explored how some of the world’s leading technology companies approach device identity. This year, we’re going one step further. Join Smallstep's CTO Josh Drake for: More Lessons from the Titans of Tech: A Proprietor's Guide to Device and Agentic Identity We’ll explore how organizations can extend the trust chain from human → device → workload → AI agent, and demo how Smallstep can establish hardware-backed trust for the devices and AI systems operating on them. Because trusted devices are only the beginning. 📅 Wednesday, September 23 ⏰ 4:20–4:35 PM CDT 📍 JNUC 2026 | Kansas City Heading to JNUC? Add the speaking session to your agenda here! https://hubs.ly/Q04whbX80 #JNUC2026 #Jamf #DeviceIdentity #AgenticAI #MacAdmins