🍎 We’re heading back to JNUC! For the second year in a row, Smallstep is proud to sponsor JNUC and support our partners at Jamf for another incredible week with the Apple community! We’re looking forward to catching up with customers and partners, meeting more of the MacAdmins community, and talking all things Apple security, device identity, and passwordless access. Stop by our booth to see how Jamf + Smallstep bring device posture and hardware-attested identity together, helping organizations give trusted devices secure, certificate-based access to Wi-Fi, VPNs, SSH, applications, and more. 🔐🍎 And, of course, we’ll have plenty of Smallstep swag. 😎 Huge thanks to the Jamf team for continuing to bring this community together. We’re excited to be back and can’t wait to see everyone in Kansas City! 🌆 📍 Kansas City | September 23–25 👋 Find Smallstep at Booth #115 #JNUC2026 #JNUC #Jamf #MacAdmins #AppleIT #DeviceIdentity #Cybersecurity #IdentitySecurity
Smallstep
Computer and Network Security
San Francisco, CA 2,494 followers
Ensure that access to corporate resources is only possible from trusted infrastructure with Smallstep Device Identity
About us
Ensure that only company-owned devices can access financial data, code repositories, PII, SaaS apps, and other sensitive resources with hardware-bound credentials.
- Website
-
https://smallstep.com/
External link for Smallstep
- Industry
- Computer and Network Security
- Company size
- 11-50 employees
- Headquarters
- San Francisco, CA
- Type
- Privately Held
- Founded
- 2016
- Specialties
- Identity, Security, mTLS, PKI, open-source, SSH, certificate management, and Zero Trust
Locations
-
Primary
Get directions
San Francisco, CA 94110, US
Employees at Smallstep
Updates
-
As our founder Michael Malone often says, hacking has never been cheaper and phishing has never been easier. 🎣 So next week, we’re giving him and Sr. Staff Engineer Carl Tashian the mic to riff on exactly that. No overly scripted presentation. No death by PowerPoint. Just a conversation about how dramatically the economics of cyberattacks have changed and why many of the security assumptions we’ve relied on haven’t changed with them. Today, attackers have access to off-the-shelf phishing kits, automated tooling, cheap infrastructure, and increasingly sophisticated AI. You don’t need to be an elite hacker to launch an effective attack anymore. And when a stolen credential is still enough to get through the door, that’s a problem. Join Mike Malone, CEO & Founder, and Carl Tashian, Sr. Staff Engineer, for the end of our webinar summer series: Hacking Has Never Been Cheaper, and Phishing Has Never Been Easier! Expect a candid conversation on what they’re seeing in the industry, why phishing continues to work so well, how the attacker playbook is evolving, and what it actually takes to build security around something stronger than a login. Bring your questions. We have a feeling this one could go in a few interesting directions. 👀 👉 Save your seat: https://hubs.ly/Q04tdpx_0 #Cybersecurity #Phishing #IdentitySecurity #DeviceIdentity #AI
-
-
🎉 Black Hat USA 2026 is officially underway! We're kicking off the week at the Welcome Reception, catching up with familiar faces, meeting new ones, and getting excited for everything the week has in store! If you're here in Las Vegas, come find the Smallstep team throughout the week at Booth #5111 near the AI Zone. Stop by for: 🎮 Interactive touchscreen demos 💬 Conversations around device identity, AI security, phishing-resistant authentication, and modern PKI 🧢 And short lived Yeti tumblers, Las Vegas hats, Trust Me keychains, and of course our iconic sticker wall! Here's to another incredible week of learning, connecting, and talking all things cybersecurity. If you see someone in a Smallstep hat or shirt tonight, come say hello! 👋 #BlackHatUSA #Cybersecurity #InfoSec #DeviceIdentity #AI #IdentitySecurity
-
-
We are SO ready. The booth is built. 🔨 The demos are polished. 💻 The swag is ready. 🧢 And tomorrow evening, it all begins. We're excited to kick off Black Hat USA 2026 at the Welcome Reception before a full week of connecting with the cybersecurity community. If you're heading to Las Vegas, be sure to stop by Booth #5111 near the AI Zone. Here's what we've got in store: 🎮 Interactive touchscreen demos 🤖 An exclusive MFA for AI theater session 📶 Live demos of passwordless Enterprise Wi-Fi with Device Identity 💬 Great conversations about AI security, phishing-resistant authentication, modern PKI, and device identity 🎁 Plus some awesome short-lived swag Whether you're a longtime customer, partner, or just curious about what we're building, we'd love to meet you! Who's ready for an incredible week at Black Hat? See you tomorrow evening at the Welcome Reception! 🎉 #BlackHatUSA #Cybersecurity #InfoSec #AI #DeviceIdentity #IdentitySecurity #MFAForAI
-
-
⏳ Are you ready for Black Hat USA 2026? One week from today, the Welcome Reception kicks off, the expo floor starts filling up, and another incredible week of cybersecurity conversations begins! 🤩 The Smallstep team is all packed up and ready for a busy week in Las Vegas! 🎰 Come visit us at Booth #5111 near the AI Zone, where you'll find: 🎮 Interactive touchscreen demos 🤖 Our exclusive MFA for AI theater session 📶 Live demos of passwordless Enterprise Wi-Fi with device identity 💬 Plenty of opportunities to chat with our team about device identity, phishing-resistant authentication, AI security, and modern PKI And yes... we'll have some awesome swag waiting for you, too. 👀 If Black Hat is on your calendar, let us know in the comments, we'd love to connect! See you at Mandalay Bay! 👋 #BlackHatUSA #BlackHat2026 #Cybersecurity #InfoSec #DeviceIdentity #AI #ZeroTrust
-
-
🚨 A password isn't the prize anymore. Today's phishing attacks don't stop at stealing credentials. Modern phishing kits can capture sessions, intercept tokens, and turn a single successful login into immediate access. Tools like OpenClaw are making these attacks easier than ever to deploy and it raises an important question.... If attackers no longer need your password, are your authentication defenses still enough? Join us tomorrow at 12:00 PM ET / 9:00 AM PT as Carl Tashian, Sr. Staff Engineer, and Ted Malone, VP of Marketing & GTM, pull back the curtain on how modern phishing kits actually work, why traditional login-based security is falling behind, and what organizations can do to stay ahead. We'll cover: 🔐 How tools like OpenClaw are redefining phishing ⚠️ Why sessions and tokens have become the new target 🛡️ Why protecting logins alone is no longer enough 💡 What modern, phishing-resistant authentication looks like If you're responsible for identity, security, or IT, this is a conversation you won't want to miss. 📅 Tomorrow | 12:00 PM ET / 9:00 AM PT 👉 Register here: https://hubs.ly/Q04qTVHn0 #Cybersecurity #Phishing #IdentitySecurity #ZeroTrust #Authentication #OpenClaw
-
🎰 The countdown is on and we are officially 12 days away from seeing you all at Black Hat in Viva Las Vegas! After a few years on the conference circuit, we've learned that surviving a week in Vegas takes more than just a conference badge. So we put together our Smallstep Black Hat USA 2026 Survival Pack 👉 AKA everything we consider essential for making it through long expo days, countless conversations, and a packed meeting schedule. Did we miss anything? What's always in your conference survival kit? If you're heading to Las Vegas, stop by Booth #5111 near the AI Zone. We'd love to show you our interactive demos, chat about device identity and AI security, and, of course, send you home with some awesome Smallstep swag. 😎 See you at Black Hat! 👋 #BlackHatUSA #Cybersecurity #InfoSec #ConferenceLife #Vegas #DeviceIdentity #AI
-
-
Every once in a while, a remote team needs to trade video calls for whiteboards, coffee chats, and face-to-face conversations. 🫸💥🫷 This week, the Smallstep team is together to collaborate, align, and plan for what's ahead! While we're spread across the globe most of the year, there's something special about getting everyone in the same room. The best ideas often come from the conversations between meetings, a quick sketch on a whiteboard, or grabbing lunch together. 🥙 We've also found ourselves in a pretty incredible city... 👀 Here are a few clues: 🌊 It's home to one of the largest freshwater lakes in the U.S. 🍦 It's just a stone's throw away from the original Ben & Jerry's factory. 🚲 It's consistently ranked as one of the most bike-friendly cities in the country. 🍁 It's surrounded by mountains, craft breweries, and some of New England's best scenery. Can you get past the blurred photo and figure out where we are? Drop your guess in the comments! 👇 #RemoteWork #TeamOffsite #Teamwork #Collaboration #LifeAtSmallstep
-
-
🎰 Las Vegas, we're almost there! In just a few short weeks, the Smallstep team will be heading to Black Hat USA 2026, and we're bringing more than just swag. 🕶️ 📍 Visit us at Booth #5111, right next to the AI Zone, to see how hardware-attested device identity is changing the way organizations secure users, devices, workloads, and AI. Here's what you'll find at our booth: 🎮 Interactive touchscreen demos you can explore at your own pace 🤖 An exclusive MFA for AI theater session on securing AI agents and non-human identities 📶 Live demos of passwordless Enterprise Wi-Fi with device identity 💻 Real-world use cases for VPN, SSH, SaaS, and Zero Trust access 💬 Plenty of opportunities to chat with our team about modern identity and certificate management And yes... we'll have some awesome swag too. 👀 🎩 Custom Las Vegas patch hats 🔑 Limited-edition keychains ☕ YETI cups and speakers (while supplies last!) Whether you're exploring AI security, modern PKI, or looking to eliminate passwords and shared secrets, we'd love to meet you. See you August 3–6 at Mandalay Bay! #BlackHatUSA #Cybersecurity #AI #DeviceIdentity #ZeroTrust #MFAForAI #PKI #IdentitySecurity
-
-
Smallstep reposted this
Missed our MFA for AI webinar? The full recording is now available! 🎥 Before you hit play, here's the one idea we think changes how you look at AI security: Authentication isn't just a feature of your AI stack. It's the foundation of its security model. Every AI agent running on a static API key is a credential waiting to be exfiltrated. Every MCP server accepting long-lived tokens is a blast radius waiting to expand. The industry has been here before...with service accounts, API keys, and shared secrets, and the fix is always the same: replace implicit trust with cryptographic identity. That's what MFA for AI is really about. Not adding a second factor to a chat interface. Giving every agent, every runtime, and every model call a verifiable, hardware-backed identity, so you know what is accessing your systems, not just that something is. Watch the recording to learn why the future of AI security starts with identity! 🤖🔒 🎥 Watch on demand: https://hubs.ly/Q04nDlfw0 #Cybersecurity #AI #MFAForAI #IdentitySecurity #AIAgents #MCP #DeviceIdentity
-