Our position on single sign-on
In February 2025, our founder wrote about the SSO tax: vendors charging a premium for the one control that does the most to protect an organization's accounts. Writing that was the easy part. Building a company that lives by it is the harder part.
So here is where QRbolt landed. Single sign-on is included on every plan that supports more than one person. No enterprise tier requirement. No per-seat surcharge. No minimum team size. It connects to any standards-compliant identity provider, and organization admins can enforce it and switch password login off entirely.
Read the 2025 article: The hidden cost of securityWhen someone leaves, you disable one identity in your identity provider and their QRbolt access ends with it. Without SSO, offboarding depends on somebody remembering that QRbolt exists. That is not a process, that is a hope.
NIST SP 800-63-4, published in final form in August 2025, sets a 15-character minimum for passwords used on their own and permits 8 when the password sits behind MFA, with no composition rules and no forced periodic rotation. The reasoning behind that shift is that reuse, not complexity, is what actually breaks passwords in practice. Every additional password you ask a person to invent is another chance they reuse one already sitting in a breach corpus. Single sign-on removes the password from the equation for your team entirely.
With SSO enforced, your MFA policy travels with it. Your conditional access, your phishing-resistant factors, your session rules. QRbolt does not become a second, weaker authentication path around the policy your team already fought to implement.
“Security should not be priced as a luxury good but instead should be considered a customer right.”
We agreed with that then. We priced for it now.