Our position on single sign-on

Single sign-on is included. Here is why.

In February 2025, our founder wrote about the SSO tax: vendors charging a premium for the one control that does the most to protect an organization's accounts. Writing that was the easy part. Building a company that lives by it is the harder part.

So here is where QRbolt landed. Single sign-on is included on every plan that supports more than one person. No enterprise tier requirement. No per-seat surcharge. No minimum team size. It connects to any standards-compliant identity provider, and organization admins can enforce it and switch password login off entirely.

Read the 2025 article: The hidden cost of security

Three reasons this matters more than a line item on a pricing page

Shadow access

When someone leaves, you disable one identity in your identity provider and their QRbolt access ends with it. Without SSO, offboarding depends on somebody remembering that QRbolt exists. That is not a process, that is a hope.

One less password

NIST SP 800-63-4, published in final form in August 2025, sets a 15-character minimum for passwords used on their own and permits 8 when the password sits behind MFA, with no composition rules and no forced periodic rotation. Every additional password you ask a person to invent is another chance they reuse one already sitting in a breach corpus. The Verizon 2026 DBIR found users are roughly four times more likely to reuse a compromised password than to pick a technically weak one, and credential abuse appears in 39 percent of breaches.

One MFA chain

With SSO enforced, your MFA policy travels with it. Your conditional access, your phishing-resistant factors, your session rules. QRbolt does not become a second, weaker authentication path around the policy your team already fought to implement.

“Security should not be priced as a luxury good but instead should be considered a customer right.”

CISA, “Why SMBs Don't Deploy Single Sign-On (SSO)”, June 2024. The same guidance adds that single sign-on capability should be available by default as part of the base offering.

We agreed with that then. We priced for it now.

Sources

  • Marko Sarunac, “The hidden cost of security: why vendors should stop charging for single sign-on (SSO)”, 2025. Read it.
  • sso.tax, the running list of vendors that charge extra for SSO. sso.tax
  • CISA, “Barriers to Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses”, released June 20, 2024.
  • NIST SP 800-63-4 / SP 800-63B-4, published in final form on August 1, 2025.
  • Verizon 2026 Data Breach Investigations Report.

See it on every multi-user plan

No enterprise tier. No surcharge. Our team configures the connection with you.

Back to pricing