Our position on single sign-on
In February 2025, our founder wrote about the SSO tax: vendors charging a premium for the one control that does the most to protect an organization's accounts. Writing that was the easy part. Building a company that lives by it is the harder part.
So here is where QRbolt landed. Single sign-on is included on every plan that supports more than one person. No enterprise tier requirement. No per-seat surcharge. No minimum team size. It connects to any standards-compliant identity provider, and organization admins can enforce it and switch password login off entirely.
Read the 2025 article: The hidden cost of securityWhen someone leaves, you disable one identity in your identity provider and their QRbolt access ends with it. Without SSO, offboarding depends on somebody remembering that QRbolt exists. That is not a process, that is a hope.
NIST SP 800-63-4, published in final form in August 2025, sets a 15-character minimum for passwords used on their own and permits 8 when the password sits behind MFA, with no composition rules and no forced periodic rotation. Every additional password you ask a person to invent is another chance they reuse one already sitting in a breach corpus. The Verizon 2026 DBIR found users are roughly four times more likely to reuse a compromised password than to pick a technically weak one, and credential abuse appears in 39 percent of breaches.
With SSO enforced, your MFA policy travels with it. Your conditional access, your phishing-resistant factors, your session rules. QRbolt does not become a second, weaker authentication path around the policy your team already fought to implement.
“Security should not be priced as a luxury good but instead should be considered a customer right.”
We agreed with that then. We priced for it now.