INTERNAL APP PLATFORM

One door for every app your colleagues build.

Right now, someone at your company is running a self-built app with no login in front of it. cyantula puts your Google Workspace door in front of every one, and runs it behind that door, with the integrations already wired in.

THE PROBLEM

Colleagues build apps faster than anyone can secure them

Your colleagues now build small web apps themselves, most of them AI-generated, and almost none of those apps handle authentication. Running one somewhere reachable is risky, so it stays on a laptop, lives in a shared folder, or never gets shared at all. IT cannot review every app by hand, and the person who wrote a tool in an afternoon should not have to bolt login, deploys, backups and a key policy on top of it. That gap is where cyantula starts.

A self-built internal tool open on a laptop, with no login in front of it

THE PLATFORM

What cyantula does

cyantula sits in front of every app as an authenticating gateway and runs the app behind it. Four things come standard, so the builder never has to.

One door, no password in the app

Google login locked to your Workspace domain. Every request arrives with verified identity headers (email, name, role) and a signed token, so the app never implements login.

Integrations belong in the platform

Deploys, rollback, backups, mail, Slack, Jira, an LLM, cron and usage stats sit in the platform once and switch on per app with a tick.

The wall and the engine, in one product

cyantula authenticates the visitor and runs the app behind it. No stitching a PaaS to a proxy to get both halves.

Built to be operated by an AI agent

An MCP server lets Claude Code and other agents publish, repair and manage apps through the same door, with the same governance as a person.

SECURITY BY DEFAULT

Proof, not adjectives

The app never sees a password. cyantula signs who the user is and a client cannot forge it.

Zero credentials reach the app: the gateway strips every client-sent identity header before the request arrives.

In 2026, self-built apps that skip authentication are a real security problem, not a hypothetical one. cyantula closes that gap by default, not as an option you have to remember to switch on.

Verified identity block, per request

X-cyantula-Email: emma@acme.com

X-cyantula-Name: Emma Devos

X-cyantula-Role: analyst

The gateway strips every identity header a client sends and replaces it with verified ones.

WHERE WE ARE

Onboarding our first ten teams by hand

cyantula is in early access in 2026. There is no self-serve signup: a person walks you through your first apps, so you know exactly what runs behind your login before it does. Built for teams where one IT person can no longer review every app by hand.

See how cyantula compares to the tools you know

Put a door in front of every app your team builds

Book a demo for a walk-through with a person, or ask for early access to be one of the first teams we onboard by hand. We answer within a working day.