Zitadel

Zitadel

AGPL-3.0 IAM platform from Switzerland โ€” SOC 2 Type II and ISO 27001:2022 verified on the SaaS tier; self-hosted edition has no MAU limits, B2B multi-tenancy and SAML included.

๐Ÿฉบ Vitals


๐Ÿ—๏ธ Profile

1. The Executive Summary

What is it? ZITADEL is an open-source Identity and Access Management platform built in Go by CAOS Ltd. (St. Gallen, Switzerland). It provides authentication and authorization infrastructure for multi-tenant B2B SaaS environments โ€” OIDC, SAML, SCIM, MFA, FIDO2/Passkeys, and delegated role management are all included in the self-hosted Community Edition at no cost. Its event-sourcing architecture means every authentication and authorization state change is written to an immutable log, providing a built-in audit trail without additional tooling. ZITADEL Cloud (SaaS) carries verified SOC 2 Type II (January 2026) and ISO 27001:2022 (June 2024) certifications. The enterprise tax on the SaaS tier is primarily around scale (100 DAU free tier limit), custom domains, geographic data residency selection, and SLA guarantees โ€” none of which apply to self-hosted deployments.

The Strategic Verdict:

2. The "Hidden" Costs (TCO Analysis)

Cost Component Auth0 (SaaS) Zitadel (Self-Hosted)
MAU Fees $0.07+/MAU overage $0 (Unlimited MAU)
B2B Multi-Tenancy Enterprise tier Native (Included)
SSO / SAML Enterprise tier Included (Default)
Data Residency Auth0-managed cloud Operator-controlled (VPC)
Audit Trail Paid log retention add-on Event-sourced (Immutable, Default)

3. The "Day 2" Reality Check

๐Ÿš€ Deployment & Operations

๐Ÿ›ก๏ธ Security & Governance (Risk Assessment)

4. Market Landscape

๐Ÿข Proprietary Incumbents

๐Ÿค Open Source Ecosystem