
We came to NewCore primarily looking for a better SSO and human identity solution, not because we were chasing the agentic AI angle, but because our existing setup had accumulated enough technical debt and security compromises that it needed replacing properly rather than patched again. What we found was an identity platform that, for the first time in a while, felt like it was built with actual security intent rather than access convenience with security retrofitted around it.
The dominant identity platforms were architected fifteen years ago for a world of employees logging into web apps, built on aging protocols like SAML and password-derived session tokens that were never designed to serve as a security perimeter. That description maps exactly to what we were running before. NewCore's approach to that problem doesn't feel incremental, the foundations are genuinely different.
The SSO experience for end users is clean and fast. Login flows feel modern without being unfamiliar, and the transition from our previous setup was smoother than we expected given how fundamental an identity migration is. The platform preserves existing federations and policies during migration, which meant we avoided downtime entirely, something we were quietly dreading going in.
The split-key architecture is the security detail that stood out most on the human identity side, the signing key is divided between NewCore and our own perimeter, meaning neither side can sign alone, and a compromised vendor cannot forge a token. For a team that has spent enough time reading breach post-mortems to know how often SSO providers themselves become the attack vector, that architectural decision resonates in a way that marketing copy usually doesn't.
VisualMFA is another standout turning user verification into an out-of-band, visually verifiable exchange that resists relay, replay, and social engineering is a meaningful step beyond the standard push-notification MFA flow that most platforms still rely on. Hardware-bound credentials anchored in TPM and Secure Enclave replace phishable factors entirely, which again feels like a genuine architectural improvement rather than a feature checkbox.
The AI-powered account recovery is a surprisingly thoughtful detail locked-out employees are verified through challenges sourced from their own recent calendar, HR, and activity data, events only the real user could answer, without opening an IT ticket or pulling an analyst. Small thing in isolation, but it signals the right thinking throughout. Review collected by and hosted on G2.com.
Being an early customer of a platform that only emerged from stealth in mid-2026 comes with honest trade-offs worth flagging for anyone evaluating it now.
The product is clearly still maturing. Some workflows that feel polished in the core SSO and authentication layer get noticeably thinner when you push into adjacent areas, reporting depth, admin console flexibility, and fine-grained policy customisation all feel like they're a few iterations away from where they need to be for larger or more complex environments.
Documentation is functional but sparse in places. For a security product where configuration decisions have real consequences, there are moments where you're making judgement calls without enough reference material to feel fully confident, and support, while responsive, is a small team that reflects the company's early stage.
The integration ecosystem is narrower than established players right now. If your stack leans heavily on less common applications or legacy enterprise tooling, expect some connectors to be missing or requiring custom work to bridge.
Pricing conversations also reflect the early stage, there's no transparent self-serve pricing structure yet, which makes budgeting harder than it should be and adds friction to the evaluation process for teams that need to move quickly. Review collected by and hosted on G2.com.