For Ontario’s Public Sector

Unmatched Security

Always-on authentication
with NO USER ACTION

Free for a year. We deploy it, you enjoy it.

Apply by September 30, 2026. Limited availability.

FIPS 140-3
FIDO2 Certified
Proudly Canadian since 1997

Why It Works

STRONGER THAN ANYTHING TODAY

The device you use to go online is now empowered to protect. It becomes your self-driving car in online traffic, always with you, navigating safely with cryptographic defense, protecting you in real time, in milliseconds, all without your action.

Friction does not equal security.

Old models make you prove “what you know, have, or are.” We add “How you got here”, your journey and context, so trust becomes adaptive, context-rich, and timeline-aware, practically impossible for attackers to spoof, while you just do what you normally do.

And because there’s no user action, phishing and AI-driven attacks fail.

There’s nothing to steal, no passwords, no tokens, no phone resets. Even helpdesk password resets, a common vulnerability, disappear.

How It Works

MagicEndpoint continuous authentication and endpoint security

Your endpoint verifies you at desktop login and establishes a persistent, cryptographically secured channel to the IdP from power-on to power-off. Through this channel, it sends real-time updates on user identity, screen lock status, device posture, compliance signals, even user intent.

The IdP uses timeline, history, and continuous intelligence to evaluate every access request dynamically, without relying on vulnerable static SSO tokens.

And because the endpoint is empowered, it goes beyond sign-ins managed by your identity provider. The endpoint can sign in to older applications that still use usernames and passwords, without user action.

Who shall apply:

Ontario's broader public sector, as covered by Bill 194:

Hospitals and health organisations

School boards

Colleges and universities

Municipalities

Provincial agencies

Law enforcement

Not sure whether Bill 194 covers you? Apply anyway, we will give you feedback.

The offer

12 months of
MagicEndpoint, on us.

Support with deployment.

Your honest feedback.
No other commitment.

What you get

After an OS login, no further user action is needed: users move through the applications behind your identity provider without passwords or prompts. The result is a better user experience, increased security, and frictionless online access. MagicEndpoint works with the IAM you already own, or on its own.

No user action

Frictionless online access: no passwords to remember, no prompts to answer, no help-desk tickets for password resets.

Always-on authentication

User, device and security conditions are continuously verified, not just once at login.

Nothing new to manage

No physical security keys. The credential lives in hardware your people already carry.

From Canadians, for Canadians

Get it free from Canadians.

Your mandate says Buy Canadian. We offer something better: Canadian security, at 0 cost.

Governments and companies around the globe have trusted WinMagic with their endpoints since 1997. We care about the protection of Canada's public sector, and we want to support Ontario's public organisations.

NSA certified, 2000 FIPS 140-3

We deploy it for you

Our offer

Authentication that never stops verifying and requires no user action.

We deploy it for you. Our engineers handle installation, integration, and support. Our requirement is a minimum of 50 seats.

Your commitment

We will ask for your feedback & publish a case study you preapprove.

Day 1
You sign up
If chosen, you get a full year of MagicEndpoint for your organisation, at no cost.
Weeks 1–6
We deploy
We help with deployment and support. All we need is around 8 hours from your team side to learn about your environment.
Month 6
Check-in
We ask for your honest feedback. By now, your users should stop missing the interruptions associated with other authentication methods and start enjoying MagicEndpoint No User Action concept.
Month 12
You decide
The decision is all yours: either revert to your old solution with all its hassles and lack of security or deploy MagicEndpoint to all your endpoints.
Apply now

Limited availability.

Frequently asked questions (FAQ)

What is MagicEndpoint?

A continuous authentication platform that verifies the user, device and conditions without requiring repeated user interaction. Learn more here.And read our latest blog: The industry gives the warning. WinMagic gives the fix

What is Bill 194?

Ontario’s Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024. It is law, its cyber security regulations are in force, and it requires broader-public-sector organisations to complete a cyber security maturity assessment by July 1, 2027. The assessment covers, among other things, how your people authenticate. MagicEndPoint puts a deployed, measurable answer in place before that date.

What do we ask in return?

Here is what we would like to get in return for one year of MagicEndpoint on us:

  • A named sponsor and a named technical owner.
  • Use of your name as a customer.
  • One case study, that we will send to you for review and approval and you can choose to be anonymous.
  • One conference session or webinar with us in the first year.
  • An honest check-in at month six with us, whether you continue or not.

What happens at month twelve?

The pricing for years 2 and 3 for MagicEndpoint is provided from Day 1. At the end of the program, you can choose to continue at the agreed price or uninstall.

We already run SecureDoc. Does this apply to us?

Yes. MagicEndpoint is a separate product and will not affect your usage of SecureDoc encryption.

The fine print

Applications are accepted on a first-come, first-served basis. Deployment needs take place within 60 days of the agreement, or the offer goes to the next applicant on the list. The agreement is a no-cost agreement with no purchase order.

How do I apply?

Fill out the application form; the link will appear here shortly. For questions, write to us at ForCanada@winmagic.com .

keyboard_arrow_up