Always-on authentication.

Secure online access with no user action.

No passwords, no prompts, no MFA codes, and thus nothing for attackers to steal or hijack.

One year of MagicEndpoint, on us: we deploy it, you enjoy it.

Apply by September 30, 2026. Limited availability.

FIPS 140-3
FIDO2 Certified
Proudly Canadian since 1997

Who is eligible to apply:

Ontario's broader public sector, as covered by Bill 194:

Hospitals and health organisations

School boards

Colleges and universities

Municipalities

Provincial agencies

Children's aid societies

Not sure whether Bill 194 covers you? Apply anyway, we will give you feedback.

The offer

12 months of
MagicEndpoint, on us.

Support with deployment.

No long-term commitment
after 12 months.

What you get

After a one-time OS login, no further user action is needed: users move through the applications behind your identity provider without passwords or prompts. The result is a better user experience, increased security, and frictionless online access. MagicEndpoint works with the IAM you already own, or on its own.

No user action

Frictionless online access: no passwords to remember, no prompts to answer, no help-desk tickets for password resets.

Always-on authentication

User, device and security conditions are continuously verified, not once at login.

Nothing new to manage

No physical security keys. The credential lives in hardware your people already carry.

From Canadian, for Canadian

Get it free from Canadians.

Your mandate says Buy Canadian. We offer something better: Canadian security, at 0 cost.

Governments and companies around the globe have trusted WinMagic with their endpoints since 1997. We care about the protection of Canada's public sector, and we want to support Ontario's public organisations.

NSA certified, 2000 FIPS 140-3

We deploy it for you

Our commitment

Authentication that never stops verifying and requires no user action.

We deploy it for you. Our engineers handle installation, integration, and support.

Your commitment

Your feedback on our product. (without One working day of your team's time to active it).

Day 0
You sign
If chosen, you get a full year of MagicEndpoint for your organisation, at no cost.
Weeks 1–6
We deploy
We deploy We help with deployment and support. You just need to activate it.
Months 1–12
In production
A year is long enough to stop noticing the technology and start noticing its absence. Your people stop typing passwords; your help desk stops resetting them.
Month 9
Check-in
We ask for your honest feedback, with no commitment attached. If the year has treated you well, we would be glad to discuss a longer partnership.
Month 12
You decide
By the end you will know, in production and against your real users, what it feels like when authentication stops interrupting them. And whether going back is something you could accept.
Apply now

Limited availability.

Frequently asked questions (FAQ)

What is MagicEndpoint?

A continuous authentication platform that verifies the user, device and conditions without requiring repeated user interaction. Learn more here.

What is Bill 194?

Ontario’s Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024. It is law, its cyber security regulations are in force, and it requires broader-public-sector organisations to complete a cyber security maturity assessment by July 1, 2027. The assessment covers, among other things, how your people authenticate. This program puts a deployed, measurable answer in place before that date.

What do we ask in return?

Here is what we would like to get in return for one year of MagicEndpoint on us:

  • A named sponsor and a named technical owner.
  • Use of your name as a customer.
  • One case study. You approve every word, and you can require it be anonymous.
  • One conference session or webinar with us in the first year.
  • An honest check-in at month nine (with us, not the public), whether you continue or not.

What happens at month twelve?

The price for years two and three is written into the agreement you sign at the start, at half our list price for the endpoints in the pilot. You are not agreeing to pay it. You are agreeing that if you want to continue, you already know the number and nobody has to negotiate anything. If you don’t want to continue, you uninstall it and we shake hands. We will still ask for the month-nine check-in, because a deployment that did not convince you is worth more to us than a polite silence.

What happens when a laptop is lost, broken, or being reimaged?

This is the question that decides passkey projects, so we will answer it before you ask. Every user in the pilot enrols our phone app at the start: if the laptop is gone, they authenticate from the phone. If the phone has gone as well, their manager approves access under a policy you set. No password resets in either path, and both are configured before the first user is enrolled rather than after the first person is locked out. The reason this works for us and not for a hardware key: your people cannot forget the endpoint, because it is what they need to do their work at all. A security key is an extra object with no other purpose, so it gets left at home constantly and fallback becomes a daily event with a cost attached. Ours stays rare enough to be a human process.

The reason this works for us and not for a hardware key: your people cannot forget the endpoint, because it is what they need to do their work at all. A security key is an extra object with no other purpose, so it gets left at home constantly and fallback becomes a daily event with a cost attached. Ours stays rare enough to be a human process.

We already run SecureDoc. Does this apply to us?

Yes. MagicEndpoint is a separate product from your SecureDoc encryption, and nothing about your encryption changes. If you trust us with your data at rest, this is the same standard applied to your logins.

The fine print

lots are given on a first-come, first-served basis. Deployment has to take place within 120 days of the agreement, or the slot goes to the next organisation on the list. The agreement is a no-cost agreement with no purchase order.

How do I apply?

Fill out the application form; the link will appear here shortly. For questions, write to us at founding@winmagic.com .

keyboard_arrow_up