No user action
Frictionless online access: no passwords to remember, no prompts to answer, no help-desk tickets for password resets.
No passwords, no prompts, no MFA codes, and thus nothing for attackers to steal or hijack.
One year of MagicEndpoint, on us: we deploy it, you enjoy it.
Apply by September 30, 2026. Limited availability.
Ontario's broader public sector, as covered by Bill 194:
Hospitals and health organisations
School boards
Colleges and universities
Municipalities
Provincial agencies
Children's aid societies
Not sure whether Bill 194 covers you? Apply anyway, we will give you feedback.
12 months of
MagicEndpoint, on us.
Support with deployment.
No long-term commitment
after 12 months.
After a one-time OS login, no further user action is needed: users move through the applications behind your identity provider without passwords or prompts. The result is a better user experience, increased security, and frictionless online access. MagicEndpoint works with the IAM you already own, or on its own.
Frictionless online access: no passwords to remember, no prompts to answer, no help-desk tickets for password resets.
User, device and security conditions are continuously verified, not once at login.
No physical security keys. The credential lives in hardware your people already carry.
Your mandate says Buy Canadian. We offer something better: Canadian security, at 0 cost.
Governments and companies around the globe have trusted WinMagic with their endpoints since 1997. We care about the protection of Canada's public sector, and we want to support Ontario's public organisations.
Our commitment
Authentication that never stops verifying and requires no user action.
We deploy it for you. Our engineers handle installation, integration, and support.
Your commitment
Your feedback on our product. (without One working day of your team's time to active it).
Limited availability.
A continuous authentication platform that verifies the user, device and conditions without requiring repeated user interaction. Learn more here.
Ontario’s Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024. It is law, its cyber security regulations are in force, and it requires broader-public-sector organisations to complete a cyber security maturity assessment by July 1, 2027. The assessment covers, among other things, how your people authenticate. This program puts a deployed, measurable answer in place before that date.
Here is what we would like to get in return for one year of MagicEndpoint on us:
The price for years two and three is written into the agreement you sign at the start, at half our list price for the endpoints in the pilot. You are not agreeing to pay it. You are agreeing that if you want to continue, you already know the number and nobody has to negotiate anything. If you don’t want to continue, you uninstall it and we shake hands. We will still ask for the month-nine check-in, because a deployment that did not convince you is worth more to us than a polite silence.
This is the question that decides passkey projects, so we will answer it before you ask. Every user in the pilot enrols our phone app at the start: if the laptop is gone, they authenticate from the phone. If the phone has gone as well, their manager approves access under a policy you set. No password resets in either path, and both are configured before the first user is enrolled rather than after the first person is locked out. The reason this works for us and not for a hardware key: your people cannot forget the endpoint, because it is what they need to do their work at all. A security key is an extra object with no other purpose, so it gets left at home constantly and fallback becomes a daily event with a cost attached. Ours stays rare enough to be a human process.
The reason this works for us and not for a hardware key: your people cannot forget the endpoint, because it is what they need to do their work at all. A security key is an extra object with no other purpose, so it gets left at home constantly and fallback becomes a daily event with a cost attached. Ours stays rare enough to be a human process.
Yes. MagicEndpoint is a separate product from your SecureDoc encryption, and nothing about your encryption changes. If you trust us with your data at rest, this is the same standard applied to your logins.
lots are given on a first-come, first-served basis. Deployment has to take place within 120 days of the agreement, or the slot goes to the next organisation on the list. The agreement is a no-cost agreement with no purchase order.
Fill out the application form; the link will appear here shortly. For questions, write to us at founding@winmagic.com .