Who we are.
B5 Secure LLC builds the security layer that .NET applications were missing — a Zero-Trust framework that treats every request as hostile until proven otherwise.
Our mission
We exist to make “Never Trust” the default, not the aspiration. Most breaches do not begin with exotic exploits; they begin with trust that was assumed and never verified — a request believed because of where it came from, a capability left on because no one turned it off. B5 Secure removes that assumed trust from the .NET stack and replaces it with signed, verified, fail-closed defaults.
What we build
B5 Secure is delivered as B5SecurityKit, a .NET library that turns Zero-Trust principles into pipeline configuration rather than checks scattered across a codebase. Authentication, data-element authorization, HMAC request signing, multi-factor, IP firewalling, replay and tamper protection, and instant suspension are first-class stages a team configures once and runs on every request.
Verify everything
Every request is authenticated and integrity-checked, regardless of network or origin.
Least privilege
Identities — human or machine — get only the access they need, scoped to records and fields.
Fail closed
When a check cannot complete, access stops. Safety is the default state, not the exception.
Where we come from
B5 Secure grew out of years of production security tooling for ASP.NET and evolved into B5SecurityKit, modernized for today’s .NET. We are building toward the platform’s future: .NET 10, first-class Azure deployment, and post-quantum cryptography (ML-KEM and ML-DSA) so the security you adopt now holds up against tomorrow’s threats.
Who we are
B5 Secure LLC is a California company founded by Todd Yancey, who holds the B5 Secure intellectual property. We are a small, senior team that values correctness over noise and ships security-critical software with the care it demands. We are based in Menlo Park, California.
See how Never Trust works.
Five fail-closed stages, configured once, enforced on every request.