“The WHY behind Zitadel” with Florian Forster, Co-Founder & CEO

Product Marketing
Ever wonder who’s at the helm of your favorite open source Identity platform, Zitadel? I recently spent time talking with Florian Forster, CEO and recorded his insights on Zitadel's YouTube channel.
Looking for a quick read instead? We also transcribed the conversation.
Getting to know Florian
Florian shares with us his technical background that has helped drive his entrepreneurial spirit as he operates as Zitadel’s CEO. His vision for Zitadel’s positive impact on organizations helps drive the future course of the company.
Early Days: The Founding Story of Zitadel
Florian teamed up with Fabienne Buhler, Maximilian Panne, Stefan Benz, Silvan Reusser, Elio Bischof, Livio Armstutz, Max Peintner, and founded Zitadel in 2019. The idea came to fruition when this group was working at a public sector company in Switzerland. Identifying the market gap for a developer-focused identity solution that supports both self-hosting and multi-tenancy, they set out to create and deliver this tool to the community.
Day in the life of the Zitadel CEO
Florian chuckles that his daily rhythm varies based on which global office he is working from. In Switzerland, his day unfolds at a measured pace, whereas starting in San Francisco means an immediate deluge of over 100 notifications. Despite his systematic approach to triage, priorities, and essential meetings, Florian always carves out time to engage with the Zitadel community and participate in GitHub discussions. He particularly values his diverse interactions with team members, customers, and the broader developer ecosystem. As a dedicated family man, Florian ensures that regardless of his professional commitments, he reserves quality time with his wife and young children before the day concludes.
Key Identity Management Challenges That Organizations Should Navigate
Florian challenges the tendency to either oversimplify or overcomplicate identity management. Often dismissed as a simple login, he emphasizes how identity fundamentally shapes your entire software security posture. The true challenge lies in accurately assessing risks and implementing appropriate security measures that protect users without creating friction.. Custom-built or homegrown solutions often fall short — developing robust identity systems requires specialized expertise, not a quick implementation. Engaging with industry experts and specialists provides invaluable peace of mind and enhances your organization’s security outcomes.
Zitadel’s Market Advantage
Zitadel distinguishes itself with a developer-centric approach that addresses gaps left by the legacy identity solutions. The platform offers exceptional flexibility, allowing it to adapt to your infrastructure requirements. This pairs well with Zitadel's modern self-hosting solution, which has seen an acceleration in adoption and growth over the recent years.
Multi-tenancy in Practice
Florian shares how most systems across the internet are inherently multi-tenant. He illustrates this with an e-commerce example where customers and employees require different roles and permissions. This complexity, Florian notes, rapidly intensifies as organizations grow. When multi-tenancy is built into the system’s foundational architecture, it provides sustainable scalability benefits This intentional design allows administrators to implement distinct security policies — such as customized two-factor authentication requirements — for different groups across tenants.
How Zitadel Enables Data Residency
Florian highlights two key dimensions of Zitadel’s approach to data residency: The first addresses geographic hosting requirements through the strategic regional deployments of Zitadel Cloud across the United States, Australia, European Union, and Switzerland, allowing customers to meet their compliance needs. The second offers complete flexibility through Zitadel’s self-hosting option, giving organizations complete control over database location, instance deployment, and access management according to their requirements.
The Shift to Self-Hosting Solutions
Florian notes that historical data breaches from third-party suppliers have created lasting concern among organizations. A significant segment of customers now prioritizes maintaining complete control over their data, viewing access management as a critical defensive strategy. He also highlights that technical teams have regained confidence in managing essential workloads internally, largely due to operational enablement from technologies like Kubernetes.
Evolution of Zitadel’s Licensing Model
Zitadel initially launched under the Apache 2.0 license, which effectively supported its distribution and helped build the community. Florian explains that over the past 18 months, while usage increased significantly, there wasn’t a proportional reciprocity with meaningful contributions back to the community, whether in the form of code contributions or financial support. The transition to the AGPL 3.0 license has enabled Zitadel to safeguard the substantial investment made by the core team and the broader community. This strategic licensing shirt ensures Zitadel can maintain its fundamental commitment to open source principles.
Note: Learn more about the AGPL 3.0 licensing change in this blog post.
Zitadel’s Strategic Vision for 2025 & Beyond
While Florian proudly acknowledges Zitadel’s exceptional login experience, he emphasizes that the company’s mission extends far beyond authentication.
He identifies three strategic pillars driving Zitadel’s future: 1. Identity Transactions: The authentication component of user login workflows represents Zitadel's foundational strength. With over 80% market coverage in this area, Florian is confident in the substantial value this functionality delivers to organizations. 2. Integrations and Workflows: This growing focus area recognizes that while customers can already build plugins for third-party applications, Zitadel aims to significantly enhance this capability. By expanding APIs and improving extensibility, Zitadel will provide developers with even greater flexibility and powerful incentives for adoption. 3. Analytics and Intelligence: This pillar, positioned to have the most transformative long-term impact, comprises three critical components:
- Audit and Forensics Reporting: Enabling customers to comprehensively track and analyze user activities
- Aggregation Reporting: Providing administrators with deeper insights into identity infrastructure performance through metrics on user behaviors, login failures, and other usage patterns
- Threat Detection and Mitigation: Empowering security teams with advanced tools to better understand and rapidly respond to potential attacks
Zitadel Establishes American Presence
Florian recounts that while Zitadel was born and initially flourished in Switzerland, maintaining strong Swiss heritage, the company's expanding footprint in the North American market naturally led to establishing a US headquarters. This strategic expansion positions Zitadel to better serve its growing American and global customer base and address its evolving recruitment requirements.
“If Not Tech…”: Alternative Career Paths
Florian reveals that if he was not securing identity in the Tech industry, there were several alternative career paths he would have pursued.
Initially, becoming a helicopter pilot captured his imagination, though he eventually dismissed this path, seeking to make a more substantial impact.
Following his military service, Florian considered joining the close protection field as a security operative. However, after careful consideration, he determined the inherent risks didn’t align with his personal values and life goals.
Surprisingly, citrus farming ultimately emerged as his most compelling alternative career path. Florian believes that through data-driven approaches and thoughtful agricultural practices, the field offers fascinating opportunities for innovation.
*While the world might have gained an innovative orange juice producer, the Zitadel team remains grateful to have Florian’s leadership in his current role 😁. *