Built by the company that had to trust it first
TrustedLogin came out of GravityKit’s own support team, and GravityKit still runs its support through it every day.
Origin, specific and honest
Zack Katz founded GravityKit, a WordPress plugin business now in its second decade, built on GravityView and its add-ons. Running support for GravityView, the recurring bottleneck wasn’t the bugs; it was getting access to look at them. Every ticket that needed a site login added a round of email, a wait, and often a password left sitting in the thread afterward. TrustedLogin started as the fix for that, inside GravityKit, before it was a product anyone else could buy.
Why that matters to you
GravityKit is a profitable, decade-old WordPress business, not a startup spending a raise to find a market. It runs its own support team through TrustedLogin today: the same grant flow, the same dashboard, the same expiry rules you’d get. Whenever a GravityKit customer asks, that’s what the same flow gets them: someone inside the site within minutes, fixing instead of describing, with a record that they were there. If TrustedLogin broke in a way that mattered, GravityKit’s own support team would feel it before any customer does.

Small team, on purpose
TrustedLogin is run by a small team. That’s not an apology. It means fewer people who could mishandle a customer’s access request, a shorter chain between a bug report and a fix, and nobody routing your support data through a department that’s never touched the product. What it means concretely: the structural safety below is a claim you can verify yourself, not one you have to take on trust.
The structural safety
Three things hold regardless of team size, and regardless of whether TrustedLogin as a company is still around in five years:
The SDK is open source: read exactly what runs on your customer’s site at github.com/trustedlogin/client. The Connector is GPL-licensed and its full source ships through WordPress.org.
The Connector has been live on WordPress.org since September 2024: a public listing, public reviews, public version history, not a private build only we can see.
Every grant is a real WordPress account the customer’s own site created. The customer, or their host, can revoke it directly in wp-admin, with or without TrustedLogin’s service being reachable.
