Skip to content
ZT-SSENew

Every connection authenticated, encrypted and authorised. No app changes.

One agent on the device, one gateway at each boundary, one policy for everything. ZT-SSE covers every connection to your other resources, and grants it according to the state of the device asking.

The question it answers

“How do we let anyone reach anything, from anywhere, without trusting the network, and cut it off the moment something is wrong?”

Nothing reaches a destination until the gateway has said yes.

Users and sites connect to a gateway. The gateway enforces the policy on every single connection, and asks the same four questions each time.

Connection request

Finance laptop to the payroll application

  1. Who is asking?

    The person, and the exact program on the device.

    Checked
  2. From what device, in what state?

    Patched, encrypted, on a trusted network, behaving normally.

    Checked
  3. What is it allowed to reach?

    Only what a rule explicitly grants. Nothing by default.

    Checked
  4. Still allowed right now?

    If the device state drops, the session is cut immediately.

    Checked

Allowed. And asked again on the next connection.

Who connects

Laptops and servers with the agent. Browsers with no agent, through the proxy. Remote sites and connected devices, each one authenticated.

Where the gateway sits

In your data centre, in your cloud, at a site or a branch office. Behind a firewall, it needs no inbound rule.

What they reach

The internet, SaaS and cloud, filtered. Private applications, without a VPN. Privileged systems, through the bastion. Other sites and clouds, over an encrypted link between gateways.

Six things it does.

One agent, one policy, every edge. No SDK, no sidecar and no code change in your applications.

  • One gateway for every connection

    The checkpoint every connection goes through: who is asking, from which device, in what state. Then, and only then, it lets it pass.

  • Private applications, without a VPN

    Access is granted per application and per user, never to the whole network.

  • Web and cloud access

    Control where people go on the internet and which cloud tenants they can use. With or without an agent.

  • Privileged access

    Administrators reach servers, databases and Kubernetes through the bastion. No standing passwords, and every session is recorded.

  • Data and AI protection

    Sensitive data is blocked or redacted before it leaves, including in AI assistants. Malware is scanned on the way in.

  • DNS security

    Malicious domains are blocked the moment a device looks them up. Hidden command channels are detected before they are used.

Access on one condition: posture.

ZT-SSE takes the posture of each device from UASR or from the ZT-Station. Access follows that posture, connection after connection. When it drops, the session is cut.

  • What the gateway looks at

    Whether the device is patched and encrypted, which network it is on, and whether it is behaving normally. The answer is part of every decision.

  • Where posture comes from

    From UASR or from the ZT-Station. ZT-SSE can run on its own, but the rules that depend on posture need one of the two.

  • What happens when it drops

    The session is cut immediately and access is reduced. It returns as posture recovers.

Learn first, then enforce.

Nobody has to flip the switch blind.

  1. Learn

    Learning mode watches first. It shows what would be blocked and proposes the rules.

  2. Test

    Shadow mode tests the policy next to the live one. You see what it would decide before it decides anything.

  3. Enforce

    You approve, then enforcement is switched on system by system.

One matrix. Default deny.

Who may reach what, on one screen. Traffic without a rule is refused.

Access matrix

Who may reach what.

Traffic without a ruleDenied

The access level of each team to each application. Where there is no rule, access is denied.
TeamPayrollCRMSource codeServers
FinanceFullRestrictedDeniedDenied
SalesDeniedFullDeniedDenied
EngineeringDeniedDeniedFullStandard
IT operationsDeniedStandardDeniedFull
ContractorsDeniedDeniedRestrictedDenied
  • Full
  • Standard
  • Restricted
  • Denied

Trust nothing by default. Verify everything, every time.

Six things that are true once ZT-SSE is in place.

  • Nothing connects unverified

    Every connection is checked before it reaches its destination, on the internet or inside your own network.

  • Least privilege, by construction

    No rule, no access. An intruder who lands on one machine cannot roam.

  • No standing credentials

    Administrators never hold a permanent password. Credentials are injected for the session, then gone.

  • Device health decides

    An unpatched laptop on hostile Wi-Fi loses access on its own. No ticket, no analyst.

  • Data stays inside

    Sensitive data is stopped before it leaves, including in AI assistants.

  • Evidence, not promises

    Every decision is logged and every privileged session is recorded: what NIS2, DORA and ISO 27001 auditors ask for.

Fewer boxes.

These are categories that typically need several separate products. ZT-SSE takes over from them with one agent and one policy.

ZT-SSE takes over from

  • Remote-access VPN
  • Jump host and privileged access
  • Cloud access broker
  • Secure web gateway
  • Data-loss appliance
  • DNS filtering

Site-to-site links remain. They run from gateway to gateway, encrypted.

On your infrastructure if you need it.

ZT-SSE can run on your own infrastructure. The gateways sit at your boundaries, and the control plane, which distributes identity and policy, runs on your own servers.

Sovereignty

One score. One policy.
One trusted system.

Start with your Cyber Score. In two weeks you know where you stand and what to fix first.