Every connection authenticated, encrypted and authorised. No app changes.
One agent on the device, one gateway at each boundary, one policy for everything. ZT-SSE covers every connection to your other resources, and grants it according to the state of the device asking.
The question it answers
“How do we let anyone reach anything, from anywhere, without trusting the network, and cut it off the moment something is wrong?”
Nothing reaches a destination until the gateway has said yes.
Users and sites connect to a gateway. The gateway enforces the policy on every single connection, and asks the same four questions each time.
Connection request
Finance laptop to the payroll application
- Checked
Who is asking?
The person, and the exact program on the device.
- Checked
From what device, in what state?
Patched, encrypted, on a trusted network, behaving normally.
- Checked
What is it allowed to reach?
Only what a rule explicitly grants. Nothing by default.
- Checked
Still allowed right now?
If the device state drops, the session is cut immediately.
Allowed. And asked again on the next connection.
Who connects
Laptops and servers with the agent. Browsers with no agent, through the proxy. Remote sites and connected devices, each one authenticated.
Where the gateway sits
In your data centre, in your cloud, at a site or a branch office. Behind a firewall, it needs no inbound rule.
What they reach
The internet, SaaS and cloud, filtered. Private applications, without a VPN. Privileged systems, through the bastion. Other sites and clouds, over an encrypted link between gateways.
Six things it does.
One agent, one policy, every edge. No SDK, no sidecar and no code change in your applications.
One gateway for every connection
The checkpoint every connection goes through: who is asking, from which device, in what state. Then, and only then, it lets it pass.
Private applications, without a VPN
Access is granted per application and per user, never to the whole network.
Web and cloud access
Control where people go on the internet and which cloud tenants they can use. With or without an agent.
Privileged access
Administrators reach servers, databases and Kubernetes through the bastion. No standing passwords, and every session is recorded.
Data and AI protection
Sensitive data is blocked or redacted before it leaves, including in AI assistants. Malware is scanned on the way in.
DNS security
Malicious domains are blocked the moment a device looks them up. Hidden command channels are detected before they are used.
Access on one condition: posture.
ZT-SSE takes the posture of each device from UASR or from the ZT-Station. Access follows that posture, connection after connection. When it drops, the session is cut.
What the gateway looks at
Whether the device is patched and encrypted, which network it is on, and whether it is behaving normally. The answer is part of every decision.
Where posture comes from
From UASR or from the ZT-Station. ZT-SSE can run on its own, but the rules that depend on posture need one of the two.
What happens when it drops
The session is cut immediately and access is reduced. It returns as posture recovers.
Learn first, then enforce.
Nobody has to flip the switch blind.
Learn
Learning mode watches first. It shows what would be blocked and proposes the rules.
Test
Shadow mode tests the policy next to the live one. You see what it would decide before it decides anything.
Enforce
You approve, then enforcement is switched on system by system.
One matrix. Default deny.
Who may reach what, on one screen. Traffic without a rule is refused.
Access matrix
Who may reach what.
Traffic without a ruleDenied
| Team | Payroll | CRM | Source code | Servers |
|---|---|---|---|---|
| Finance | Full | Restricted | Denied | Denied |
| Sales | Denied | Full | Denied | Denied |
| Engineering | Denied | Denied | Full | Standard |
| IT operations | Denied | Standard | Denied | Full |
| Contractors | Denied | Denied | Restricted | Denied |
- Full
- Standard
- Restricted
- Denied
Trust nothing by default. Verify everything, every time.
Six things that are true once ZT-SSE is in place.
Nothing connects unverified
Every connection is checked before it reaches its destination, on the internet or inside your own network.
Least privilege, by construction
No rule, no access. An intruder who lands on one machine cannot roam.
No standing credentials
Administrators never hold a permanent password. Credentials are injected for the session, then gone.
Device health decides
An unpatched laptop on hostile Wi-Fi loses access on its own. No ticket, no analyst.
Data stays inside
Sensitive data is stopped before it leaves, including in AI assistants.
Evidence, not promises
Every decision is logged and every privileged session is recorded: what NIS2, DORA and ISO 27001 auditors ask for.
Fewer boxes.
These are categories that typically need several separate products. ZT-SSE takes over from them with one agent and one policy.
ZT-SSE takes over from
- Remote-access VPN
- Jump host and privileged access
- Cloud access broker
- Secure web gateway
- Data-loss appliance
- DNS filtering
Site-to-site links remain. They run from gateway to gateway, encrypted.
On your infrastructure if you need it.
ZT-SSE can run on your own infrastructure. The gateways sit at your boundaries, and the control plane, which distributes identity and policy, runs on your own servers.
Sovereignty