CISO and IT directors
All six NIST CSF functions, with the team you have.
Three products, each complete on its own, mapped to the six functions of NIST CSF 2.0. Start with UASR: one score, and the ten actions that move it. Then add ZT-SSE, and the posture of each device decides what it can reach.
Ten tasks, not four thousand.
Your team is the size it is. UASR looks at your internet exposure, laptops, cloud, internal network and governance, puts one number on it, and ranks the actions that move that number. Your team knows what to do on Monday morning.
Score 62 out of 100, grade B. Up 0 points. 0 of 10 actions done.
Today's ten actions
Ranked by effort. Tick one and watch the number move.
Points and grades are examples.
Every surface reports in
Internet exposure, laptops and devices, the browser and AI assistants, Microsoft 365 and Google Workspace, the internal network and Active Directory, governance. All of it feeds one score.
Ranked by effort
The list is ordered by what each action gains for the work it takes. Nobody has to sort four thousand findings first.
Fixes, not only findings
Hardening measures are applied with guidance, or automatically. Drift is detected, and the loop starts again.
Then your posture decides who gets access.
ZT-SSE takes the posture of each device from UASR or from the ZT-Station. Every connection is authenticated, encrypted and authorised, and granted on one condition: the state of the device asking.
No ticket, no analyst
An unpatched laptop loses access on its own. Access returns as its posture recovers.
Learn first, then enforce
Learning mode shows what would be blocked. Shadow mode tests the policy next to the live one. Enforcement is switched on system by system.
Evidence, not promises
Every decision is logged and every privileged session is recorded. When the auditor asks, the proof is already there.
Monday: the score dropped.
What it looks like in practice, with the team you have.
Monday morning, the score is down.
Twelve laptops are graded D after the weekend. You see which ones, and why.
The task list puts them first.
The fix is at the top of today's actions. Your team knows where to start.
ZT-SSE has already reduced their access.
It takes device posture from UASR, so those laptops reach less until they are fixed. No ticket, no analyst.
The fix is pushed. By Tuesday the score is back.
ZT-SSE restores access as posture recovers, and the board sees the dip and the recovery.
UASR and ZT-SSE are sold separately, and each works on its own.
We help you become compliant and we give you the evidence.
NIS2, ISO/IEC 27001 and GDPR each ask you for proof. One answer counts for every framework that asks the same question, and the audit trail is complete and exportable.
What you hand the auditor
NIS2
A compliance score per control, playbooks, recorded privileged sessions, secure administration.
ISO/IEC 27001
A control-by-control assessment, gaps tracked as issues, a complete audit trail.
CRA and GDPR
Vulnerability history, patch reports, data-loss event history, CNIL notification templates.
The questions we get.
“We already have a VPN and an EDR.”
Good. Keep the EDR. A VPN trusts the network once you are in, and an EDR watches after the fact. We remove the assumptions both rely on.
“Three products is three integrations.”
They are one lifecycle. Start with UASR or the ZT-Station, each complete on its own, and add ZT-SSE, which draws device posture from whichever you chose.
“Rolling out zero-trust policy is risky.”
Learning mode shows what would be blocked. Shadow mode tests the policy next to the live one. Enforcement is switched on system by system.