01 · AGENT
It starts on the device.
Every connection begins with a verified identity: the user, the device posture, the app making the request. No identity, no path.
- SSO identity + device posture check
- Works on any OS, any network
Zero Trust Access
Every connection starts with the user and the device. The path lands on the application, never on a flat network. No public exposure, no segment to babysit.
Application-aware access
01 · AGENT
Every connection begins with a verified identity: the user, the device posture, the app making the request. No identity, no path.
02 · GATEWAY
Per-app, per-identity rules resolve at the gateway closest to the request. The gateway knows the application, not just an IP and a port.
03 · EGRESS
Leave from your own exit nodes, or hand egress to Pulse Orbit. Pin the region, keep your keys, and decide what gets logged, down to nothing at all.
04 · APP
The connection lands on the application directly. It is never exposed to the public internet, and resolves through internal, app-based DNS.
Test before you trust
Pick a user, a device and a service, and watch the decision resolve stage by stage, from posture and device to access and egress, with the exact policy that matched. No guessing in production.
# simulate · who can reach what, and why user dana@acme.com device macbook-dana · managed service payments-api → posture ✓ pass # disk encryption · screen lock → device ✓ pass # managed · agent up to date → access ✓ allow # matched policy: eng-payments → egress orbit · eu-central # region pinned decision ALLOW
Plans
The self-hosted network includes identity-aware paths to your apps. Pulse Orbit and Security unlock at Business and above.
For small teams getting started with zero trust access.
For growing teams who need more control and visibility.
For organizations with advanced security and compliance needs.
Full feature breakdown on the pricing page →
Better together · Business and up
Same policy engine, same fabric. Add DNS-layer threat blocking without adding a single appliance.