Network / Zero Trust Access

Zero Trust Access

Policy follows the app,
not the IP.

Every connection starts with the user and the device. The path lands on the application, never on a flat network. No public exposure, no segment to babysit.

Identity · device posture · per-app policy · private path
0
Apps on the public internet
1
Identity per request
Any
Port, site or cloud
<5 s
Failover when a path dies

Application-aware access

Policy follows the app and the identity, not the IP address.

01 · AGENT

It starts on the device.

Every connection begins with a verified identity: the user, the device posture, the app making the request. No identity, no path.

  • SSO identity + device posture check
  • Works on any OS, any network

02 · GATEWAY

Policy is evaluated at the gateway.

Per-app, per-identity rules resolve at the gateway closest to the request. The gateway knows the application, not just an IP and a port.

  • Per-app, per-identity policy
  • No brittle IP allowlists

03 · EGRESS

Egress on your terms.

Leave from your own exit nodes, or hand egress to Pulse Orbit. Pin the region, keep your keys, and decide what gets logged, down to nothing at all.

  • Self-hosted or Orbit egress
  • Region pinning + logging you control

04 · APP

A private path to the app.

The connection lands on the application directly. It is never exposed to the public internet, and resolves through internal, app-based DNS.

  • Apps never exposed publicly
  • Internal / app-based DNS

Test before you trust

Simulate any access decision before it ships.

Pick a user, a device and a service, and watch the decision resolve stage by stage, from posture and device to access and egress, with the exact policy that matched. No guessing in production.

policy simulator
# simulate · who can reach what, and why
user     dana@acme.com
device   macbook-dana · managed
service  payments-api

 posture   ✓ pass  # disk encryption · screen lock
 device    ✓ pass  # managed · agent up to date
 access    ✓ allow # matched policy: eng-payments
 egress    orbit · eu-central # region pinned

decision ALLOW

Plans

Zero trust access ships in every tier.

The self-hosted network includes identity-aware paths to your apps. Pulse Orbit and Security unlock at Business and above.

Core

For small teams getting started with zero trust access.

  • Zero trust access
  • Self-hosted exit nodes
  • Pulse Orbit egress

Enterprise

For organizations with advanced security and compliance needs.

  • Everything in Business
  • All Pulse Orbit regions
  • Custom limits & SLAs

Full feature breakdown on the pricing page →

Better together · Business and up

Network pairs with Pulse Security.

Same policy engine, same fabric. Add DNS-layer threat blocking without adding a single appliance.

  • DNS-layer threat blocking on the gateways you already route through.
  • One policy model: the same identity- and app-aware rules.
  • Unlocks at Business tier and above. No migration, just switch it on.
Explore Security
pulse-security · live events Active
09:42:01 crypto-drainer.net · malware feed block
09:42:03 payments-api → stripe allow
09:42:06 unmanaged host · posture denied block
09:42:09 eng-payments · internal-db allow