01 · IDENTITY
Who is making the request?
Identity comes from your IdP, the user and their group, and is verified on every request rather than just at login.
- SSO / SCIM identity, continuously checked
- Group- and role-based access
DNS-layer web filtering, firewall and access control on one identity-aware policy plane. Enforced at your gateways, audited end to end.
Identity enforcement
01 · IDENTITY
Identity comes from your IdP, the user and their group, and is verified on every request rather than just at login.
02 · DEVICE
Device posture decides what's allowed: managed, encrypted, patched. Unhealthy devices never reach the app.
03 · POLICY
Write the rule once and it is enforced at every gateway. Web filtering, firewall and access live on one policy plane, so there is no rule sprawl.
04 · VERDICT
Every decision is enforced inline and written to a tamper-evident audit trail. Nothing happens off the record.
One policy plane fans out to every app, gateway and user. No duplicated rules, no drift between tools. Change a policy in one place and it's live everywhere.
Everything in Security
DNS-layer web filtering, firewall and access control. Unified, application-aware and audited end to end.
DNS-layer filtering by domain, category and identity, backed by curated threat intelligence feeds. Bad destinations are blocked before a connection is ever made.
Identity-aware L3/L4 firewall with IP lists and a rule simulator. One rule set across every site and cloud.
Per-app, per-identity access with IP and time-window conditions. Allow exactly who and what should connect.
Gate access on live checks for disk encryption, firewall, OS version, screen lock and antivirus, with trust score thresholds.
Policy that understands the app, not just an IP and a port.
Every decision logged to a tamper-evident record, retained on your terms.
Who and what, verified on every request.
Test any access decision stage by stage before it ships.
Cyber Essentials Plus certified, with audit evidence built for the questions assessors ask.
Audit trail
Allow or block, who and what, when and why. Every enforcement decision is written to a tamper-evident audit trail and retained on your terms. Built for the questions auditors actually ask.
The agent reads the device's own security state, from encryption and antivirus to firewall and OS, and scores it into every access decision.
Plans
Every plan includes the full self-hosted network. Add Security from Business and above. Same policy plane, no migration.
Full feature breakdown on the pricing page →
Better together
Security runs on the Pulse Network, and Network is included in every tier, including yours. The policy plane that enforces your traffic also routes it, with managed gateways, egress and DNS built in.