01 · IDENTITY
Who is making the request?
Identity comes from your IdP — the user and their group — verified on every request, not just at login.
- SSO / SCIM identity, continuously checked
- Group- and role-based access
Secure web gateway, firewall and access control on one identity-aware policy plane. Enforced at your gateways, audited end to end.
Identity enforcement
01 · IDENTITY
Identity comes from your IdP — the user and their group — verified on every request, not just at login.
02 · DEVICE
Device posture decides what's allowed — managed, encrypted, patched. Unhealthy devices never reach the app.
03 · POLICY
Write the rule once and it is enforced at every gateway. SWG, firewall and access live on one policy plane — no rule sprawl.
04 · VERDICT
Every decision is enforced inline and written to a tamper-evident audit trail. Nothing happens off the record.
One policy plane fans out to every app, gateway and user. No duplicated rules, no drift between tools — change a policy in one place and it's live everywhere.
Everything in Security
Secure web gateway, firewall and access control — unified, application-aware, and audited end to end.
DNS-level filtering by domain, category and identity — connections to bad destinations are blocked before they are ever made.
Identity-aware L3/L4 firewall with IP lists and a rule simulator — one rule set across every site and cloud.
Per-app, per-identity access with IP and time-window conditions — allow exactly who and what should connect.
Gate access on live checks — disk encryption, firewall, OS version, screen lock, antivirus — with trust score thresholds.
Policy that understands the app — not just an IP and a port.
Every decision logged to a tamper-evident record, retained on your terms.
Who and what, verified on every request.
Test any access decision stage by stage before it ships.
Cyber Essentials Plus certified, with audit evidence built for the questions assessors ask.
Audit trail
Allow or block, who and what, when and why — every enforcement decision is written to a tamper-evident audit trail, retained on your terms. Built for the questions auditors actually ask.
The agent reads the device's own security state — encryption, antivirus, firewall, OS — and scores it into every access decision.
Plans
Every plan includes the full self-hosted network. Add Security from Business and above — same policy plane, no migration.
Full feature breakdown on the plans page →
Security runs on the Pulse Network — and Network is included in every tier, including yours. The policy plane that enforces your traffic also routes it, with managed gateways, egress and DNS built in.