InstaSafe ZTNA platform

Access control that works the way your network actually does.

Identity, device, network and application — every layer verified on every request. One console, one agent, one policy engine.

  • Zero trustby design
  • No inboundexposure
  • Least privilegeby default
  • Full visibilityand audit
  • Verify every layerIdentity, device, network and application verified on every request.
  • One policy engineConsistent access decisions across every user, app and location.
  • One agentLightweight agent for posture, tunnel and secure access — everywhere.
  • One consoleSee everything. Control everything. Prove everything.
  • Built for zero trustNo inbound access. No lateral movement. No unnecessary exposure.
  • Tata
  • Siemens
  • HDB Financial Services
  • Aditya Birla Group
  • Asian Paints
  • Mphasis
  • Landmark Group
  • NHPC
  • Pidilite
  • Axis Max Life
  • Haldiram's
  • Allcargo Logistics
  • Mirae Asset Sharekhan
  • Jana Small Finance Bank
  • DTDC
  • Bajaj General Insurance
  • Samsonite
  • Cafe Coffee Day
  • 4layers verified per request
  • 7application types, one portal
  • 1console, one agent, one policy engine

What is the InstaSafe platform?

The platform

One request. Every check.

Most security tools answer one question each — a VPN answers whether you can reach the network, MFA answers whether the password is really yours, a posture tool answers whether the laptop is safe. InstaSafe asks all of them at once, on every single access request.

  • Four questions, asked togetherWho is asking, from what device, in what context, for which resource — every request is checked on all four before anything opens. An attacker has to get every answer right, not one.
  • Then one connection, not a networkA pass opens one encrypted tunnel to that one application. Not to the network it lives on, not to anything adjacent — one user, one app, one logged session.
  • Everything else stays darkThe network, the other servers, the databases and the internal apps the request never asked for remain unreachable — not firewalled off, simply never offered.
  • One console runs all of itZTNA, ZTAA, IAM, MFA, SSO and endpoint controls are one engine with one policy, not five tools with five ideas of who you are.
USERarjun@company.comDEVICECorporate laptopCONTEXTOffice · 09:42 ISTREQUESTSAP Finance PortalInstaSafeACCESS REQUESTarjun@company.com SAP (Finance Portal)Identitywho they claim to be?VerifiedDevicesecure and compliant?CompliantContextplace, time, network?AllowedResourcethe right app for them?AuthorizedPOLICY DECISIONAll checks passedENCRYPTED TUNNELsession-4821Finance PortalLIVEEVERYTHING ELSE, MEANWHILE_The networknot accessibleOther serversnot accessibleDatabasesnot accessibleInternal appsnot accessible
4checks per request
1application per tunnel
0network access granted

The shape of it

Four layers, one decision, every time a session opens.

01/04Identity (IAM)

Who is asking?

Explore identity
Sign-in
Hi, AlenAJ
SlackSalesforceWorkdayGitHubGoogle WorkspaceZoom
WS-FIN-01425/25
Koramangala, Bengaluru · 10.24.8.101Device bound · certificate valid
Disk encryptionOnEDR agentPresentOS patch levelCurrentScreen lock5 min
GatewayLive
Internet exposureHidden
Server visibilityBlackened
Default gatewayDrop all
AuthenticationIdentity verified
Tunnel creationPer session
Tunnel scopeApplication specific
LayerLayer 3 · IP
Supported clientsThick client
Network protocolsAny TCP/IP
Session lifetimeDynamic
Idle timeoutConfigurable
Device trustVerified
Portal
Hi, AlenAJ
ServiceNowSAPFinance RDPFigmaNotionSalesforce
Finance RDP — 10.24.8.44

Directory sync, then a single verified sign-in. 8 configurable auth profiles, 6 MFA methods, SSO to every provisioned app.

Active DirectoryOpenLDAPAzure ADGoogle WorkspaceMicrosoft 365

25 posture check types across 144 named rules. 1,500+ OS/device combinations. Device binding ties each session to an approved, certificated device.

Server blackening and a drop-all gateway make assets invisible to the internet. Per-session tunnels at the IP layer for thick clients and network protocols.

7 app types through one portal — FQDN, WEB, RDP, SSH, VNC, DB, WFS. Session recording, watermarking, and clipboard control on sensitive apps.

  1. 01/04Identity (IAM)

    Who is asking?

    Sign-in
    Hi, AlenAJ
    SlackSalesforceWorkdayGitHubGoogle WorkspaceZoom

    Directory sync, then a single verified sign-in. 8 configurable auth profiles, 6 MFA methods, SSO to every provisioned app.

    Active DirectoryOpenLDAPAzure ADGoogle WorkspaceMicrosoft 365
    Explore identity
  2. 02/04Device

    What are they asking from?

    WS-FIN-01425/25
    Koramangala, Bengaluru · 10.24.8.101Device bound · certificate valid
    Disk encryptionOnEDR agentPresentOS patch levelCurrentScreen lock5 min

    25 posture check types across 144 named rules. 1,500+ OS/device combinations. Device binding ties each session to an approved, certificated device.

    Explore device posture
  3. 03/04Network (ZTNA)

    How do they connect?

    GatewayLive
    Internet exposureHidden
    Server visibilityBlackened
    Default gatewayDrop all
    AuthenticationIdentity verified
    Tunnel creationPer session
    Tunnel scopeApplication specific
    LayerLayer 3 · IP
    Supported clientsThick client
    Network protocolsAny TCP/IP
    Session lifetimeDynamic
    Idle timeoutConfigurable
    Device trustVerified

    Server blackening and a drop-all gateway make assets invisible to the internet. Per-session tunnels at the IP layer for thick clients and network protocols.

    Explore ZTNA
  4. 04/04Application (ZTAA)

    What exactly can they touch?

    Portal
    Hi, AlenAJ
    ServiceNowSAPFinance RDPFigmaNotionSalesforce
    Finance RDP — 10.24.8.44

    7 app types through one portal — FQDN, WEB, RDP, SSH, VNC, DB, WFS. Session recording, watermarking, and clipboard control on sensitive apps.

    Explore ZTAA
the decision layer

One engine decides. Every session.

Identity, device posture, location, time and risk score are not five separate checks that each pass or fail. They are evaluated together, once, before a single packet reaches the application.

21
policy combinations
12 → 4
risk triggers, automatic responses
202
event types, every decision logged
Explore the Trust Engine
policy gate
policy.evaluatesession

evaluatingpriya@acme.co → erp-core

identity
directory match · mfa satisfied
device
bound · posture 25/25
location
IN · within allowed geo
time
14:02 IST · inside window
risk
2 / 100

ALLOW erp-finance-readonly ttl 8h

evaluatingpriya@acme.co → erp-core

location
SG · 41 min after last IN login
risk
78 / 100 · impossible travel

STEP-UP challenge issued event logged

same user · same targetone input changed

The engine

One movement, checked on every beat.

Identity, device, location, time and risk are not five products taking turns. They are one movement, evaluated together, on every request — and the whole of it runs from one console.

identitydevicelocationtimerisk

Inside the Trust Engine
  • 1,500+OS and device combinations
  • 8configurable auth profiles
  • 11report types out of the box
The walkthrough

How a request actually flows.

Five steps, in order, between someone clicking an application and that application answering for the first time.

one request _ end to end
  • 01 · RequestThe user opens the agent or the browser portal and asks for an application.nothing has responded yet — assets sit dark behind a drop-all gateway
  • 02 · IdentityThe controller checks the directory and enforces the auth profile for this user group.your AD / LDAP / IdP, or InstaSafe's built-in directory
  • 03 · DeviceThe agent reports posture, and the device certificate is matched against the binding record.OS version, patching, antivirus, firewall, disk encryption
  • 04 · ContextLocation, IP range, time window and behavioural signals are scored against policy.anomalies raise risk; risk can force step-up or refuse outright
  • 05 · ConnectOnly now does the gateway open — one encrypted tunnel, this device to this application.the network is never exposed; the session is logged, and recorded where policy says so
Quick scan

The spec sheet, as a checklist.

Tick what your evaluation actually needs, then copy the shortlist straight into your ticket. Filtering hides rows; it never clears a tick.

quick scan _ platform specs
Access
Identity
Policy
Audit
Deployment
0 of 12 markedtick what your evaluation actually needs — take it into the demo

so what changes on monday

You have the VPN, the MFA vendor and the spreadsheets. What retires first?

all three — and the network stops being the thing you grant
One console

One platform,not five tools

ZTNA, ZTAA, IAM, MFA, SSO and endpoint controls from one console — so the VPN, the separate MFA vendor and the access spreadsheets all retire together.

One platform, not five tools

ZTNA, ZTAA, IAM, MFA, SSO and endpoint controls from one console. Retire the VPN, the separate MFA vendor and the access spreadsheets.

Invisible infrastructure

Server blackening means your applications don't appear on the internet at all. Attackers can't scan what doesn't respond.

Your data never touches us

Split-plane architecture: InstaSafe runs the control plane; your data flows directly between your users and your apps.

FAQ

The platform, answered.

Tap a question — or open them all and read straight through.

Talk to us

//Ready when you are//

Ditch the VPN. Keep your apps invisible.

Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.

Regulated, air-gapped, or on-premise? See deployment options