The app that runs the business predates the security it needs.
MFA, device checks, and modern access control for systems that can't be modified. The enforcement goes in front of the app, not inside its code.

You can't put modern security inside the old app. Put it in front.
enforcement in front
Every established organisation runs software that predates modern identity: the client-server ERP module, the AS/400 green screen, the plant application last updated when its vendor still existed. These systems can't speak modern sign-in standards, can't add multi-factor authentication (MFA), and can't be replaced on any timeline the security team controls. Yet they frequently hold the most operationally critical data in the company.
- The application doesn't changeNothing is added to it, nothing is rewritten inside it. It simply stops being reachable by any route except through InstaSafe.
- Every check happens firstMulti-factor authentication, device binding, posture, context and logging all resolve before a single packet arrives at the application.
- The risk window closes nowThe system that cannot be patched stops being scannable, which is the protection the replacement project was going to deliver in three years.
Three legacy patterns, three governed paths
What the system speaks decides how it is published. None of the three touches the system itself.
- Thick clientDesktop client-server applications and odd protocols ride the IP-layer tunnels of Zero Trust Network Access (ZTNA). The client connects the way it always has.
- RDP-publishedWindows and web-wrapped front-ends are published through the Zero Trust Application Access portal as recorded remote desktop (RDP) sessions, with no direct route to the host.
- Network gearRADIUS and TACACS+ modernise authentication on network-adjacent equipment that will never learn a newer one.
Enforcement in front of the app, not code changes inside it.
Green screen in a new frame
The app doesn't change at all — it simply becomes unreachable except through InstaSafe, where MFA, device binding, posture, context and logging all happen before any packet arrives.

neha.v · managed laptop · the app is unchanged
VENO-ERP ORDER ENTRY 3270 --------------------------------- CUSTOMER . . : _____ ORDER TYPE . : ____ STATUS . . . : READY ===> PF3=EXIT PF12=CANCEL
The unpatchable becomesunreachable except by policy.
Three things change the day enforcement moves in front of the application.
Unreachable by default
What cannot be patched stops being scannable, because the only path left to it is the one policy opens.
MFA lands anyway
Multi-factor authentication reaches applications that will never support it natively, because it happens before they are involved.
Room to modernise
The replacement roadmap gets its own timeline without the organisation carrying the old risk in the meantime.
legacy applications, answered.
Tap a question. If yours is not here, a specialist can answer it.
Talk to a specialist//Ready when you are//
The 2009 application can stay exactly as it is.
Book a demo and bring the system nobody is allowed to touch. The checks go in front of it, not inside it.
Regulated, air-gapped, or on-premise? See deployment options