LEGACY APPLICATIONS

The app that runs the business predates the security it needs.

MFA, device checks, and modern access control for systems that can't be modified. The enforcement goes in front of the app, not inside its code.

A man works at a laptop between a green-screen mainframe terminal and the mainframe itself, the access check standing in front of both.

You can't put modern security inside the old app. Put it in front.

enforcement in front

Every established organisation runs software that predates modern identity: the client-server ERP module, the AS/400 green screen, the plant application last updated when its vendor still existed. These systems can't speak modern sign-in standards, can't add multi-factor authentication (MFA), and can't be replaced on any timeline the security team controls. Yet they frequently hold the most operationally critical data in the company.

  • The application doesn't changeNothing is added to it, nothing is rewritten inside it. It simply stops being reachable by any route except through InstaSafe.
  • Every check happens firstMulti-factor authentication, device binding, posture, context and logging all resolve before a single packet arrives at the application.
  • The risk window closes nowThe system that cannot be patched stops being scannable, which is the protection the replacement project was going to deliver in three years.

Three legacy patterns, three governed paths

What the system speaks decides how it is published. None of the three touches the system itself.

  • Thick clientDesktop client-server applications and odd protocols ride the IP-layer tunnels of Zero Trust Network Access (ZTNA). The client connects the way it always has.
  • RDP-publishedWindows and web-wrapped front-ends are published through the Zero Trust Application Access portal as recorded remote desktop (RDP) sessions, with no direct route to the host.
  • Network gearRADIUS and TACACS+ modernise authentication on network-adjacent equipment that will never learn a newer one.
Use cases

Enforcement in front of the app, not code changes inside it.

Terminal front-ends

Green screen in a new frame

The app doesn't change at all — it simply becomes unreachable except through InstaSafe, where MFA, device binding, posture, context and logging all happen before any packet arrives.

neha.v · managed laptop · the app is unchanged

InstaSafe · published session
VENO-ERP  ORDER ENTRY        3270
---------------------------------

 CUSTOMER . . :  _____
 ORDER TYPE . :  ____
 STATUS . . . :  READY
===>  PF3=EXIT      PF12=CANCEL
recorded · onclipboard · offwatermark · onapp changes · none
nothing run yet · the session is already governed
Legacy outcomes

The unpatchable becomesunreachable except by policy.

Three things change the day enforcement moves in front of the application.

Unreachable by default

What cannot be patched stops being scannable, because the only path left to it is the one policy opens.

MFA lands anyway

Multi-factor authentication reaches applications that will never support it natively, because it happens before they are involved.

Room to modernise

The replacement roadmap gets its own timeline without the organisation carrying the old risk in the meantime.

FAQ

legacy applications, answered.

Tap a question. If yours is not here, a specialist can answer it.

Talk to a specialist

//Ready when you are//

The 2009 application can stay exactly as it is.

Book a demo and bring the system nobody is allowed to touch. The checks go in front of it, not inside it.

Regulated, air-gapped, or on-premise? See deployment options