Why InstaSafe

Security that doesn't route through the vendor.

Most Zero Trust vendors inspect your traffic on their infrastructure. We architected ourselves out of your data path — and publish the numbers others keep vague.

Deployed acrossregulated IndiaBuilt in Indiafor the worldPrivacy byarchitecture
InstaSafe
No backhaul. No inspection. No vendor in the middle.You stay in control of your data, your performance and your compliance.
0msAdded latencyDirect to resource.No detours.
0GBData proxiedYour data staysin your environment.
0Traffic hopsStraight to whereyou need to be.
100%Encrypted end-to-endEnd-to-end encryptionyou own.
160+Countries servedGlobal coverage.Local performance.
100%TransparencyWe publish whatothers won't.
The data path

We are not in it.

Most Zero Trust vendors terminate your sessions on their own infrastructure — which means decrypting your traffic to inspect it, then re-encrypting it and sending it on. That is the usual premise. Ours splits the two planes apart and only ever holds one of them.

The usual premise
Vendor cloudPolicy · auth · telemetry…and your traffic, decrypted
One plane. Theirs.
The split plane
InstaSafeControl planePolicy · auth · telemetry
Data planeYour traffic, your environment
Two planes. One of them is ours.
What converges

The decisions meet here. Your traffic never does.

Identity, device posture, location and risk are evaluated in one place, on every request. What comes out is a verdict — the session it authorises runs straight from your people to your applications.

WorkforceDevicesIdentityAppsLocationsNetworksControl planeYour apps, directTake the data path apart
We can't leak what we never carry.

What that buys you

A vendor breach is not your breach.

The numbers

Every figure here has a page behind it.

Enumerable controls are the difference between a security posture and a security story. Each cluster below links to the page that proves it — because a number nobody can check is marketing.

Checkable, not quotable

Every number here is something you can query

Controls you can enumerate are only worth anything if you can pull the evidence yourself. Every decision the platform makes is logged as a typed event, exportable to the tooling you already run.

7SIEM formats to export to
11report types out of the box
WindowsmacOSLinuxAndroidiOSEntra IDOktaGoogleADLDAPSAMLOIDC
  • 144named policy rules
  • 25device check types
  • 202event log types
The record

Not new here, and not new at this.

Zero Trust became a category around us rather than the other way round. The dates matter because architecture decisions taken early are the ones that are expensive to reverse later.

  1. 2012Founded in BengaluruBuilt for Indian enterprises before Zero Trust was a category anyone was buying.
  2. 2018A platform, not a VPN swapIdentity, device trust and application access converge into one control plane rather than three products.
  3. 2020Remote work, at onceWorkforces moved home in weeks. The architecture scaled by configuration, because there was no hardware in the path to size.
  4. TodayOne console, six productsZTNA, ZTAA, identity, MFA, privileged access and endpoint control, governed from a single policy engine.
Recognition

Judged by people who had no stake in it.

Analyst houses, industry bodies and the review sites where the scores come from customers rather than from us. Each one is an outside read of the same product this page describes.

See every award and recognition

Recognised since 2018 — by the analysts, and by the people who actually run it.

Indian regulators and global standards, from one platform. Most vendors are strong in one column and thin in the other — the combination is the part the market lacks.

IndiaThe regulators your auditor cites
  • DPDPDigital Personal Data Protection ActData stays in your environment, so the processing boundary stays yours.Controls map; obligations remain yours
  • RBIReserve Bank of IndiaAccess control and audit trail evidence for regulated banking estates.
  • SEBISecurities and Exchange Board of IndiaSession recording and privileged-access oversight for market infrastructure.
  • IRDAIInsurance Regulatory and Development AuthorityPolicy and logging evidence for insurer access reviews.
  • NPCINational Payments Corporation of IndiaSegregated, recorded access paths for payment operations.
GlobalThe standards your board cites
  • NIST SP 800-207Zero Trust ArchitectureThe architecture the standard describes, implemented rather than approximated.
  • CSA SDPSoftware-Defined PerimeterDrop-all gateways with single-packet authorisation.
  • ISO 27001Information Security ManagementAccess control clauses evidenced from the platform's own logs.
  • PCI DSSPayment Card Industry Data Security StandardSegmentation and privileged-session evidence for cardholder estates.
  • HIPAAHealth Insurance Portability and Accountability ActLeast-privilege access to systems holding patient data.
  • GDPRGeneral Data Protection RegulationNo vendor-side copy of the data in transit.Controls map; obligations remain yours
  • SOXSarbanes-Oxley ActChange and access evidence for financial reporting systems.
Control-by-control mappings in the Trust Center
Line by line

The same questions, asked of every option.

Categories rather than company names — the differences below are architectural, and they hold across every vendor in each column.

What mattersInstaSafeGlobal SASEVPN incumbentWorkspace suite
Data transits vendor cloudNeverAlwaysVia applianceVaries
Published product depthYes, with numbersRarelyNoPartial
Deploy timeDaysWeeksWeeksWeeks
Device posture depth25 types · 144 rulesVariesMinimalVaries
Clientless third-party pathYesYesNoPartial
DPDP and India regulatory fluencyYesPartialNoPartial
App types in one portal7n/an/aVaries

marks the rows where the difference is architectural rather than a matter of degree — the two you cannot configure your way out of.

The architecture

Your data never travels through us.

Decisions come from us. Traffic never does. Everything above is a consequence of this one drawing.

AUTH POLICY LOG YOUR DATA YOUR DATA YOUR DATA YOUR DATA CONTROL PLANE DATA PLANE SPLIT PLANE RAILS  v1.0 PRIVACY BY DESIGN ISOMETRIC VIEW Z Y X NEVER TOUCH NEVER MIX PRIVACY FIRST INSTASAFE ARCHITECTURE DIAGRAM FIG. 01
CONTROL PLANE · INSTASAFEdecisions onlyAUTHPOLICYLOGNEVER MIXno shared path · no vendor-side copyDATA PLANE · YOURSyour traffic, your environmentyour peopleyour appsFIG. 01 — SPLIT PLANE
Reachability

A VPN lets people onto the network.
InstaSafe lets them into one app.

Same people, same devices, same day. The only thing that changes is what a session can reach once it is connected.

With InstaSafe: identity, device and posture are checked, then the gateway resolves exactly one host for this session — payroll.internal. The other six are not denied at the door; they never appear.With InstaSafe: checks pass, then one host resolves — payroll.internal. The other six never appear.

Incoming sessions
InstaSafe
InstaSafe gateway
Identity
Managed device
Posture: 25 checks
Role: Finance
Application estate
CRMcrm.internal
Payrollpayroll.internal
Source reposgit.internal
Wikiwiki.internal
Build serverci.internal
File sharefiles.internal
Database consoledb.internal

10.0.0.0/8 — no route offered, nothing to discover

Routed for this sessionReachable because the network is reachableDoes not resolve
FAQ

The questions that decide it.

Tap a question — or open them all and read straight through.

Talk to us

//Ready when you are//

Ditch the VPN. Keep your apps invisible.

Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.

Regulated, air-gapped, or on-premise? See deployment options