One portal. Every app. No network exposed.
Web apps, remote desktops, SSH, databases, file servers — opened from a browser, governed per session, invisible to everyone else.
- 7application types_
- 202event log types_
- 11built-in reports_
- 0network joined_
What is ZTAA?
Zero Trust Application Access
Applications, not networks.
Zero Trust Application Access delivers applications instead of networks. Where ZTNA opens a narrow tunnel at the network layer, ZTAA goes one step further up: the user never touches the network at all.
- One sign-in, then a page of tilesThey open a browser, sign in once, and see only the applications they have been provisioned. Click a tile and it opens — internal web app, Windows remote desktop, SSH terminal, database console or file share.
- Seven ways in, one doorFQDN, WEB, RDP, SSH, VNC, DB and WFS all arrive through the same portal under the same identity. The engineer's shell and the finance team's ERP are one URL and one login apart.
- The session is governed, not just startedBecause access is brokered at the application layer, policy can act inside the session: recording the screen for privileged work, watermarking content, blocking copy-paste out of a sensitive app, controlling downloads.
- Everything that happened is on the record202 event types, 11 built-in reports and 7 SIEM export formats. Who opened what, from which device, and what they did once inside it.
Granting access is easy. Proving what happened next is the job.
The tools are scattered. So is the evidence.
A toolkit held together by bookmarks
Jump servers for SSH, a VDI farm for desktops, a vault for database credentials, a VPN for the rest. Every one is provisioned separately, logged separately, and forgotten separately when someone leaves.
Access granted, then unobserved
Most access products can tell you a session started. Far fewer can tell you what happened inside it — which is the exact question an auditor asks about privileged and vendor work.
The people you don't manage
Contractors, vendors and BYOD users arrive on devices you cannot install anything on. Handing them a VPN client is how third-party access becomes your incident.
Seven application types. One portal.
The engineer's SSH session, the finance team's ERP, the auditor's read-only web view — one URL, one login, per-user tiles. Web, RDP, SSH and VNC open straight from the browser; a lightweight agent handles thick-client and certificate-based device identity where it is needed.
Database access covers PostgreSQL, MSSQL and SQL Server (generally available), Oracle and Elasticsearch (beta), ClickHouse and MongoDB (alpha) — brokered through the portal with the same identity, posture and logging as every other session.
Change the person. Watch the portal change.
This is what the person signing in actually sees. Switch between an infrastructure engineer, a finance systems lead and a designer — the applications, the network resources, the device and the history all change with them, because entitlements are the portal.
Access opens the app. Control stays inside it.
Getting into an application is the first decision, not the last. Eight controls run for the life of the session — over the tunnel, the clipboard, the screen and the keyboard.
See all capabilities ↗Every signal, visible and verifiable.
Logs, reports and exports — built in. No add-ons. No gaps.
- Logins34
- Failures28
- Posture results26
- Policy decisions31
- Session starts / ends24
- In-session actions59
- 10:24:31Login successalen.josephBrowserAllowed
- 10:24:18Posture checkDevice compliantWindows 11Passed
- 10:24:07Policy decisionerp-core accessZero TrustAllowed
- 10:23:58Session startedfinance dashboardWeb appActive
- 10:23:41File downloadQ4_report.xlsxIn-sessionLogged
- 10:23:12Logoutalen.josephBrowserEnded
202 event log types
Logins, failures, posture results, policy decisions, session starts/ends, in-session actions.
Learn more11 built-in report types
Access summaries, device reports, user activity, authentication summaries.
Learn moreSame portal. Very different people.
Employees get their whole toolkit behind one login. Contractors get two systems, recorded, until the contract ends. Neither of them gets a network.
Workforce access
Employees get their full toolkit in one portal, on managed or personal devices, with MFA and posture invisible until something is wrong.
One portal. Every app their role lists. No network behind any of it.
ZTAA specs, at a glance.
- Access modelApplication-layer brokering — browser portal + agent
- App typesFQDN, WEB, RDP, SSH, VNC, DB, WFS
- DB enginesPostgreSQL / MSSQL / SQL Server GAOracle, Elasticsearch beta · ClickHouse, MongoDB alpha
- ClientlessWEB, RDP, SSH and VNC open from the browser
- Session controlsRecording, watermark, clipboard, download, timeout
- IdentitySSO — SAML 2.0, OAuth, OIDC · 6 MFA methods · 8 auth profiles
- DeviceBinding + 25 posture checks when agentedSession controls compensate in clientless mode
- Policy21 context combinations · 12 risk triggers · 4 auto-actions
- Logging202 event types · 11 reports · 7 SIEM formats
- CompanionZTNA for anything a browser cannot deliver
- 7application types_
- 21policy combinations_
- 202event log types_
One record.Every sessionit opens.
One provisioning surface across all seven application types. What a person may reach, what they may do inside it, and what they did — all decided from the same record.
The network stops being the product
Users consume applications. The network disappears from their world — and from the attacker's.
In-session governance
Recording, watermarking and clipboard policy turn “we granted access” into “we can prove what happened”.
One door to close
Joiner, mover and leaver become a single provisioning action across all seven application types.
what about the apps a browser cannot open
Thick clients, legacy protocols, engineering tools. What carries those?
ZTNA — the same platform, one layer down↓//Ready when you are//
Ditch the VPN. Keep your apps invisible.
Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.
Regulated, air-gapped, or on-premise? See deployment options