SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Security Service Edge · SSE · Live

Security Service Edge

Powerful security protection embedded at every level of your network. Manage centrally, run worry-free, operated 24/7 by Level-3 engineers.

Overview

Security built into the fabric.

Avoid the need to acquire and manage multiple additional packages bolted on to your SASE service. Open Systems integrates comprehensive security functions across the Open Systems SASE Experience, so you can manage them centrally from a single portal and run worry-free.

SSE is the security half of SASE: zero trust access, web and cloud security, threat protection and email security, delivered as one cloud-native layer and operated end to end by our engineers, not handed back to your team as another console to staff.

Built-in security functions throughout your network

One layer, every control.

Managed SASE is what you need

Centrally managed, worry-free.

  • All security functions activated and enforced from one Mission Control portal
  • Consistent policy across users, sites and clouds, on a 35-year operational baseline
  • Level-3 engineers take on integration and 24/7 operations, no L1, no L2
  • Add functions like CASB in minutes for existing Secure Web Gateway customers
See how we operate it
Open Systems SSE security functions managed centrally
What is different about Open Systems SSE

Differentiators.

No bolt-ons

One integrated service instead of a stack of separately licensed point products.

AI-run, human-backed

Automation where it should be, Level-3 engineers where it counts.

Single pane of glass

Discovery, policy, monitoring and reporting for every control in one portal.

FAQ

Questions about SSE.

What is the difference between SASE and SSE?

SSE is the security half of SASE. It covers zero trust access, web and cloud security, threat protection and email security, delivered from the cloud. SASE is that plus the network: SD-WAN, the private backbone and the connectivity underneath it. You can buy SSE on its own, and many organizations start there, but the two were designed to be operated together. See Secure Network for the other half.

Which controls are included, and which cost extra?

ZTNA, Secure Web Gateway, CASB, firewall, email security and cloud sandbox are the SSE layer. Commercially they sit in the Secure Access, Advanced Security, Threat Defense and Email Security modules, so you can take the whole layer or only the parts you need. The prices are public on the pricing page.

Is this our SSE, or yours? Who writes the policy?

You set the intent, we run the machinery. Policy is yours and is visible and editable in the portal, plus the public API and Terraform if you prefer it in code. What we take on is integration, tuning, monitoring and 24/7 operations, so the policy does not quietly rot because nobody has time to maintain it.

We already run a Secure Web Gateway from you. How hard is adding CASB?

Minutes, not a project. The controls sit in one service on one enforcement layer, so adding CASB for an existing Secure Web Gateway customer is an activation rather than a deployment. That is the practical payoff of no bolt-ons: nothing has to be integrated twice.

How is this different from buying the same controls from one vendor's portfolio?

A portfolio is a price list; this is one service. The controls share a policy model, an enforcement layer and a portal, and they are operated end to end by Level-3 engineers instead of handed back to you as another console to staff. The usual failure of a DIY SSE project is not the products, it is that nobody has the hours to run six of them well.

Do users have to backhaul traffic to a data centre?

No. Enforcement happens at the point of presence closest to the user, across the global PoP network, so a user in Singapore is not routed through Frankfurt to read a web page. That is the whole reason web security moved to the cloud.

What does zero trust actually change for our users?

Access follows identity and device posture instead of an IP address, and it is scoped to individual applications rather than to the network. In practice: fewer VPN clients, no flat network behind a single tunnel, and a compromised credential that reaches one app instead of everything. The ZTNA page goes into the mechanics.

Leave complexity behind.

See how Open Systems runs the full SSE layer and SASE Experience for your organization.

Contact us
Already a customerEverything you use today keeps running.