SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Secure Access · SSE · Live

Zero Trust Network Access

Provide secure access to anyone, anywhere. Access follows identity, not IP addresses, on a need-to-know, least-privilege basis. We run it 24/7 with Level-3 engineers, on 35 years of operational baseline.

What is ZTNA?

Never trust, always verify.

ZTNA stands for Zero Trust Network Access, a security framework that shifts the focus from traditional perimeter-based security to a more holistic approach, where every user, device and network connection is treated as untrusted by default. The main principle of ZTNA is "never trust, always verify," which means that each access request must be authenticated, authorized and continuously validated before granting access to resources or data.

Zero Trust Network Access architecture follows an adaptive trust model, operating on a need-to-know, least-privilege basis.

Under ZTNA, only authenticated and authorized users, endpoints and applications are granted access to corporate resources. Access is centrally managed, policy-based and granular, ensuring flexibility and security.

Open Systems ZTNA architecture: users and devices reaching applications through a cloud-based zero trust access layer
Why organizations need ZTNA

Benefits.

Connect everything securely

ZTNA provides flexible and secure access to users, sites and partners using any device, anywhere in the world.

ZTNA cloud

We offer integrated, smart routing via cloud-based ZTNA PoPs, ensuring higher performance.

True zero trust architecture

By separating identity provider, traffic routing and ZTNA, the impact of a compromise can be minimized.

24/7 fully managed service

Delivered with every capability you need to start using it today, operated by Level-3 engineers. No L1, no L2.

How ZTNA works

Serve every user, reach every app.

Serve every user

  • Agentless or agent-based, to include any type of user
  • For agent-based: enforce encryption on all incoming traffic via ZTNA by adding a Secure Web Gateway
ZTNA connects any user, device and location, from the left, through the zero trust cloud to applications

A range of policy options

  • Enrich authentication using credentials, certificates and MFA
  • Set policy by factors including user group, device posture and NDR-provided risk score
ZTNA policy options based on identity, device posture and risk score

Access all applications

  • Ensure short paths and place enforcement points near your apps
  • Control access to corporate SaaS, cloud-based and on-premises applications
ZTNA controlling access to SaaS, cloud and on-premises applications
ZTNA vs. VPN

Why ZTNA replaces the VPN.

ZTNA and VPNs (Virtual Private Networks) are both technologies that enable secure remote access to organizational resources. However, they differ in their approach, architecture and security principles.

Trust model

ZTNA operates on a "never trust, always verify" principle, so each access request must be authenticated, authorized and continuously validated. VPNs establish a secure tunnel to the network, and once a user is connected they are often granted broad access to resources.

Access control

ZTNA enforces granular, context-aware access policies based on user identity, device and other factors. Access is granted on a need-to-know basis and limited to specific applications. VPNs provide network-level access, which can expose a larger attack surface.

Lateral movement

ZTNA eliminates the possibility of lateral movement by granting access solely to necessary resources. VPNs often provide access to the full internal network, which attackers could exploit.

User experience

ZTNA grants access to specific applications without a full network connection, for a more seamless experience. VPNs require connecting to the corporate network first, which can be slower and more cumbersome.

Scalability and performance

ZTNA is typically more scalable and handles many users and connections more efficiently than traditional VPNs, which matters in cloud-based or distributed environments where traffic and locations change rapidly.

One platform

Deliver network and security in the cloud.

Integrate Open Systems ZTNA with our cloud-based Managed SASE service for maximum protection. Begin your SASE journey with ZTNA and add our other services, Secure Web Gateway, Mobile Entry Point, Firewall and CASB, as needed. Manage all of them from a unified interface.

ZTNA is available as a stand-alone product or as an add-on to any of our Managed SASE service plans. Our plans combine 24/7 Level-3 expertise focused on connecting and protecting users, apps, sites and clouds, all unified on an intelligent platform running on 35 years of operational baseline.

Open Systems engineers operating the platform
FAQ

Questions about ZTNA.

Do our users have to install an agent?

Not necessarily. Access can be agentless or agent-based, which is what makes it possible to cover every type of user, including contractors and unmanaged devices that a rollout would otherwise stall on. The agent adds enforcement options, for example routing all incoming traffic through a Secure Web Gateway.

Does ZTNA only work for SaaS, or also for our own applications?

Both. Policy covers corporate SaaS, cloud-based and on-premises applications alike, and enforcement points are placed close to the apps so the path stays short. That matters for the older internal application that is the real reason the VPN is still running.

What happens if a device stops being trustworthy mid-session?

Access is continuously validated, not checked once at login. Policy takes user group, device posture and, where NDR is in use, a live risk score into account, so a session whose conditions no longer hold loses its access instead of running until the token expires.

Do we have to replace our identity provider?

No. Your IdP stays, and ZTNA layers policy on top of it: credentials, certificates and MFA for authentication, then context for authorization. Keeping identity provider, traffic routing and ZTNA separate is deliberate, because that separation is what keeps one compromise from becoming all three.

How do contractors, partners and integrators get access?

The same way employees do, scoped to the individual application rather than to the network. That is usually the fastest win of a ZTNA project: third-party access stops being a VPN account with broad reach and becomes a named, time-bounded, logged path to exactly one system.

Can we start with ZTNA and add the rest later?

Yes. ZTNA is available stand-alone or as an add-on to any Managed SASE plan, and it is the most common entry point into the platform. Secure Web Gateway, CASB, Firewall and Mobile Entry Point can follow whenever the next contract falls due, managed from the same interface.
Resources

Go deeper.

Leave complexity behind.

See how Open Systems runs ZTNA and the full SASE Experience for your organization. Talk to a specialist.

Contact us
Already a customerEverything you use today keeps running.