SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Secure Access · SSE

Zero trust, for every user.

ZTNA, Secure Web Gateway, CASB, email security and firewall in one managed SSE layer. Security follows identity, not IP addresses, and we operate it 24/7.

Managed, not just deployed

We run the SSE, you set the intent.

24/7 monitoring, policy optimization and incident response, on 35 years of operational baseline.

Book a demo
Straight answers

Questions about secure access.

What comes up in the first workshop, before anyone writes a policy.

Does this replace our VPN?

Yes, and that is usually the first reason people arrive here. A VPN puts a device on the network and trusts it from then on; ZTNA grants access to a single application after identity, device posture and context are validated, and keeps validating. The practical difference shows up after a credential is stolen: the attacker reaches one app instead of the flat network behind the tunnel. The ZTNA page has the detail.

Do users need an agent on every device?

No. Access can be agentless or agent-based, which matters because contractors, partners and unmanaged devices are exactly the population a rollout stalls on. Agent-based access adds enforcement options such as routing all incoming traffic through the Secure Web Gateway.

We already have an identity provider. Does it get replaced?

No, it gets used. The platform integrates with your IdP and layers policy on top: credentials, certificates and MFA for authentication, then user group, device posture and NDR risk score for authorization. Keeping the identity provider, the traffic routing and the access enforcement separate is deliberate, so that one compromise does not become all three.

Is CASB worth it if we already control our SaaS?

The question CASB answers is the one about the SaaS you do not control. Discovery covers thousands of applications, sanctioned and shadow, which is typically where the surprise lives: a department that solved a problem with a credit card two years ago. Control comes after visibility, not before it.

Won't SSL inspection slow everything down or break applications?

Inspection happens at the point of presence nearest the user rather than in a backhauled data centre, so there is no detour, and exception handling for applications that legitimately refuse inspection, such as banking or health portals, is part of the policy work we do rather than something you discover in production.

Who runs this day to day?

We do, if you want. Level-3 engineers handle 24/7 monitoring, policy optimization and incident response on a 35-year operational baseline, and you set the intent. If you would rather run it yourself, the same controls are available self-serve with a public API. That choice is made per module, see the operating models.
Already a customerEverything you use today keeps running.