The platform
One agent. Every layer of access.
QuickZTNA consolidates your VPN, SSO gateway, secrets manager, SIEM, DLP, session recorder, and Terraform workflow into one tailnet. Every feature below is shipped, tested, and gated by plan — no coming-soon shelf.
Networking & Connectivity
The ZTNA primitives. Ship with every plan, no gate, no trial. This is the foundation.
10 features
Post-Quantum WireGuard
FreeX25519 + ML-KEM-768 hybrid key exchange on every tunnel. FIPS 203 compliant. No config — quantum-safe by default.
MagicDNS
FreeEvery device reachable at
DERP relays
Free4 global regions (BLR, NYC, LON, SFO) relay when P2P is blocked by symmetric NAT or CGNAT.
STUN NAT discovery
FreeAutomatic public endpoint discovery. Peers find each other without central coordination.
ABAC ACLs
FreeRules on user, tag, posture, time of day, country, protocol, port. Evaluated per connection.
Subnet routes
FreeAdvertise + accept CIDR routes. Bridge home labs, cloud VPCs, legacy networks.
Exit nodes
FreeRoute outbound traffic through a chosen peer. Geofence compliance, egress control.
Device posture
FreeOS version, disk encryption, firewall, antivirus checks. Block non-compliant devices.
Auto-quarantine
FreeFailed posture → machine isolated automatically. Admin notified.
Tailnet IP allocation
FreeAtomic 100.64.x.x allocation. Guaranteed no collisions, even under concurrent registration.
AI & Assistant
Claude-powered. Answers questions about your tenant, drafts policies, explains events, takes action.
9 features
AI chat
FreeConversational Q&A about your network, policies, users, and recent events.
Natural-language ACLs
FreeType "Laptops can SSH to prod between 9–6 IST" — get a ready-to-apply ACL rule.
Event summarizer
Free24-hour security digest. Anomalies surfaced, noise suppressed.
Security digest
FreeDaily report: machines, threats blocked, compliance rate, JIT requests.
Policy drift detection
FreeAI reviews your ACLs vs industry baselines. Flags overly permissive rules.
Access heatmap
FreeVisualize which users touch which resources, when, how often.
AI actions
Business+Approved auto-remediation. AI proposes, admin confirms, system executes with rollback.
Incident response playbooks
Business+Generate context-aware response steps for a specific incident.
JIT recommendations
Business+Suggests time-bounded grants based on historical access patterns.
Security & Threat Detection
Defense in depth. Shipped as a single agent, not five separate tools to deploy.
7 features
DNS filtering
FreeBlock malicious domains. Per-org allow/deny lists. Threat-intel feed sync.
Cloud firewall (FaaS)
FreeStateful firewall rules at the edge. Per-app, per-user, per-tag.
Honeypot / deception
Business+Decoy machines. Any interaction alerts. Zero false positives.
Anomaly detection
WorkforceUEBA baselines. Flags unusual access patterns, data movement, login geography.
Data Loss Prevention (DLP)
WorkforceScans agent-captured text for credit cards, SSNs, API keys. Report or block.
CASB
WorkforceSaaS app discovery, shadow-IT visibility, approval workflow.
User risk scoring
WorkforcePer-user risk timeline. Combines posture, behavior, threat intel.
Governance & Compliance
Audit-ready by default. SOC 2 / ISO 27001 / HIPAA artifacts generated, not assembled.
6 features
Compliance reports
Business+One-click SOC 2 / ISO 27001 / HIPAA evidence bundles. Signed, timestamped.
Continuous compliance
Business+Background rules run daily. Drift flagged before audit time.
Session recording
Business+Capture admin sessions (shell, SSH jump). Replay for audit.
JIT access workflow
FreeRequest → approve → time-bounded grant → auto-revoke. Full audit trail.
Access review campaigns
FreePeriodic campaigns. Approvers confirm / revoke. Everything logged.
Policy version rollback
FreeEvery ACL change versioned. Roll back to any prior version instantly.
Identity & Provisioning
Bring your identity provider. SSO, SCIM, OAuth — all free. MFA-ready, device-bound.
6 features
Email + password
FreePBKDF2-SHA256 100K iterations. Timing-safe. Per-email rate-limited.
GitHub / Google OAuth
FreeOne-click sign-in for dev teams. Respects org domains.
SAML / OIDC SSO
FreeOkta, Azure AD, Google Workspace, Auth0, any IdP.
TOTP MFA
FreeRFC 6238. Replay-protected (used codes cached 90s). 10 backup codes per user.
SCIM 2.0 provisioning
Business+Automated user lifecycle from Okta, Azure AD. Groups sync.
Org groups (departments)
WorkforceSub-tenants within an org. Scoped ACLs, isolated users.
Endpoint Management
One agent — remote commands, secure shell, WebRTC desktop, OTA updates.
5 features
Remote management
Business+Run safe diagnostic commands across the fleet. Whitelisted verbs only.
Remote desktop (WebRTC)
WorkforceBrowser-based remote control. Consent-gated, session-recorded.
Software inventory
WorkforcePatch overview per device. Approved software policy. Outdated versions flagged.
Device wipe / lock
FreeAdmin can lock or wipe stolen/lost devices with signed commands.
OTA agent updates
FreeSelf-update via signed releases. Controlled by client_versions table.
Data & Access Layer
Protect internal apps, databases, Kubernetes, cloud VPCs — through the same tailnet.
7 features
Secrets vault
Business+AES-256-GCM encrypted secrets. Envelope encryption with per-org DEKs. Rotation policies.
Database access broker
WorkforceRegister PG/MySQL/Mongo/Redis. JIT credentials, scoped queries, audit.
Kubernetes access
WorkforceIdentity-scoped kubeconfig. RBAC inherited from your org roles.
Cloud firewall sync
WorkforceAWS SG / Azure NSG / GCP firewall auto-sync with tailnet membership.
App connector
WorkforceProtect internal web apps (Jira, Jenkins, Grafana) with reverse proxy + ZTNA auth.
Webhook forwarder
WorkforceInbound webhooks delivered through the mesh to private targets.
Terraform provider
WorkforceFull IaC for machines, ACLs, DNS, users, settings. GitOps-friendly.
Workforce & Productivity
Built for distributed teams. Consent-first, GDPR-aware, compliance-ready.
6 features
Session tracking
WorkforceLogin/logout, active time, idle windows, machine activity.
App & domain usage
WorkforceTop domains per user, per machine. Productive vs unproductive categorization.
Productivity scoring
WorkforceRule-based scoring. Custom rules per team. Weekly reports.
Schedule compliance
WorkforceWork-hour adherence. Flag excessive overtime, weekend work.
Digital Experience Monitoring
WorkforcePer-device network health: latency, packet loss, jitter. Health score.
Monitoring consent (GDPR)
WorkforceRequired user acknowledgment before analytics start. Audit-logged.
See exactly what's on each plan.
Full per-feature comparison. Honest limits. No surprise upsells.