The platform

One agent. Every layer of access.

QuickZTNA consolidates your VPN, SSO gateway, access-governance workflow, and Terraform state into one tailnet. Every feature below is shipped today and available on both plans — no coming-soon shelf, and nothing here is gated behind an upgrade.

Free — 5 users, every feature Business — $10 / user / mo
Category 01

Networking & Connectivity

The ZTNA primitives. Ship with every plan, no gate, no trial. This is the foundation.

10 features

WireGuard mesh data plane

Free

Modern, audited X25519 + ChaCha20-Poly1305 + Poly1305 stack. Direct peer-to-peer where NAT allows; DERP relay fallback (Bangalore + Frankfurt) for CGNAT and symmetric NAT.

MagicDNS

Free

Every device reachable at ..zt.net. Zero DNS config.

DERP relays

Free

2 regions (Bangalore + Frankfurt) relay when P2P is blocked by symmetric NAT or CGNAT.

STUN NAT discovery

Free

Automatic public endpoint discovery. Peers find each other without central coordination.

ABAC ACLs

Free

Rules on user, tag, posture, time of day, country, protocol, port. Evaluated per connection.

Subnet routes

Free

Advertise + accept CIDR routes. Bridge home labs, cloud VPCs, legacy networks.

Exit nodes

Free

Route outbound traffic through a chosen peer. Geofence compliance, egress control.

Device posture

Free

OS version, disk encryption, firewall, antivirus checks. Block non-compliant devices.

Auto-quarantine

Free

Failed posture → machine isolated automatically. Admin notified.

Tailnet IP allocation

Free

Atomic 100.64.x.x allocation. Guaranteed no collisions, even under concurrent registration.

Category 02

Admin Insights

Deterministic reports computed from your own tenant data. No model in the decision path.

4 features

Security digest

Free

24-hour report: machines, threats blocked, compliance rate, JIT requests.

Policy drift detection

Free

Flags overly permissive ACL rules against a deterministic baseline.

Access heatmap

Free

Which users touch which resources, when, how often.

Optional LLM summary

Free

Any insight can be rendered as a written summary — opt-in per request, off by default. The underlying numbers are computed, not generated.

Category 03

Security & Threat Detection

Defense in depth. Shipped as a single agent, not five separate tools to deploy.

1 features

Malware detection (file-hash)

Free

Agents report SHA-256 file hashes; confirmed-malicious hits are recorded and, in enforce mode, quarantine the device.

Category 04

Governance & Compliance

Audit-ready by default. SOC 2 / ISO 27001 / HIPAA artifacts generated, not assembled.

5 features

Compliance reports

Free

One-click SOC 2 / ISO 27001 / HIPAA evidence bundles. Signed, timestamped.

Continuous compliance

Free

Background rules run daily. Drift flagged before audit time.

JIT access workflow

Free

Request → approve → time-bounded grant → auto-revoke. Full audit trail.

Access review campaigns

Free

Periodic campaigns. Approvers confirm / revoke. Everything logged.

Policy version rollback

Free

Every ACL change versioned. Roll back to any prior version instantly.

Category 05

Identity & Provisioning

Bring your identity provider. SSO, SCIM, OAuth — all free. MFA-ready, device-bound.

6 features

Email + password

Free

PBKDF2-SHA256 100K iterations. Timing-safe. Per-email rate-limited.

GitHub / Google OAuth

Free

One-click sign-in for dev teams. Respects org domains.

OIDC SSO

Free

Okta, Azure AD, Google Workspace, Auth0, any OIDC-compliant IdP. (SAML login is temporarily disabled pending a security fix — use OIDC with the same providers.)

TOTP MFA

Free

RFC 6238. Replay-protected (used codes cached 90s). 10 backup codes per user.

SCIM 2.0 provisioning

Free

Automated user lifecycle from Okta, Azure AD. Groups sync.

Org groups (departments)

Free

Sub-tenants within an org. Scoped ACLs, isolated users.

Category 06

Endpoint Management

One agent — remote diagnostics, secure shell, device lifecycle, OTA updates.

4 features

Remote management

Free

Run safe diagnostic commands across the fleet. Whitelisted verbs only.

Remote shell

Free

Browser-based shell for diagnostics, opened with a single-use ticket. Included on every plan, not gated behind an enterprise tier.

Device wipe / lock

Free

Admin can lock or wipe stolen/lost devices with signed commands.

OTA agent updates

Free

Self-update via signed releases. Controlled by client_versions table.

Category 07

Data & Access Layer

Protect internal apps, databases, Kubernetes, cloud VPCs — through the same tailnet.

5 features

Database access broker

Free

Register PG/MySQL/Mongo/Redis. JIT credentials, scoped queries, audit.

Kubernetes access

Free

Identity-scoped kubeconfig. RBAC inherited from your org roles.

App connector

Free

Protect internal web apps (Jira, Jenkins, Grafana) with reverse proxy + ZTNA auth.

Webhook forwarder

Free

Inbound webhooks delivered through the mesh to private targets.

Terraform provider

Free

Full IaC for machines, ACLs, DNS, users, settings. GitOps-friendly.

FAQ

Common questions about QuickZTNA features

Is the WireGuard encryption available on every plan?
Yes. WireGuard's X25519 + ChaCha20-Poly1305 + Poly1305 cipher suite is used on every tunnel, on every plan including Free. It is not a paid feature, not behind a flag, and cannot be downgraded. Key rotation follows the WireGuard spec.
What is the difference between the Free and Business plans?
Features are identical — both plans include the entire platform (WireGuard ZTNA mesh, ABAC + device posture, JIT access, access reviews, compliance reports, remote shell, SSO, SCIM, and more). The only difference is scale: Free covers 5 users and up to 100 devices; Business ($10 per user per month) is unlimited users billed per seat, with up to 10,000 devices. Billing is per user, never per device — you pay to grow, not to unlock features.
Does QuickZTNA support OIDC SSO?
Yes. OIDC SSO works on every plan including Free, with pre-configured connectors for Google Workspace, Microsoft Entra (formerly Azure AD), Okta, Authentik, GitHub, and any standards-compliant identity provider. SCIM 2.0 provisioning and TOTP multi-factor authentication are included on every plan. SAML login is temporarily disabled pending a security fix — the same identity providers work over OIDC in the meantime.
Can QuickZTNA replace my existing VPN?
Yes, for most workloads. QuickZTNA is a mesh VPN with WireGuard data plane plus the full ZTNA feature set (identity-based ACLs, continuous device posture, audit log retention, JIT access with approvals and policy rollback). Teams typically migrate user-VPN, site-to-site, and bastion-host access. Hardware VPN concentrators and IPsec-specific compliance scenarios may still need a separate solution.
Which platforms does QuickZTNA support?
Linux, macOS, and Windows. Native binaries for x86_64 (amd64) and arm64, plus armv7 on Linux. Headless installs with pre-authentication keys are supported for servers and containers. There are no mobile (iOS/Android) clients today.
What compliance certifications does QuickZTNA support?
We offer a GDPR-aligned DPA and sign HIPAA Business Associate Agreements on the Business plan. SOC 2 Type II and ISO 27001 certifications are in progress with target completion in 2026.
Is there a self-hosted or air-gapped deployment option?
Not today — QuickZTNA is a fully managed cloud service. If self-hosted or air-gapped deployment is a requirement for your organization, contact sales@quickztna.com to discuss your needs and our roadmap.
Does any tenant data go to a third-party AI provider?
Not by default. Admin Insights are computed deterministically from your own tenant data — no model sits in the decision path. A written summary of an insight can be requested explicitly per call, and only then is that report's content sent to the LLM provider; leave it off and no tenant data reaches a third-party model at all.

See exactly what's on each plan.

Full per-feature comparison. Honest limits. No surprise upsells.