The platform
One agent. Every layer of access.
QuickZTNA consolidates your VPN, SSO gateway, access-governance workflow, and Terraform state into one tailnet. Every feature below is shipped today and available on both plans — no coming-soon shelf, and nothing here is gated behind an upgrade.
Networking & Connectivity
The ZTNA primitives. Ship with every plan, no gate, no trial. This is the foundation.
10 features
WireGuard mesh data plane
FreeModern, audited X25519 + ChaCha20-Poly1305 + Poly1305 stack. Direct peer-to-peer where NAT allows; DERP relay fallback (Bangalore + Frankfurt) for CGNAT and symmetric NAT.
MagicDNS
FreeEvery device reachable at
DERP relays
Free2 regions (Bangalore + Frankfurt) relay when P2P is blocked by symmetric NAT or CGNAT.
STUN NAT discovery
FreeAutomatic public endpoint discovery. Peers find each other without central coordination.
ABAC ACLs
FreeRules on user, tag, posture, time of day, country, protocol, port. Evaluated per connection.
Subnet routes
FreeAdvertise + accept CIDR routes. Bridge home labs, cloud VPCs, legacy networks.
Exit nodes
FreeRoute outbound traffic through a chosen peer. Geofence compliance, egress control.
Device posture
FreeOS version, disk encryption, firewall, antivirus checks. Block non-compliant devices.
Auto-quarantine
FreeFailed posture → machine isolated automatically. Admin notified.
Tailnet IP allocation
FreeAtomic 100.64.x.x allocation. Guaranteed no collisions, even under concurrent registration.
Admin Insights
Deterministic reports computed from your own tenant data. No model in the decision path.
4 features
Security digest
Free24-hour report: machines, threats blocked, compliance rate, JIT requests.
Policy drift detection
FreeFlags overly permissive ACL rules against a deterministic baseline.
Access heatmap
FreeWhich users touch which resources, when, how often.
Optional LLM summary
FreeAny insight can be rendered as a written summary — opt-in per request, off by default. The underlying numbers are computed, not generated.
Security & Threat Detection
Defense in depth. Shipped as a single agent, not five separate tools to deploy.
1 features
Malware detection (file-hash)
FreeAgents report SHA-256 file hashes; confirmed-malicious hits are recorded and, in enforce mode, quarantine the device.
Governance & Compliance
Audit-ready by default. SOC 2 / ISO 27001 / HIPAA artifacts generated, not assembled.
5 features
Compliance reports
FreeOne-click SOC 2 / ISO 27001 / HIPAA evidence bundles. Signed, timestamped.
Continuous compliance
FreeBackground rules run daily. Drift flagged before audit time.
JIT access workflow
FreeRequest → approve → time-bounded grant → auto-revoke. Full audit trail.
Access review campaigns
FreePeriodic campaigns. Approvers confirm / revoke. Everything logged.
Policy version rollback
FreeEvery ACL change versioned. Roll back to any prior version instantly.
Identity & Provisioning
Bring your identity provider. SSO, SCIM, OAuth — all free. MFA-ready, device-bound.
6 features
Email + password
FreePBKDF2-SHA256 100K iterations. Timing-safe. Per-email rate-limited.
GitHub / Google OAuth
FreeOne-click sign-in for dev teams. Respects org domains.
OIDC SSO
FreeOkta, Azure AD, Google Workspace, Auth0, any OIDC-compliant IdP. (SAML login is temporarily disabled pending a security fix — use OIDC with the same providers.)
TOTP MFA
FreeRFC 6238. Replay-protected (used codes cached 90s). 10 backup codes per user.
SCIM 2.0 provisioning
FreeAutomated user lifecycle from Okta, Azure AD. Groups sync.
Org groups (departments)
FreeSub-tenants within an org. Scoped ACLs, isolated users.
Endpoint Management
One agent — remote diagnostics, secure shell, device lifecycle, OTA updates.
4 features
Remote management
FreeRun safe diagnostic commands across the fleet. Whitelisted verbs only.
Remote shell
FreeBrowser-based shell for diagnostics, opened with a single-use ticket. Included on every plan, not gated behind an enterprise tier.
Device wipe / lock
FreeAdmin can lock or wipe stolen/lost devices with signed commands.
OTA agent updates
FreeSelf-update via signed releases. Controlled by client_versions table.
Data & Access Layer
Protect internal apps, databases, Kubernetes, cloud VPCs — through the same tailnet.
5 features
Database access broker
FreeRegister PG/MySQL/Mongo/Redis. JIT credentials, scoped queries, audit.
Kubernetes access
FreeIdentity-scoped kubeconfig. RBAC inherited from your org roles.
App connector
FreeProtect internal web apps (Jira, Jenkins, Grafana) with reverse proxy + ZTNA auth.
Webhook forwarder
FreeInbound webhooks delivered through the mesh to private targets.
Terraform provider
FreeFull IaC for machines, ACLs, DNS, users, settings. GitOps-friendly.
FAQ
Common questions about QuickZTNA features
Is the WireGuard encryption available on every plan?
What is the difference between the Free and Business plans?
Does QuickZTNA support OIDC SSO?
Can QuickZTNA replace my existing VPN?
Which platforms does QuickZTNA support?
What compliance certifications does QuickZTNA support?
Is there a self-hosted or air-gapped deployment option?
Does any tenant data go to a third-party AI provider?
See exactly what's on each plan.
Full per-feature comparison. Honest limits. No surprise upsells.