Skip to content
Apex
ApexProductsAetherEdge

AetherEdge.

Zero Trust & SASE — one model, one policy.

Secure access for every user, device and app: ZTNA, secure web gateway, CASB, firewall-as-a-service and inline DLP on one policy engine, with a continuous trust engine and digital experience monitoring. Inline inspection under 50ms, ZTNA setup under 400ms, session revocation under 5 seconds, 250,000 concurrent users — SASE parity, and uniquely, self-hosted and air-gapped.

Engines
12, one policy
Inline
≤ 50ms p95
Trust
Continuous, ≤ 2s
Deploy
Cloud · self-hosted · air-gapped
Coverage

One edge, one policy.

SASE was supposed to converge the stack, but most platforms are acquired modules behind one bill — four consoles and policies that drift. AetherEdge runs ZTNA, SWG, CASB, FWaaS and DLP on one policy engine and one model, with trust recomputed continuously, so a user's access reflects their risk right now, everywhere at once.

01

Zero Trust Network Access

App-level access, never network-level — a user reaches the one application they're entitled to, not the network it sits on. Connection setup under 400ms, no inbound ports exposed.

02

Secure web gateway

Inline TLS inspection at line rate with URL filtering, threat prevention and sandboxing — every web request inspected close to the user.

03

Cloud access security broker

Discover and govern SaaS and shadow IT, control risky OAuth grants and data movement to unsanctioned apps — inline and via API.

04

Firewall-as-a-service

Cloud-delivered L3–L7 firewall and IPS — consistent policy for every site and user without shipping appliances to branches.

05

Inline DLP

Data-loss prevention enforced at the edge across web, SaaS and private apps — the same classification that protects data at rest, applied in motion.

06

Unified policy decision point

One policy engine across ZTNA, SWG, CASB and FWaaS — write the rule once, enforce it everywhere, instead of four consoles that disagree.

07

Continuous trust engine

Trust is recomputed continuously from identity, device posture and behaviour — under 2 seconds — so access adapts the moment risk changes, not at the next login.

08

Identity federation

Integrate your IdP for SSO and conditional access, with device and posture signals feeding every access decision.

09

Global edge fabric

A network of points of presence with inline inspection under 50ms and user-to-PoP RTT under 30ms, scaling past 250,000 concurrent users and tunnels.

10

Digital experience monitoring

End-to-end visibility into the user's actual experience — where latency comes from, app, network or device — so security doesn't get blamed for every slowdown.

11

Session control

Revoke a session in under 5 seconds when trust drops — a compromised device or an anomalous user is cut off in real time, not at token expiry.

12

SASE copilot

Author a policy, investigate an access denial, explain a risk decision — in plain language over the whole edge estate.

One platform vs the SASE clouds

Converged, continuous — and yours to run.

The incumbents are shared clouds you route through. AetherEdge converges the stack on one policy engine, adds continuous trust, and can run as your own private edge.

✓ZTNA
✓Secure web gateway
✓CASB
✓Firewall-as-a-service
✓Inline DLP
✓Continuous trust engine
✓Digital experience monitoring
✓Self-hosted / air-gapped
The numbers

Inline, and invisible.

Security inline only works if users don't feel it. These are the budgets the platform is built to.

≤ 50 ms
inline inspection (p95)

every request

≤ 30 ms
user-to-PoP RTT (p95)

close to the user

≤ 400 ms
ZTNA setup (p95)

app connection

≤ 2 s
trust recompute (p95)

continuous, not at login

≤ 5 s
session revocation (p95)

cut off real-time

≤ 60 s
policy propagation (p95)

global

250,000+
concurrent users

and tunnels

Air-gapped
self-hosted option

private edge

Stack it replaces

One platform for the edge.

ZTNA, SWG, CASB, FWaaS, DLP and the VPN collapse into one policy engine, one console and one audit trail.

cloud SASE platforms
SSE platforms
SASE suites
edge-security platforms
SASE platforms
ZTNA services
Legacy VPN
Branch firewall appliances
FAQ

Good to know.

How is this different from cloud SASE platforms or SSE platforms?

Those pioneered cloud SASE and are excellent — but they're multi-tenant clouds you route your traffic through, with the security modules historically acquired and stitched. AetherEdge runs ZTNA, SWG, CASB, FWaaS and DLP on one policy engine and one model, adds a continuous trust engine that recomputes access in under 2 seconds, and — uniquely — deploys self-hosted or air-gapped, so you can run your own private edge for traffic that can't leave your boundary.

Is it fast enough to sit inline?

Inline inspection is under 50ms p95, user-to-PoP RTT under 30ms, and TLS inspection runs at line rate — security users don't feel. ZTNA app connections set up in under 400ms.

What makes the trust 'continuous'?

Access isn't granted once at login and forgotten. Identity, device posture and behaviour are evaluated continuously and trust is recomputed in under 2 seconds — so if a device falls out of compliance or a user does something anomalous, the session is revoked in under 5 seconds, not at the next token refresh.

Can we run our own edge?

Yes — self-hosted and fully air-gapped, scaling past 250,000 concurrent users and tunnels, so regulated or sovereign traffic gets SASE without routing through a vendor's shared cloud.

Converge the edge — on your terms.

ZTNA to DLP on one policy engine with continuous trust, inline under 50ms. Request access to deploy it as a managed edge or your own self-hosted, air-gapped private edge.

Part of Aether Security — one platform across thirteen domains. Zero Trust sits on the same foundation as the rest of Aether — one model, every discipline.