Zero trust access
Replace the VPN with identity-based, app-level access. PulseHA checks who they are, then routes around a dead gateway or backend so the session does not die with the path.
3 policies – 12/12 devices online
dana-mbp
macOS
lee-win
Windows
partner-linux
Linux
Protected Services
payments-api
TCP:8443
internal-db
TCP:5432
legacy-smb
TCP:445
dana-mbp
Dana Morganlee-win
Lee Cheneu-west-gw-1
uksouthpayments-api
TCP:8443legacy-smb
TCP:445Manage registered gateway nodes and their connectivity status.
| Name | Region / Site | Exit | Status | Sessions | Last 24h Traffic | Tunnel IP | Version | Last Seen | ||
|---|---|---|---|---|---|---|---|---|---|---|
| eu-west-gw-1 | uksouth | Active | Online | 7 | RX 1.2 GB / TX 840 MB | 10.8.0.1 | 1.4.2 | just now | ||
| eu-west-gw-2 | uksouth | Active | Online | 3 | RX 410 MB / TX 190 MB | 10.8.0.2 | 1.4.2 | 12s ago | ||
| us-east-gw-1 | us-east-1 | Capable | Online | 2 | RX 96 MB / TX 44 MB | 10.8.0.3 | 1.4.1 | 8s ago |
Monitor enrolled endpoints, confirm healthy tunnels, and revoke access when a device drifts out of compliance.
| Device | User | Connection | Posture | IP Address | Traffic | Platform | Version | Gateway | Last seen | |
|---|---|---|---|---|---|---|---|---|---|---|
| dana-mbp | dana@acme.com | Online | Compliant | 10.8.0.12 | ↓ 240 MB↑ 18 MB | macOS | 1.4.2 | uksouth | just now | |
| lee-win | lee@acme.com | Online | Compliant | 10.8.0.18 | ↓ 91 MB↑ 12 MB | Windows | 1.4.2 | us-east-1 | 12s ago | |
| partner-linux | contractor@partner.io | Idle | Non-compliant | 10.8.0.41 | ↓ 4 MB↑ 1 MB | Linux | 1.3.9 | uksouth | 4m ago |
Observe protected resources, the gateways advertising them, and the latest health telemetry.
| Service | Target | Gateways | Health | Updated | ||
|---|---|---|---|---|---|---|
| payments-api HTTP | 10.20.0.14:8443 | eu-west-gw-1 | Healthy 18ms latency | 12s ago | ||
| internal-db NONE | 10.20.0.40:5432 | eu-west-gw-1 | Healthy 6ms latency | 18s ago | ||
| legacy-smb NONE | 10.20.0.88:445 | us-east-gw-1 | Down Checked 4m ago | 4m ago |
Control who can reach protected resources, which gateways enforce those rules, and when the policies last changed.
| Status | Policy | Effect | Sources | Services | Gateways | Updated | |
|---|---|---|---|---|---|---|---|
| eng-payments | Allow | eng-payments | payments-api | eu-west-gw-1 | 2h ago | ||
| eng-data | Allow | eng-payments | internal-db | eu-west-gw-1 | 1d ago | ||
| contractor-smb | Deny | contractor | legacy-smb | us-east-gw-1 | 5d ago |
Active in 1 of 3 regions. Route traffic via exit policies.
1 of 3 regions active. Lit regions carry your egress today.
| Region | Geography | Status |
|---|---|---|
| Frankfurt (Germany) | Europe | Opted in |
| Washington, D.C. (United States) | Americas | Available |
| Singapore (Singapore) | Asia-Pacific | Available |
Policy Coverage Healthy
90Identity Security At Risk
70Device Posture Healthy
88Access Hygiene Healthy
85Network Segmentation Healthy
80Visibility At Risk
75Threat surface
Grade BLooking good
Reading the terrain
Each ridge is one security factor. Higher, redder peaks mean more exposure — flat green ground means you're covered.
80+ healthy
60–79 at risk
<60 critical
Biggest win right now
Tighten identity security → SettingsBlocked access attempts, web filtering decisions, and top offenders.
Access
42
■ 870 total decisions
Secure Web
186
■ 1.2k DNS queries
94 malware blocked
Firewall
12
■ 36 total decisions
payments-api18
internal-db12
legacy-smb8
malware94
phishing48
newly-registered28
10.20.0.888
10.20.0.143
Define the security checks devices must pass and how non-compliance is enforced before granting network access.
Applies whenever no device, group, or role override wins.
Disk Encryption, Firewall, OS Version
Device overrides win first, followed by group, role, then the baseline.
| Applies to | Precedence | Mode | Requirements | Effective on | Status | Updated | |
|---|---|---|---|---|---|---|---|
| dana-mbpDevice | 1 · DeviceOrder 1 | Monitor | Screen Lock | 1 devices | Active | 2d ago |
Control DNS-level web gateway policies for your organization.
| Status | Name | Scope | Rules | ||
|---|---|---|---|---|---|
| Malware feed | All users | 8 | |||
| Engineering GitHub | eng-payments | 1 |
Manage L3/L4 firewall rules enforced at the gateway level, independent of ZTNA access policies.
| Priority | Name | Direction | Source | Destination | Protocol/Port | Action | Log | Status | Updated | ||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 10 | deny-smb-inbound | Inbound | Any | 10.20.0.88 | TCP/445 | Deny | On | 2d ago | |||
| 20 | allow-eng-egress | Outbound | eng-payments | Any | Any | Allow | Off | 5d ago |
| Time | Category | Event | Actor | Agent | Gateway | Destination | Protocol | Decision |
|---|---|---|---|---|---|---|---|---|
| just now | Content Filter | Domain Blockedcrypto-drainer.net | dana@acme.com | dana-mbp | eu-west-gw-1 | crypto-drainer.net | DNS | deny |
| 12s ago | Access | Access Allow | dana@acme.com | dana-mbp | eu-west-gw-1 | payments-api | TCP | allow |
Manage your profile information and preferences
Upload an image or use your initials
UploadJPEG, PNG, GIF, or WebP. Max 5MB.
Manage your personal information
Full Name
Dana Morgan
Email Address
dana@acme.com Read-only
Customize how PulseHA looks on your device
Configure how and when you receive notifications
Manage two-factor authentication for your account
Single sign-on, user provisioning, and session policies for your organization.
Control how devices enroll and prove they belong to your organization.
View your organization details and usage statistics.
Manage and verify your organisation's domains. Verified domains can be used for SSO authentication and custom DNS suffixes.
Configure DNS-based service discovery for your network.
Invite teammates, assign roles, and manage access.
| Name | Role | Status | Last Activity | |
|---|---|---|---|---|
| Dana Morgan | dana@acme.com | Owner | Active | just now |
| Lee Chen | lee@acme.com | Admin | Active | 12s ago |
Create custom roles and assign granular permissions for your organization.
View and manage your billing plan.
In production where downtime is unforgiving.
Platform
Start with zero trust access. Add health-aware routing. Add DNS-layer filtering and an identity-aware firewall. Same identity, same gateways — for users, sites, and clouds.
Why VPNs fail
A VPN authenticates once, opens a path, and assumes everything behind it stays healthy. That is how you get sprawl, a single point of failure, and users landing on dead apps.
Too many tunnels. Full-network access after login. Almost no idea who reached what.
One failed gateway or concentrator stalls every connection. There is no second path.
Users authenticate successfully and still land on a backend that is already down.
Use cases
Remote staff, contractors, critical apps, and hybrid networks — without opening the network.
Staff reach the apps they need from any network. No concentrator, no full-tunnel dump.
Give contractors and partners a path to specific apps. The rest of the network stays invisible.
When a gateway or backend fails, traffic moves to a healthy path. Users stay in the app.
Join data centers, clouds, and edge sites under one identity-aware fabric.
In real-time game hosting, failures are immediate. Level 1K uses PulseHA to keep access up without giving up performance.
Self-hosted gateways on the infrastructure you already run, including Azure, with health and policy in one console.
Built by engineers who operate production networks. Security tooling should earn trust in the path, not the pitch.