01 · AGENT
It starts on the device.
Every connection begins with a verified identity — the user, the device posture, the app making the request. No identity, no path.
- SSO identity + device posture check
- Works on any OS, any network
Zero Trust Network Access
Smart routing, automatic failover, and gateways and DNS you control — plus Pulse Orbit, managed egress you opt into region by region. One identity-aware network across every site, cloud and device. No backhaul. No appliances.
Application-aware access
01 · AGENT
Every connection begins with a verified identity — the user, the device posture, the app making the request. No identity, no path.
02 · GATEWAY
Per-app, per-identity rules resolve at the gateway closest to the request. The gateway knows the application — not just an IP and a port.
03 · EGRESS
Leave from your own exit nodes, or hand egress to Pulse Orbit. Pin the region, keep your keys, and decide what gets logged — down to nothing at all.
04 · APP
The connection lands on the application directly — never exposed to the public internet, resolved through internal, app-based DNS.
Pulse Orbit · Managed Egress
Egress is a choice. Keep it all in your own network with self-hosted gateways and DNS — or hand it to Pulse Orbit: managed exit regions you opt into one by one, each tagged for data residency and health-checked continuously. Smart routing picks the fastest path, live.
Your data, your control
Egress from your own nodes, pin the region, and decide what gets logged — full, metadata only, or off. Privacy is the default — not an upsell.
Smart routing · The HA in PulseHA
Gateways are ranked on live signals — latency, load, region and priority — and every agent keeps re-measuring its own round-trip times. When a path goes quiet, traffic moves to the next-best gateway in seconds, and the event lands in your audit log.
Everything in Network
Nothing buried behind a sales call. Every plan includes the full self-hosted network.
Identity- and app-level policy across any port or cloud — no IP allowlists, no network segments to babysit.
BYO exit nodes, region pinning, and logging you control — metadata, full, or off.
Ranked multi-gateway failover, detected in seconds — the HA in PulseHA.
Paths scored on latency, load, region and priority — re-ranked live.
Managed exit regions you opt into one by one, each tagged for data residency.
Deploy at any site or cloud — health, metrics and tunnels in one console.
Private resolution mapped to apps.
Connect whole networks behind gateways — no appliance mesh to maintain.
SAML, OIDC and Entra auto-login, with SCIM provisioning and JIT.
Test before you trust
Pick a user, a device and a service, and watch the decision resolve stage by stage — posture, device, access, egress — with the exact policy that matched. No guessing in production.
# simulate · who can reach what, and why user dana@acme.com device macbook-dana · managed service payments-api → posture ✓ pass # disk encryption · screen lock → device ✓ pass # managed · agent up to date → access ✓ allow # matched policy: eng-payments → egress orbit · eu-central # region pinned decision ALLOW
In real-time game hosting, failures are immediate and unforgiving. Level 1K uses PulseHA to secure infrastructure without sacrificing performance or availability
Built on enterprise-grade infrastructure with security and reliability engineered from the foundation up.
PulseHA is built by engineers who ship open source, operate production networks, and believe security tooling should earn trust through transparency.
Plans
Run your own gateways, exits and DNS on day one. Pulse Orbit and security unlock at Business and above.
Full feature breakdown on the plans page →
Better together · Business and up
Same policy engine, same fabric. Add inline threat defence without adding a single appliance.