ZTXGate represents a cutting-edge Zero Trust Network Access (ZTNA) solution that merges the intuitive experience of a contemporary SaaS control plane with the benefits of on-premises software, including deployment flexibility, data sovereignty, and isolated blast-radius capabilities. Each client utilizes a unique single-tenant instance to ensure optimal security and performance.
The platform facilitates identity federation through OIDC SSO for the administrative portal, featuring a per-provider registry, PKCE implementation, group-to-role mapping, and a local break-glass conversion. It also supports SCIM 2.0 inbound provisioning via a dedicated hardened listener equipped with per-token bearer authentication, CIDR allowlisting, and rate limitations. The system enables cross-protocol identifier linkage to ensure that an OIDC login and a SCIM-provisioned user are recognized as a single identity.
Additionally, ZTXGate offers a pluggable biometric step-up solution that allows for push challenges through its own authenticator (ZTXBAS), as well as Okta Verify Push and Duo Push, all governed by a unified policy field. Resource-specific policies determine the backend in use, while API credentials are securely encrypted at rest.
Furthermore, the platform incorporates MDM and EDR device posture as a crucial element of its policy framework, supporting integrations with Microsoft Intune, Defender, and SentinelOne Singularity to enhance overall security posture and compliance.