Skip to main content

Security and Trust at CoreZT

CoreZT builds access products around a simple principle: access should be explicitly authorized, limited to what is required, and visible to the teams responsible for protecting the environment.

ZTXGate combines identity, device context, resource-level policy, authentication, access enforcement, and audit visibility in a Zero Trust Network Access platform that can be operated by the customer or an MSP.

Least-Privilege Access

ZTXGate is designed to give users access to defined resources instead of treating private-network connectivity as authorization by itself.

Policies can consider user identity, role, enrolled device, device posture, network location, time, resource, and access duration.

Individual Device Identity

Each device can be enrolled and managed individually. If an endpoint is lost, retired, or no longer trusted, administrators can revoke that device without necessarily affecting the user's other enrolled endpoints.

Device Posture

In connected environments, ZTXGate can use posture information from supported endpoint-security platforms as an additional policy signal.

Current integrations include Microsoft Intune, Microsoft Defender for Endpoint, SentinelOne Singularity, CrowdStrike, and Jamf.

Explore Identity & Device Trust

Identity Integration

ZTXGate supports OIDC for authentication and single sign-on, and SCIM for user provisioning and identity lifecycle synchronization.

Authentication According to Risk

ZTXGate supports policy-based additional verification using supported methods. When licensed with ZTXGate, ZTXBAS is tightly integrated as a library and does not require a separate ZTXBAS server deployment. It works across connected, on-premises, hybrid, and fully air-gapped ZTXGate deployments. Cloud-dependent authentication services such as Okta Verify and Duo remain available where those services are reachable.

The security properties of each authentication method depend on that method's design and configuration.

Temporary and Approved Access

ZTXGate supports temporary access and request-and-approve workflows for sensitive resources. An authorized approver can grant access for a defined period, after which the permission expires automatically.

Continuous Policy Enforcement

Conditions can change after access begins. ZTXGate can continue evaluating relevant policy conditions and revoke access when those conditions no longer satisfy policy.

WireGuard-Based Connectivity

Managed ZTXGate endpoints use WireGuard-based connectivity for authorized access. Within ZTXGate, tunnel connectivity is only one part of the access model: identity, device state, resource definition, and policy determine what access is actually authorized through the platform.

Explore WireGuard & ZTNA

Clientless HTTP/HTTPS Access

ZTXGate can also provide clientless access for HTTP and HTTPS applications through its policy-enforcing proxy, allowing authorized browser-based access without requiring WireGuard on the endpoint.

Customer- or MSP-Operated Deployment

ZTXGate is deployed inside infrastructure operated by the customer or an MSP. Core access operation does not require a mandatory CoreZT-hosted cloud control plane.

Supported deployment models include on-premises, cloud-hosted infrastructure, hybrid environments, and air-gapped environments.

External integrations naturally retain their own connectivity requirements.

Explore the control-plane model

Administration and Separation of Responsibilities

ZTXGate provides built-in administrator, helpdesk, and read-only audit roles so operational responsibilities do not all require full administrative authority.

Policy Simulation

ZTXGate includes policy simulation capabilities that allow administrators to evaluate an intended (user, device, resource) access decision before relying on the policy in production.

Audit Records

ZTXGate maintains records related to access, authentication, and policy activity. Administrators can use these records for investigations, operational reviews, access reviews, troubleshooting, and audit evidence collection.

SIEM Integration

ZTXGate can forward relevant events using RFC 5424 syslog, ArcSight CEF, or JSON. Supported transport options include UDP, TCP, and TCP with TLS according to the integration.

Backup and Disaster Recovery

ZTXGate does not provide conventional HA clustering. The administration portal supports periodic backups, and a backup can be restored into a fresh ZTXGate deployment when recovery is required.

This is a backup-and-restore disaster recovery model rather than continuous failover. Organizations should protect backup copies and plan replacement infrastructure and recovery procedures according to their own recovery objectives.

Security in Air-Gapped Environments

ZTXGate's core access platform can be deployed without depending on a CoreZT-hosted cloud control plane. A standalone deployment uses manual license and software update workflows and can remain fully air-gapped.

When licensed with ZTXGate, integrated ZTXBAS remains available within an isolated deployment for phishing-resistant biometric authentication without a separate ZTXBAS server. External identity, MDM, EDR, SIEM, or cloud authentication services remain external dependencies and require connectivity if used.

Connected deployments that want centralized update and license management can optionally use ZTXHub, a service owned and operated by CoreZT; it is not required for standalone ZTXGate operation.

Explore Air-Gapped ZTNA

Compliance and Audit Support

Security products can support an organization's compliance program, but product capabilities should not be confused with certification.

ZTXGate provides controls and evidence that can support activities such as access-control reviews, user and device accountability, temporary-access management, authentication records, policy records, security-event monitoring, and audit evidence collection.

These capabilities may help organizations satisfy controls relevant to frameworks and regulatory requirements such as SOC 2, ISO 27001, PCI DSS, or HIPAA, depending on the customer's environment and implementation.

Using ZTXGate does not by itself make an organization compliant with any framework, and references to those frameworks do not imply a CoreZT certification unless explicitly stated.

Security of the Surrounding Environment Matters

Organizations deploying ZTXGate remain responsible for security practices around the systems they operate, including host hardening, operating-system maintenance, administrator access, certificate and key management, network configuration, backup protection, log monitoring, availability, and integration security.

ZTXGate forms part of that security architecture rather than replacing it.

Privacy and Data Handling

Review the relevant legal and privacy information alongside the technical architecture:

Reporting a Security Issue

Until CoreZT publishes a dedicated vulnerability-reporting address or disclosure page, security-related reports can be sent privately to support@corezt.com.

Please include enough information for the CoreZT team to understand and reproduce the issue while avoiding unnecessary exposure of sensitive data.

Security Is an Access Lifecycle

Identity → Device → Policy → Authentication → Access → Continuous Enforcement → Audit

The objective is to make access explicit, limited, observable, and responsive to changing conditions.