Device-Based ZTNA: Secure SaaS & Internal Access | Smallstep

Modern enterprise ZTNA backed by cryptographic device trust

Smallstep Enterprise Relay is a transparent VPN built on standards-based private MASQUE relays (RFC 9298). Using mutual TLS and hardware-bound device certificates, it ensures only trusted, managed devices can access SaaS apps, internal networks, and modern AI-initiated workflows, including MCP clients and automated tools, without passwords or user prompts.

Transparent to users

Device-wide enforcement

Stronger trust model with mutual TLS

Covers both SaaS and internal apps

Exclusive egress IPs

Cross-platform coverage

Protect SaaS apps and internal resources

Smallstep Enterprise Relay secures access to internal networks and public cloud apps like GitHub, Google Workspace, and Stripe. Easily specify which domains to route through the relay using match/exclude rules, then enforce access via IP allow lists and mutual TLS. From dashboards and APIs to SaaS accounts, Relay provides a unified layer of secure control.

Replace browser plugins and identity-only ZTNA

Many ZTNA tools rely on browser plugins or DNS workarounds. Smallstep Enterprise Relay provides network-level protection across the entire device. It authenticates hardware-attested devices—not just user sessions—and routes only approved traffic through a dedicated outbound IP range. Policies are enforced based on trusted, hardware-bound certificates, not just login credentials. No browser extensions, no redirect pages—only seamless, device-based security.

Enable transparent authentication for every user

With Smallstep Enterprise Relay, authentication happens silently in the background. There are no popups, login screens, or user prompts. If a device has a valid attested certificate, it gets access. If not, it’s blocked, and your users never need to think about it.

Extend ZTNA to all devices. Yes, Linux too

Smallstep Enterprise Relay is natively supported on Apple devices via the Managed Relay MDM payload (iOS 17+, iPadOS 17+, macOS 14+, tvOS 17+). For Windows and Linux, the Smallstep agent extends the same hardware-bound mutual TLS authentication. No browser extensions or third-party clients—just unified, system-level access control across your entire device fleet.

Learn more about the platform

The Smallstep platform helps mitigate numerous cybersecurity threats – from phishing to advanced hardware attacks – without impacting end-user workflows.

Device identity based ZTNA that just works

Deploy in the cloud or on-prem. Apply Zero Trust policies across every device without breaking workflows.

FAQs ZTNA

How does Smallstep ZTNA differ from traditional VPNs and perimeter-based access?

What makes Smallstep’s ZTNA approach unique?

What role does MASQUE/HTTP/3 play in Smallstep ZTNA?

Does Smallstep ZTNA require an agent?

How does Smallstep ZTNA connect remote users to private applications?

How does Smallstep prevent compromised or unmanaged devices from accessing apps?

Which applications can Smallstep ZTNA protect?

How is Zero Trust enforced for CLI tools, SSH, and non-browser applications?

How does Smallstep ZTNA integrate with SSO, IAM, and posture systems?

Does Smallstep ZTNA support per-app, per-user, and per-device policies?

How does Smallstep ZTNA compare to VPN-based remote access?

How is traffic secured between the user/device and internal applications?

What happens if a user’s device is stolen or compromised?

Can Smallstep ZTNA operate in air-gapped, hybrid, or sovereign environments?