NEWZTNA · Zero Touch Provisioning

Stop trusting
the network.
Trust the request.

FireTun verifies who connects, what device they use, and under what conditions — continuously, not just at login. Built on WireGuard. Multi-tenant by default.

Built on
No implicit trustPer-tenant isolationGDPR · Law 21.719WireGuard encryption
How it works

Four gates between a user and the resource.

A connection that succeeds passes every gate. A connection that fails never reaches the network.

01 · Provisioning

A new device is provisioned in seconds.

Your IdP sends a one-time invite link. The agent installs, authenticates, and registers the device fingerprint — no shared keys, no manual configs, no installation manual. Offboarding is just as automatic.

seconds
invite to connected
0
shared keys
live
directory sync
IDENTITY PROVIDERMicrosoft EntraNEW DEVICEConnecting…AUTHPOSTUREKEYSCONNECTED12s · zero clicks
What is ZTNA

Zero Trust Network Access.

Traditional VPNs grant full network access once you log in. ZTNA flips it: every connection is authorized on its own and re-evaluated continuously, against current identity, device, and context. If anything is off, it is denied.

01

Continuous identity verification

Every connection is evaluated against the user’s current state in your IdP and the device’s current state, and re-checked continuously.

02

Device posture

Up-to-date OS, active EDR, encrypted disk, no disallowed tools. Out of spec → quarantine.

03

Per-resource microsegmentation

Users only see what they are entitled to. No flat network. No lateral movement.

04

Full audit trail

Every connection, attempt, and policy change recorded. Traceability for GDPR and Chile’s Law 21.719.

What is RZTP

Zero Touch Provisioning

RZTP makes sure users and devices reach FireTun with verified identity from minute one. Nothing is configured by hand. Nothing is shared by email. Everything flows from your directory.

R1

Zero-click provisioning

A new teammate gets a link, installs the agent, and is connected in seconds with their corporate identity.

R2

Directory integration

Users and groups stream from your IdP. Role changes and offboardings propagate within minutes.

R3

Live device inventory

Every device registered with fingerprint, OS, and posture state. Real-time visibility, instant revocation.

firetun · agent● connected
Invite link clicked
0:00
Auth → Microsoft Entra
0:03
Device fingerprint registered
0:06
Posture verified · OS checks passed
0:09
Tunnel keys provisioned
0:11
Connected · 14 resources available
0:12
Everything to operate

Visual design, granular policy, modern crypto.

Visual topology canvas

Design your network as a map. Drag users, resources, policies. The wire-level config is generated automatically.

Modern end-to-end encryption

WireGuard with per-device keys that rotate automatically for the tunnel, and isolated per-tenant data keys in Vault. On direct (P2P) connections traffic flows peer-to-peer — we get telemetry, never its content.

Granular group-based access

Every policy can restrict protocol, port, schedule, country, and device posture. Group-driven, not user-driven.

vs. Traditional VPN

A VPN trusts the perimeter. FireTun trusts no one.

Legacy

Traditional VPN

Authentication
Once at login
Network model
Flat — full LAN access
Device check
None or one-time
Lateral movement
Possible
Provisioning
Manual configs, shared keys
Audit
Connection logs
FireTun

ZTNA + RZTP

Authentication
Per connection + continuous re-checks
Network model
Microsegmented per resource
Device check
Continuous posture evaluation
Lateral movement
Blocked by design — no flat network
Provisioning
Zero-touch from your IdP
Audit
Per-connection decisions, full trace
Use cases

Who runs on FireTun.

Sector 01

Banking & FinTech

Enforce posture and country policy per connection, re-checked continuously. Access control, posture and auditable traceability aligned with CMF’s RAN 20-10 and NCG 454.

Sector 02

Healthcare

Segment EHR systems per role. Quarantine non-compliant devices before they reach patient data.

Sector 03

Industrial & OT

Reach PLCs and HMIs over signed tunnels with device-level identity. No flat IT/OT bridge.

Sector 04

Small & growing teams

Enterprise-grade access security without a dedicated IT team. Configure it visually, connect it to your directory, and it scales with you as your team grows.

Compliance

GDPR-ready. Aligned with Chile’s Law 21.719.

Every access decision is recorded with who, what, when, where, and on which device. Logs are tenant-scoped, exportable, and immutable.

Per-tenant data isolationEncrypted at restRegion-pinned storageTelemetry only — never your trafficRight-to-export & eraseImmutable audit logsWireGuard ChaCha20-Poly1305
GDPR
EU 2016/679
Lawful basis · DPA · DPIA
Ley 21.719
Chile · in force 2026
Data subject rights
Per-tenant data keys
Vault Transit
Isolated data-encryption keys per tenant
Audit trail
Per-connection
Every access decision logged

Replace your VPN this quarter.

Free for small teams. Dedicated tenant when you need more. No long contracts.

FAQ

Questions we get a lot.