Security & Continuity
Firewall & Network Security
Managed next-generation firewall for each site, hardware included, with intrusion prevention, web filtering and segmentation.
Up to 10% off multi-year terms
Key specifications
Illustrations are for reference. Service scope is defined by the plan you choose.
Save 5% with a 2-year term or 10% with a 3-year term.
Managed WireGuard-based VPN for remote staff and branch offices, with single sign-on, MFA and access rules per team.
Business VPN connects remote employees and branch offices to your internal systems without exposing those systems to the internet. It is built on WireGuard, a modern VPN protocol with a small code base and fast connection setup, and integrated with your identity provider so access follows your user directory.
We deploy and operate the gateways, package client apps for company devices, and define who can reach which systems: finance users reach the accounting server, developers reach staging, contractors reach only what they need. When an employee leaves, disabling their directory account revokes VPN access.
All prices in USD, per organization per year at the 1-year rate. Swipe the table sideways to see every plan.
| Feature | Business | Professional Recommended | Enterprise |
|---|---|---|---|
| Price | $7,000.00 / year per organization | $13,500.00 / year per organization | $27,000.00 / year per organization |
| With a 3-year term | $6,300.00 / year Save 10% | $12,150.00 / year Save 10% | $24,300.00 / year Save 10% |
| Best for | For small teams working remotely. | For hybrid companies with several offices and access rules per team. | For larger organizations needing redundancy and audit-ready logging. |
| What’s included |
|
|
|
| Order | Customize term & quantity for the Business plan | Customize term & quantity for the Professional plan | Customize term & quantity for the Enterprise plan |
| SKU | TS-SEC-501 |
|---|---|
| Category | Security & Continuity |
| Pricing | Per organization, per year |
| Contract | Annual subscription; 1-, 2- or 3-year term |
| Users | 50 / 150 / 500 depending on tier |
| Protocol | WireGuard for users; WireGuard or IPsec for site-to-site |
| Identity | SAML/OIDC single sign-on with MFA |
| Site-to-site tunnels | 1 / 5 / 20 depending on tier |
| Clients | Windows, macOS, Linux, iOS and Android |
| Logging | Connection logs kept 30 to 365 days |
| Lead time | Deployed in 5 business days |
By default, only traffic to your private systems goes through the VPN (split tunneling), which keeps video calls and web browsing fast. Full-tunnel mode is available if your security policy requires it.
In most cases, yes. We build site-to-site tunnels to common business firewalls and to AWS, Azure or Google Cloud networks using WireGuard or IPsec.
Access is tied to your identity provider. Disabling the user in your directory blocks new VPN sessions, and we can terminate any active session immediately on request.
Have another question? Ask a solutions architect