EVX: The zero-trust appliance
Our multi-service access node delivering zero-touch access to the evolving ZERO NaaS platform.
More than just a next-generation gateway, its the trust enforcement point for your business.

Open source. Hardened.
The EVX is a composable, secure edge node that converges networking, security, and zero-trust services into a single modular platform.
Built on a hardened Debian linux install, we leverage trusted, auditable open source tools to build and secure our endpoints and create a flexible platform for multiple, composable services.

Zero-trust everywhere

SDWAN Secure Access Fabric
Two flavours of WAN connectivity
The EVX delivers two distinct SDWAN models, depending on where you are in your zero-trust journey.
Physical / Virtual
Secure SDWAN
Our traditional SDWAN architecture. Built to provide secure, resilient connectivity between customer sites and cloud applications.
It combines bandwith aggregation, bidirectional QoS, and multi-link failover with strong encryption at the edge.
Secure SDWAN is ideal for organisations that need full network reachability across sites, with consistent performance and layered security.
ZERO SDWAN
A new SDWAN model based on our Zero Surface Architecture.
With ZERO SDWAN, there is no routable network by default, zero exposed ports, and zero lateral movement – by design.
Access to services is granted on a per-user, per-device, and per-session basis.
ZERO SDWAN is suited to organisations adopting a full zero-trust posture, where the goal is to eliminate implicit trust, not just encrypt it.
Zero Trust Firewall
Default deny. ZTNA-ready.
This lightweight perimeter firewall delivers essential protection with simplicity. Built on Linux and open source tools, it integrates easily and provides first-line defence for any business.
Designed to complement ZTNA and endpoint security, it offers low-cost, managed network security that fits into modern zero-trust architectures.
Universal ZTNA Gateway
Cafe style network access
Most ZTNA solutions force traffic through a centralised cloud before reaching your apps – adding latency, complexity, and cost. The EVX takes a different approach.
As a Universal ZTNA Gateway, it enforces identity-based access at the edge, creating direct, ephemeral tunnels from users to internal or cloud-hosted apps. No detours, no exposed surfaces.

Network segmentation
VRF, VLAN & microsegmentation
The EVX supports all forms of network segmentation, from traditional VLAN separation through to full device level microsegments.
Zero lateral movement
Zero default policy
Zero device to device access
VLAN + VRF
Logical segmentation using VLANs, subnets, and zone-based policies.
Ideal for environments where internal systems need persistent reachability, with access controlled by Zero Trust Firewall policy enforcement.
Integrates with both Layer 2 and Layer 3 network topologies.
Zero Trust Network Segmentation
A modern alternative where no internal network is implicitly trusted.
Every connection is isolated by default, with access granted per identity, per device, per session.
EVX eliminates lateral movement and minimises blast radius.
Ideal for high-security environments and aligns with zero-trust principles end to end.
Advanced Routing + Forwarding
Full featured multi-path router
The EVX is more than an edge security and access device – it’s a full-featured router built for complex, multi-path environments.
With support for BGP, OSPF, static routes, and policy-based routing, the EVX integrates cleanly into existing topologies and dynamically adapts to network changes.
Whether you need tight control at the WAN edge or flexible routing between segments, the EVX gives you granular, programmable forwarding without losing sight of zero-trust principles.
