ZTGuard secures both layers of your infrastructure: Application Gateway publishes web apps with Email OTP, and Private Mesh connects admins and infrastructure over encrypted WireGuard tunnels.
14-day free trial · ✓ No credit card required · Each $12 / Bundle $20/user
Browser users access internal apps with Email OTP and 30-day trusted sessions — no VPN, no client software.
Connect admins, servers, and sites over encrypted peer-to-peer WireGuard. SSH, RDP, any protocol.
Browser users access web apps via Email OTP — no VPN, no client, no open ports.
Admins reach SSH, Proxmox, RDP over encrypted WireGuard. Infrastructure hidden from internet.
Fully self-hosted. Your keys, your data. Ottawa, ON — PIPEDA compliant.
Modern Zero Trust requires two separate layers: application access for browser users, and infrastructure networking for admins. ZTGuard delivers both.
Publish any internal web app to the internet behind Email OTP. Browser users — no software to install.
Connect admins, servers, and sites in a secure WireGuard mesh. SSH, RDP, any protocol — peer-to-peer.
Browser users reach web apps through Application Gateway. Admins reach infrastructure through Private Mesh. Two independent, complementary layers.
No firewall changes. No certificate management. Install the connector, publish the site, users authenticate via Email OTP.
One Docker command on any server. Dials outbound — no inbound ports needed.
Point any domain at your internal app. Automatic HTTPS. Live in under 5 minutes.
Enter email, receive OTP code, access the app. No passwords. No apps to install.
Replace VPNs, close public SSH ports, give admins encrypted peer-to-peer access to any infrastructure from anywhere.
Install the mesh client on admin laptops and servers. One command to join the mesh.
Create groups (Admins, Infrastructure, Clients) and ACL rules. Each peer only talks to permitted peers.
Move SSH, RDP, and Proxmox behind the mesh. Block port 22 from the internet. Zero public exposure.
VPN helpdesk calls and exposed port incidents carry real dollar costs. Calculate your exact savings.
"We replaced our VPN and exposed SSH with ZTGuard. Browser apps through Gateway, admin access through Mesh. Attack surface dropped to near zero."
Individual products at $12/user/month. Bundle both and save $4/user/month.
✓ No credit card · 14-day trial
Enter your work email — most teams are live within 24 hours of signing up.
✓ No credit card · ✓ Both products in trial · ✓ Cancel anytime
How the complete ZTGuard platform compares to piecing together individual tools.
| Capability | ZTGuard Complete | Tailscale + Cloudflare | Traditional VPN | Tailscale Only |
|---|---|---|---|---|
| Web app publishing (browser users) | ✓ Gateway | ✓ CF Tunnels | ✗ No | ✗ No |
| Email OTP — no client for users | ✓ Yes | Add-on | ✗ No | ✗ No |
| 30-day trusted device sessions | ✓ Yes | ✗ No | ✗ No | ✗ No |
| WireGuard p2p infrastructure mesh | ✓ Mesh | ✓ Tailscale | Partial | ✓ Yes |
| SSH, RDP, any protocol | ✓ Yes | ✓ Yes | ✓ Yes | ✓ Yes |
| No client install for browser users | ✓ Yes | ✓ CF side | ✗ No | ✗ Requires client |
| Full self-hosted data sovereignty | ✓ Canadian | ✗ US-hosted | Varies | ✗ US-hosted |
| Single vendor, both access layers | ✓ Yes | ✗ Two vendors | ✗ No | ✗ No |
| Pricing (combined) | $20/user/mo | $7–$18/user/mo | Hardware + IT | $6+/device |
← Swipe to compare on mobile →
Both products covered.
No. Application Gateway users access protected sites through any browser — no VPN, no extension, no app. Email, OTP code, done.
The NetBird client — install once on Linux, macOS, or Windows. Servers enroll automatically via setup keys — no interactive auth needed.
Each product works independently at $12/user/month. The bundle at $20 is for teams wanting complete Zero Trust coverage. Start with one, add the other anytime.
Cloudflare handles web apps (like Gateway) but not SSH, RDP, or direct protocol access. It also requires DNS migration and routes control data through US infrastructure. ZTGuard gives both layers on Canadian infrastructure without DNS migration.
No. The default "All to All" policy is removed. Each peer only reaches peers explicitly permitted by ACL policy. A compromised device has a blast radius limited to its policy group.
After Gateway OTP, users see "Stay signed in?". If accepted, a secure cookie is stored. Subsequent visits skip OTP. Clearing cookies or new browser requires re-authentication.
Both products: access revoked immediately. No token expiry delay. Gateway: session terminated. Mesh: peer deleted — all tunnel access lost within seconds.
Yes. Each client site runs one mesh peer. All devices behind that peer become reachable through the mesh without installing the client on every device. Per-client ACL policies prevent cross-client access.
Yes. Both products run entirely on your infrastructure. Your keys never leave your servers. Canadian data centres, Ottawa, ON. PIPEDA compliant.
Gateway: protected apps temporarily unavailable. Mesh: existing WireGuard tunnels remain active — only new enrollments pause. ZTGuard targets 99.9% uptime. status.ztguard.net
Application Gateway for browser users. Private Mesh for infrastructure. Deploy together or start with one.
⚡ Setup assistance included for all trial signups this month