Apex Aegis Product

The next-generation white-labeled SASE for providers and operators.

Voice-driven operations, ITSM-native governance, and policy-gated autonomy — with AI Lookup scoring every request against reputation and threat intelligence before it resolves.

Voice ops ITSM governance Tenant isolation
Apex Aegis managed SASE operations interface
Platform

Built for operators, architects, and partner delivery teams

Voice-Driven Agentic AI

Operators can ask, investigate, stage, and verify common SASE workflows by voice or natural language, with low-risk actions bound to policy gates.

Governance by Design

Every material change flows through RBAC, ITSM approval, immutable audit records, and post-change verification.

Multi-Tenant, Isolated

Dedicated tenant boundaries, tenant-scoped APIs, delegated admin, and MSP-ready operating views for service-provider teams.

Endpoint SD-WAN

Per-user WiFi and cellular bonding, app-aware QoS, and secure edge controls for hybrid workforces beyond branch-only SD-WAN.

Enterprise Identity

Designed for Okta, hybrid Entra, on-prem AD, legacy line-of-sight requirements, and mixed enterprise identity estates.

Built for Service Providers

White-label ready workflows, partner economics, tenant lifecycle hooks, billing export paths, and NOC/SOC operating models.

Platform Differentiators

What no other white-label SASE delivers

Endpoint SD-WAN

Zero-hardware SD-WAN built into every endpoint. No CPE appliances, no on-site deployment — branch-grade connectivity from the device itself.

Ghost App Discovery

Real-time detection of shadow IT and unauthorised applications across the entire network. Full visibility into what users are actually running.

Agentic AI for NOC & SOC

A user reports "I can’t access the network" — the AI diagnoses, simulates remediation, and resolves autonomously. Under five minutes, zero false positives.

Complete Platform

Twelve capabilities, one license, no add-on SKUs

Every capability included end-to-end in a single white-label platform — no per-feature surcharges, no hidden infrastructure costs.

Service Provider Architecture

  • True multi-tenant isolation per operator
  • Native AD + modern IDP with DC line-of-sight
  • Full white-label branding, portal & reporting

Zero-Hardware Networking

  • Endpoint SD-WAN — no CPE appliances needed
  • Bundled cellular, WiFi, MPLS over 5G
  • Network slicing for guaranteed performance

Continuous Security Validation

  • CTEM — continuous data exposure monitoring
  • CVE posture validation — check in minutes
  • Security posture scoring & compliance dashboards

AI & Advanced Security

  • Agentic AI for NOC & SOC — autonomous remediation
  • Ghost App Discovery — full shadow IT visibility
  • Banking-grade DLP built into SASE
Technical Edge

Deeper than the market leaders go

Capabilities the market still doesn’t offer — or charges extra for.

Continuous DLP

Endpoint DLP and transit DLP working in tandem — data protected at rest on the device and in motion across the network, with no gaps.

Segregated Event Logs

Isolated logging per security layer. Each function generates its own audit trail — clean forensics, clean compliance.

Post-Quantum QUIC & TLS

Hybrid X25519 + ML-KEM negotiated live in the handshake — on both the QUIC fast path and the TLS/443 fallback, so a harvest-now-decrypt-later capture stays useless.

Legacy-Ready Device Posture

Endpoint posture checks for legacy AD and on-prem DC identity providers that do not support modern device-context signals.

AI/ML UEBA

Behavioural analytics powered by machine learning — detect insider threats, compromised accounts, and anomalous access in real time.

ATP for Private Access

Advanced Threat Protection for private application access, not just internet traffic — where competitors only cover the internet gateway.

Security Architecture

Engineered from the ground up — not bolted on

Attack Path Simulation

Visualise attack paths with and without Apex Aegis — prove posture improvement before and after deployment, demo-ready for every prospect.

Endpoint SD-WAN Optimiser

Intelligent traffic steering at the endpoint level — optimise path selection across cellular, WiFi, and MPLS with no branch hardware.

Agentic AI Remote Access

AI-driven remote diagnostics resolve issues in minutes — no TeamViewer, AnyDesk, or third-party remote-access tools required.

mTLS by Design

Mutual TLS is built into the core, with easy certificate enrolment via step-ca using JWT and DNS validation.

DNS-Layer Security

Route and filter at the DNS layer — malicious traffic is stopped before it ever reaches the network.

Cert Enrolment in Minutes

Automated mTLS certificate provisioning using step-ca, JWT tokens, and DNS challenges — enterprise PKI without the complexity.

Resilience

Engineered for the network that fights back

UDP blocked. QUIC refused. A single WAN link. On the most hostile network your users will hit, the security floor still holds — the tunnel just changes shape.

Fails over to TLS on 443

Same port, no firewall exception — and per link, so one UDP-hostile network never drops the session.

Post-quantum on the fallback

Hybrid X25519 + ML-KEM rides the TLS/443 path too — blocking QUIC never downgrades your crypto.

Security never degrades

Policy, DLP and app identification are identical on the slow path. Blocking the fast path costs speed, not control.

OS-grade TCP recovery

Selective-ACK and window scaling keep a single degraded link filling the pipe — no cliff, just good modern TCP.

Acceleration roadmap

Where mainstream SASE stops at connectivity, we keep optimizing: byte-level caching and Scalable Data Referencing — dedicated WAN-optimization that cuts repeat bytes on the wire, even on one degraded link.

How it works

Incident triage that proves the operating model

  1. 1

    L1 operator asks why a customer site is blocked for a named tenant.

  2. 2

    Apex Aegis correlates identity, policy, endpoint path, and service health.

  3. 3

    The agent identifies the root cause and checks whether other tenants show the same pattern.

  4. 4

    Low-risk remediation is staged with tenant-scoped approval and change record creation.

  5. 5

    After approval, the agent executes, verifies restoration, and closes the ticket with evidence.

Architecture

Cloud-first pilot, partner-embedded data plane when scale requires it

Management plane (Policy Decision Point (PDP))

Central SaaS Policy Decision Point where the Policy Engine sits, with policy intent, partner admin, tenant lifecycle, reporting, and API integrations.

Tenant Boundary

Tenant-scoped RBAC, data segmentation, audit trails, policy objects, and delegated customer administration.

Data Plane

Policy Enforcement Points (PEPs), starting in a cloud provider region and later extending into ECS on EC2, bare metal, or partner PoPs where tunnel mode, scale, or sovereignty requires it.

Governance Spine

Policy Administrator (PA) mTLS communication between clients, the PDP, and PEP enforcement, plus ITSM integration, approval rules, deterministic policy gates, confidence thresholds, and full action evidence.

Data Plane

Split PEP functions so the right data plane handles the right traffic

Secure Web PEP

Handles outbound web and internet inspection on ECS on EC2 behind ALBs. ECS Service Auto Scaling grows tasks, while Cluster Auto Scaling grows the infrastructure that supports the identity-aware tunnel data plane.

Private Access PEP

Handles ZTNA and private application access separately from secure web PEP inspection. Private access PEPs run on ECS Fargate behind ALBs with service autoscaling, while PrivateLink, service discovery, or direct internal routing avoids unnecessary NAT hairpin flows.

Tunnel PEP

Used when the deployment needs full VPN server behavior, WireGuard-style UDP tunneling, TUN/TAP, or kernel routing. This PEP mode belongs on ECS on EC2, bare metal, or operator PoP infrastructure.

Endpoint Edge

Runs secure edge networking and endpoint SD-WAN on the user device for WiFi and cellular bonding, local policy checks, failover, and regional breakout decisions.

Tenancy

Shared, dedicated, and endpoint edge are service choices

Shared Pool

A multi-tenant Fargate fleet, shared database, tenant-aware routing, tenant-scoped RBAC, and row-level/data-level isolation for cost-conscious customers.

Dedicated Stack

A tenant-specific stack with its own PEP fleet, database, and load-balancing boundary for regulated, isolation-first, or premium managed-service customers.

Customer Choice

Tenancy is a packaging option rather than a tier lock. A small healthcare startup can buy dedicated isolation, while a larger advertising customer can stay shared.

Enforcement Placement

Home, away, and smart provisioning for regional enforcement

Home PEP

Primary-country inspection point for headquarters, branch, data center, and local compliance needs. It is the always-on anchor for the customer service.

Away PEP

Regional Policy Enforcement Point for remote workers, secondary markets, and lower-latency inspection near the user population. Initially configured by customer or operator choice.

Smart Provisioning

Traffic-origin and latency analysis can recommend new regional PEPs when a meaningful share of customer traffic appears in a new country or region.

Bundled Endpoint

Optional laptop, virtual SIM, endpoint SD-WAN, and secure edge networking bundle makes the operator the provider of device, connectivity, and security.

Governed Autonomy

Probabilistic AI inside deterministic rules

Apex Aegis is built around a simple rule: being right and being allowed are different checks. A machine acts only where policy permits the action and confidence clears the threshold set for the tenant, asset, and action class.

Operator Experience

Zero friction, full control

Deploy in minutes, master in hours, scale without surprises.

Zero Learning Curve

Built on standard next-generation security consoles operators already know — no proprietary UI to learn, no retraining.

Minutes-to-Live Storefront

Guided onboarding with expert sales and account managers, and transparent billing from day one — no surprise charges.

Simulate Before Deployment

The analyse engine previews policy impact before go-live, and APT simulations validate the security posture pre-deployment.

Flexible PEP Locations

Choose operator-owned Policy Enforcement Points or let auto-provisioning optimise — home and away, no unnecessary PoPs.

À La Carte Subscriptions

Activate any capability at any time — no forced bundles, no lock-in packages. Subscribe only to what you need.

Partner Operations

Built for service providers

Revenue share, native integrations, and management-ready reporting out of the box — 10% revenue share, full branding rights, operator-first economics.

White-Label Rights

Full branding rights for service providers with a 10% revenue share — operator brand, operator customers, our platform behind the scenes.

Built-in ITSM

Native ITSM that integrates with ServiceNow, Jira, or any third-party ITSM in minutes — bi-directional sync from day one.

Log-to-Ticket Automation

Denied traffic triggers a change request automatically. Approve once and policy updates in minutes — no manual rule changes.

SIEM Integration (CEF)

Standard CEF-format event export to any SIEM — plug into Splunk, QRadar, Sentinel, or Elastic with zero custom parsing.

Management Reports

Pre-built executive dashboards and board-ready reports generated on demand — not after a two-week sprint.

Dedicated Partner Team

We recruit project managers, sales, and account managers on the operator’s behalf — a fully staffed GTM team embedded in their operation.

Commercial Access

Infrastructure sizing and wholesale economics are restricted

The public product story stays focused on architecture and operating value. Detailed seat bands, AWS sizing, PEP licensing, and competitor pricing references require an approved access password.

Restricted Commercial Detail

Password required to view pricing, sizing, and margin assumptions.

This section contains wholesale rates, infrastructure cost bands, operator retail assumptions, and competitive pricing references. Share it only with approved service delivery partners, operators, and diligence teams.

Need access? Request commercial access.

Security & Compliance

Built to survive telco diligence

Apex Aegis is designed for conservative operating environments where auditability, tenant isolation, and clear ownership matter as much as feature depth.

Probabilistic AI constrained by deterministic policy rules and asset-level confidence thresholds Agent permissions inherit the caller scope and never bypass tenant RBAC Every prompt, source, recommendation, approval, execution, and verification is logged Policy changes default to recommendation and approval unless explicitly classified as low-risk and reversible SOC 2 Type II readiness roadmap and IMDA-aligned cloud resilience/security path Source-code escrow option for strategic white-label partners
Technical FAQ

Diligence answers for PDP and PEP architecture

What is the honest Fargate boundary?

Fargate is the right fit for the Management plane (Policy Decision Point (PDP)) and private access Policy Enforcement Points (PEPs) behind ALBs with service autoscaling. The secure web PEP runs on ECS on EC2 because the identity-aware tunnel performs traffic inspection and needs more control over the data plane than Fargate should carry.

How do you reduce NAT and port exhaustion risk at mid-market scale?

Split the paths. The Management plane (Policy Decision Point (PDP)) hosts the Policy Engine (PE), and the Policy Administrator (PA) coordinates mTLS communication between the client, PDP, and Policy Enforcement Points (PEPs). Private access PEPs run on ECS Fargate behind ALBs with service autoscaling. The secure web PEP runs on ECS on EC2 behind ALBs, with ECS Service Auto Scaling at the task level and Cluster Auto Scaling at the infrastructure level. That lets inspection capacity grow independently from private access and management, reducing NAT, TCP port exhaustion, and hairpin pressure.

Can one Fargate task handle both internet and private access enforcement?

It can, with separate listener ports and shared policy services, but the recommended scale architecture splits secure web and private access PEPs. Split PEPs let operators scale, debug, and isolate each traffic path independently.

How is UDP private access positioned?

UDP support is workload-dependent in the TCP-optimized cloud PEP. For truly private UDP access, Apex Aegis should use an encrypted tunnel design and a data plane that supports the required packet-handling mode.

How are license gates enforced?

The tenant license token should include tier, feature list, PEP entitlement, expiry, and tenant identity. APIs verify the license before gated actions such as advanced DLP, CASB, Away PEP activation, or agentic operations.

Early Access

Bring Apex Aegis into your service delivery partner evaluation.

We will align on the use case, tenant model, identity posture, ITSM flow, pilot scope, and success criteria before any production commitment.