Managed Zero-Trust Networking for businesses
Technology: WireGuard
We run your secure corporate network – without classic VPN port forwarding and without hiring a dedicated network administrator. Access is granular; devices are managed centrally.
Why zero trust instead of a classic VPN?
Instead of “all or nothing” on the corporate LAN, users only get the access they need – traceable and quickly revocable.
Secure remote and field staff access
Access to servers, NAS and internal applications
Optional site-to-site connectivity
Fast deactivation of lost devices
What we take care of
Included in the managed service
- Operation of management infrastructure for your zero-trust network
- Monitoring, security updates and configuration backup
- Management of organisations, users, groups and devices
- Maintenance of access and network rules
- Client setup assistance and standard email support
Not included by default
- Third-party firewall administration or on-site visits
- Full network design or 24/7 on-call without agreement
- Recovery of customer data outside the managed networking service
Typical use cases
Many organisations need the same foundation: secure access on the road, clear rules on who may reach what, and less attack surface than a classic VPN. Here is how that can look in practice.
SMEs & offices
For teams with distributed workplaces that rely on file servers, line-of-business software or devices on site – without moving everything to the cloud.
- Remote and field access to files and applications on the office network
- Central management of laptops, PCs and optionally mobile devices
- Fast lock-out when devices are lost or staff leave
- Optional site-to-site when warehouse, branch or workshop needs connecting
Law firms & consulting
Client data and internal communication need controlled access – especially when working from home or on the move.
- No open RDP or remote-support ports exposed on the internet router
- Granular access to matter drives, DMS or practice software
- Separate groups for partners, trainees, admin and external providers
- Clear structure for internal IT and compliance requirements
Trades & branches
Workshop, warehouse and head office often share ERP, NAS or POS – sites should be linked without running complex VPN hardware yourself.
- ERP, inventory or time-tracking access from every branch
- Site-to-site between workshop, showroom and back office
- Secure access for field staff and fitters to project and customer data
- Less effort than classic firewall VPN setup and maintenance
Agencies & IT teams
Changing project teams, client environments and remote work are normal – access must be granted and revoked quickly.
- Onboarding new staff and freelancers in a few steps
- Separate rules per client or project where agreed in scope
- Access to internal Git, test or staging environments without public ports
- Complement or alternative to heavy site-to-site VPNs run in-house
How we get started
Analysis
Clarify requirements, sites, users and existing systems.
Setup
Configure organisation, server and access rules.
Onboarding
Roll out clients, assign groups and test.
Operations
Ongoing maintenance, monitoring and support.
Privacy & security
Security and privacy are part of day-to-day operations – not an afterthought.
Data processing agreement (Art. 28 GDPR) for regular operations
WireGuard-encrypted connections – without open VPN ports exposed to the internet
Least-privilege access with traceable permissions
No analysis of file, email or application content inside the tunnel
Operations in the EU – in German data centres or on your own servers
Hardened servers, TLS, updates and technical logging for operations & security
Tailored quote
Costs depend on server, number of active clients/devices and options (e.g. site-to-site, extended SLA). We prepare a tailored quote based on your requirements.
Contact usFrequently asked questions
What is managed zero-trust networking?
A professionally operated corporate network built on zero-trust principles: devices connect over encrypted WireGuard tunnels without classic VPN concentrators and broad port forwarding to the internet.
How is this different from a classic VPN?
Access is more granular (least privilege), users and devices are managed centrally, and you typically avoid open remote ports on the internet.
How quickly can we get started?
Once requirements, sites and devices are clear, first productive access is often possible within a few business days – depending on scope and integrations. We set out the exact timeline in your quote.
What counts as a client?
A device is a client: each active endpoint provisioned for you with network access through the service (e.g. laptop, PC or server). Exact billing rules are defined in your quote.
Is site-to-site possible?
Yes, site connectivity can be set up optionally – depending on your infrastructure and agreed scope.
Does the service replace firewall and endpoint security?
No. It secures networking and access control. Firewalls, EDR, backup and patch management remain separate parts of your security stack.
What do you need from us to get started?
A point of contact, an overview of sites and users, and which systems (servers, NAS, applications) should be reachable. Optional details on existing firewalls or routers – we cover the rest in the kick-off.
What happens if a device is lost or stolen?
The affected client can be disabled immediately in management; access is revoked without rebuilding the whole network. We provision a replacement device according to your policies.
Put your zero-trust network into operation
Talk to us about your requirements – we plan setup and ongoing operations together with you.
Book a consultationRelated articles
More background on zero trust, secure access and modern network architecture – from our blog.

