Remote SSH · free on every tier · not gated behind enterprise · See it

Zero Trust access, two minutes to deploy.

A WireGuard-encrypted mesh with identity-based ABAC policies and continuous device posture. JIT access with approvals, and audit-ready evidence bundles. Free forever for up to 5 users.

curl -fsSL https://login.quickztna.com/install.sh | ZTNA_AUTH_KEY=tskey-auth-xxx sh

acme.zt.net · fleet rollout ● 100 connected
$ ansible all -m shell -a "curl -fsSL .../install.sh | ZTNA_AUTH_KEY=$KEY sh"
→ 100 hosts · detecting OS/arch...
→ Downloading ztna v3.3.41 (linux-amd64, darwin-arm64, windows-amd64)
→ Installing service · starting daemon · ztna up
→ WireGuard keypair generated per host
→ Tailnet IPs allocated · MagicDNS registered · ABAC policies pushed
✓ 100/100 devices online in 1m 47s — ZTNA mesh formed
 
$ ztna status
laptop-prod-01 100.64.1.7 · tag:laptop · direct
db-primary 100.64.1.12 · tag:prod-server · 4.2ms
ci-runner-03 100.64.1.18 · tag:ci · 38ms direct
eu-edge-07 100.64.1.31 · tag:edge · derp-fra1

Built on open standards · Audited WireGuard crypto · No proprietary tunnel protocol

ABAC + device posture
GDPR · DPA available
2 global DERP regions (BLR + FRA)
Dodo Payments · custom invoicing
Open-source Go client
Free SSH on every tier

The platform

One control plane. Every layer of access.

Mesh networking, identity, ZTNA policy, and access governance — unified in a single agent.

Access governance

Prove who had access, and why

Standing access is the audit finding. Engineers request time-bounded elevation, an approver signs off, and the grant auto-revokes — every step in the audit log. Run periodic access-review campaigns, roll any ACL back to a prior version in one click, and export the evidence bundle your auditor asks for.

JIT
request · approve · expire
Reviews
periodic campaigns
1-click
roll back any policy
Audited
90-day log retention
JIT grants Access reviews Policy rollback Evidence bundles
Mesh networking

WireGuard P2P with DERP fallback

Direct peer-to-peer tunnels wherever NAT allows. Two global DERP relays (Bangalore + Frankfurt) cover CGNAT and symmetric-NAT peers automatically.

JIT access

Request · approve · auto-revoke.

ABAC policies

Rules keyed on user, tag, device posture, time of day, country, protocol, and port. Evaluated per connection.

MagicDNS & subnet routes

Every device reachable at <name>.<org>.zt.net. Advertise subnet routes · exit nodes.

Remote shell

Browser-based remote shell for diagnostics, from the same agent, on every plan.

SSO + SCIM 2.0

Google, GitHub, OIDC. SCIM provisioning for Okta, Azure AD. TOTP MFA. Device-bound refresh tokens.

Private app & data access

Reach internal web apps, PostgreSQL/MySQL/Mongo, and Kubernetes through the mesh — brokered, identity-scoped, audited.

Terraform + API

57 REST endpoints. Full Terraform provider for machines, ACLs, DNS, users. GitOps your network state.

Setup

Two minutes, not two quarters.

No bastion hosts. No certificates to rotate. No firewall-change requests. No public IPs exposed. Bring your identity provider, run one command, ship.

Read quickstart
01

Issue one auth key

In the dashboard, create a reusable auth key that covers every device you want to enrol. Set an expiry, optional tags, and that's it.

ztna auth-key create --reusable
02

Pipe the installer everywhere

One command on Linux, macOS, and Windows. Works from shell, Ansible, Intune, Jamf, cloud-init. Detects OS, installs service, auto-connects.

curl ... | ZTNA_AUTH_KEY=tskey-auth-xxx sh
03

You're on the mesh

Every device joins your tailnet over a WireGuard mesh tunnel. Reachable by MagicDNS name. ABAC policies + device posture enforced on every connection.

ssh prod-db.acme.zt.net

Zero-trust access for remote workforces. Free forever for up to 5 users.

Built for the founder, the indie ops team, the YC batch, the Fortune 500 pilot. Every feature is free for up to 5 users — upgrade to Business ($10 per user /mo) only when you need more seats and machines.

Start free Compare plans
  • No credit card · no time limit
  • Self-serve SSO + SCIM
  • Free SSH on every tier

FAQ

Common questions about QuickZTNA

Short, factual answers — same content as our docs and blog, summarized.

What is QuickZTNA?
QuickZTNA is a Zero Trust Network Access platform that connects laptops, servers, and containers into a single encrypted private mesh network. Every connection is authenticated against your identity provider, authorized against ABAC policies + continuous device posture, and encrypted by WireGuard. It adds JIT access with approvals, access-review campaigns, and one-click compliance evidence bundles. Free for up to 5 users, forever — every feature included.
How is QuickZTNA different from Tailscale?
Both are mesh VPN products built on WireGuard, and Tailscale has the more mature client ecosystem. QuickZTNA's depth is in governance and threat control rather than the mesh primitive: JIT access requests with approval and auto-revoke, periodic access-review campaigns, versioned ACLs with one-click rollback, exportable SOC 2 / ISO 27001 / HIPAA evidence bundles, enforced per organization, and remote SSH included on the free tier rather than gated behind an enterprise plan.
Is QuickZTNA really free, forever?
Yes. The Free plan covers up to 5 users and up to 100 devices with no trial timer and no credit card requirement — and it includes every feature: WireGuard-encrypted mesh, MagicDNS, ABAC policies, device posture, JIT access, access reviews, compliance reports, SSO, SCIM, and remote shell. The plan never expires; upgrade to Business only when you need more seats — billing is per user, never per device, and never to unlock features.
How fast can I deploy QuickZTNA across my team?
Roughly two minutes per device for an interactive install, or seconds per device for fleet rollouts with pre-authentication keys. The install is one command (curl on Linux/macOS, PowerShell on Windows). The client auto-registers with your organization and joins the mesh. For 100 devices via Ansible, Intune, or cloud-init, end-to-end fleet rollout is typically under 2 minutes.
Does QuickZTNA work behind NAT, CGNAT, and corporate firewalls?
Yes. The client only requires outbound HTTPS (TCP/443) to *.quickztna.com — no inbound ports, no firewall changes, no port forwarding. Peer-to-peer connections use UDP NAT traversal where possible; when UDP is blocked by symmetric NAT or strict firewalls, traffic transparently falls back to an encrypted TCP-over-HTTPS relay (DERP) in our two global regions (Bangalore + Frankfurt).
What identity providers does QuickZTNA integrate with?
Any IdP that speaks OIDC: Google Workspace, Microsoft Entra (Azure AD), Okta, Authentik, plus generic OIDC for any standards-compliant provider, and direct Google and GitHub sign-in. SCIM 2.0 provisioning for proactive user lifecycle is included on every plan, as is TOTP multi-factor authentication. SAML login is currently disabled pending a security fix — use OIDC with the same providers in the meantime.
Does QuickZTNA hold a SOC 2 attestation?
Not yet — we hold no certification today, and we won't imply otherwise. We offer a GDPR-aligned DPA and sign HIPAA Business Associate Agreements on the Business plan, and the platform generates SOC 2 / ISO 27001 / HIPAA evidence bundles to support your own audit. Our SOC 2 Type II and ISO 27001 audits are in progress, targeting 2026.
Can QuickZTNA be self-hosted?
Not today — QuickZTNA is a fully managed cloud service. If self-hosting is a requirement for your organization, contact sales@quickztna.com to discuss your needs and our roadmap.