Processing...

 Zero Trust Advanced Managed VPN

Secure Gateway or Managed Zero Trust tiers

WireGuard

Zero Trust Advanced Managed VPN

Fully managed secure networking with modern identity, device checks, and policy-driven access.

Replace the "flat network" VPN with a service designed for least privilege: secure remote access, predictable egress IPs, and advanced policy control. We handle the design and configuration for you, including complex access scenarios, so your users get secure connectivity without the operational burden.

Zero Trust WireGuard

What you get

This service is a managed WireGuard network with an identity layer (Zitadel) and a policy layer. Instead of "connect = full network access", we design access around who the user is, what device they're on, and what they're trying to reach.

  • Fast and modern VPN transport (WireGuard) with centrally managed keys and configuration.
  • Fully managed by experts, including onboarding, policy design, routing, and complex scenario setup.
  • Identity-aware onboarding using Zitadel user accounts and controlled enrolment.
  • Managed routing points via dedicated Exit Nodes on your corporate LAN.
  • Optional zero trust controls: routes, ports, groups, policies, and posture checks.

Good for

  • Remote teams that need a trusted "office IP" for SaaS allowlists
  • SMBs replacing legacy VPN appliances
  • Compliance-driven access patterns (least privilege, auditability)

Contract

All plans

  • 12-month contract
  • Billed monthly
  • UK-based support and management

Zero Trust (in plain English)

Zero Trust means we don't assume a device is trusted just because it's "on the VPN". Every access decision is treated as a new request to be evaluated.

  • Verify explicitly: identity, device, and context before allowing access.
  • Least privilege: users only get the routes and ports they need.
  • Assume breach: segment the network to limit blast radius.

WireGuard (why it matters)

WireGuard is a modern VPN protocol known for strong cryptography, small attack surface, and excellent performance. It's a great fit for always-on remote access.

  • Fast handshakes and roaming-friendly connections
  • Simple, auditable design
  • Works well across desktop and mobile devices

Fully managed by specialists

This is not a self-service VPN kit. We design, configure, and manage the service for you, including more advanced requirements such as segmented access, policy rules, exit nodes, and hybrid cloud or on-prem routing.

  • Expert-led setup for straightforward and complex environments
  • Policies, routes, and access rules built around your real requirements
  • Reduced operational overhead for your internal IT team

Works over HTTPS-friendly paths

The platform can be deployed to use HTTPS-based connectivity, helping remote users connect securely from hotels, guest Wi-Fi, mobile networks, and other restrictive environments where traditional VPN traffic may be blocked or unreliable.

  • Useful in firewall-heavy and tightly filtered networks
  • Can improve reachability in restrictive or censored environments
  • Maintains secure corporate access in challenging real-world conditions

Key concepts

Exit Nodes

An Exit Node is a traffic routing node on your corporate LAN that handles VPN traffic between remote users and the internal resources they are allowed to reach.

This can be a single node for simpler environments, or multiple nodes deployed for load balancing, resilience, and failover.

All plans include one exit node. Additional exit nodes can be added for capacity, redundancy, failover, or to support different sites and network segments.

Routes

Routes decide which internal networks a user can reach over the VPN—for example a specific subnet containing file servers, a lab network, or a cloud VPC.

  • Per-group access to subnets (e.g. Finance vs Engineering)
  • Split tunnelling where appropriate
  • Clear separation between internal access and internet egress

Policies & Groups

Policies define what is allowed. Groups keep management simple by applying those policies to a set of users (and optionally devices).

  • Role-based access: "Support", "Developers", "Contractors"
  • Time-limited or project-limited access
  • Auditable change history (who got access to what, and when)

Micro-segmentation (Ports & Protocols)

Instead of "VPN gives you the whole network", we can allow only the specific ports needed. For example: SSH to a bastion, RDP to a jump host, or HTTPS to an internal app.

  • Reduce blast radius and lateral movement
  • Align access with compliance requirements
  • Supports safer third-party/contractor access

Posture checks

Posture checks are rules about the device's security state—used to allow, restrict, or block access. Typical checks include: OS version, disk encryption, endpoint protection, and device enrolment.

This is where zero trust becomes practical: a user can be valid, but access can still be limited if the device doesn't meet your baseline.

Common access scenarios

The same managed VPN platform can be shaped around very different access requirements, from tightly scoped application access to broader network connectivity.

Single RDP server access

A remote user can be granted access to one Windows server only, typically over RDP, without exposing the wider company network.

  • Allow access to one hostname or IP only
  • Restrict to RDP and supporting management ports
  • Suitable for admins, support staff, or contractors

Proxied intranet access

Users can reach an internal web application or intranet through a controlled route or proxy path, rather than being placed broadly onto the LAN.

  • Expose a specific internal site securely
  • Keep back-end systems hidden from general access
  • Useful for HR, portals, dashboards, and line-of-business apps

File server access

Remote users can be limited to one or more file resources, such as a single NAS share, departmental storage, or a defined set of internal file servers.

  • Scope access to specific servers or subnets
  • Works well for SMB/CIFS-based file access
  • Ideal for hybrid staff needing controlled document access

Full network or subnet access

Some roles need broader connectivity. Access can be granted to the entire company network or limited to a specific internal subnet such as a finance VLAN, lab, or cloud segment.

  • Supports traditional VPN-style network access where needed
  • Can still be segmented by user, team, or device posture
  • Useful for IT teams, power users, and migration scenarios

Internal API and microservice access

Developers, integrations, or support users can be allowed to reach specific internal APIs or microservices only, without access to unrelated hosts or ports.

  • Restrict access to named services, ports, or application paths
  • Well suited to private dashboards, back-office APIs, and service management tools
  • Helps enforce least-privilege access in modern distributed environments

Fixed Internet routing

Remote workers can have their internet-bound traffic routed so it originates from a fixed public IP, helping with SaaS allowlists, partner access controls, and consistent outbound identity.

  • Useful for staff working remotely who need a known source IP
  • Supports third-party systems that rely on IP-based allowlisting
  • Can be applied selectively to users, groups, or specific traffic flows

Pricing

GENAccess is a managed WireGuard/NetBird based VPN service. Pricing is £5 per user/month with one exit node included free. Additional exit/routing nodes are £10/month each.

Plan Users Exit Nodes SLA Description Monthly
Single 1 1 SLA3 Single user with included exit node £5.00
Pack5 5 1 SLA3 5 user pack with included exit node £24.00
Pack10 10 1 SLA4 10 user pack with included exit node £47.00
Pack20 20 1 SLA4 20 user pack with included exit node £90.00
Pack50 50 1 SLA5 50 user pack with included exit node £215.00
Pack100 100 1 SLA5 100 user pack with included exit node £400.00
ExtraExitNode 0 1 SLA3 Additional exit/routing node £10.00

All plans include one exit node at no extra cost. Additional exit nodes are £10/month. 12-month contract, billed monthly. Larger deployments, resilient multi-node designs, or complex routing requirements may require a tailored design.

Contact Us