ZTNA market 2025
$1.34B
Global ZTNA market size in 2025.
Managed ZTNA · Infrastructure as a Service
PISTIS delivers ZTARC as infrastructure-as-a-service ZTNA — securing SSH, web apps and jump-host access without exposing anything to the public internet.
Provided by Pistis Digital Indonesia
Behind a legacy VPN
$ nmap -Pn vpn.acme-legacy.net
Host is up (0.021s latency).
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
Anyone on the internet can reach these.
3 open ports · discoverable
Behind ZTARC
$ nmap -Pn app.acme.internal
Host seems down. No response.
PORT STATE SERVICE
(all 65535 ports filtered)
The same app — reachable, but not findable.
0 open ports · no response
Both hosts serve the same internal app. Only one of them can be found.
Context
Remote work, SaaS and multi-cloud dissolved the corporate LAN. The old “trust inside, block outside” model no longer maps to how work happens.
ZTNA market 2025
$1.34B
Global ZTNA market size in 2025.
Forecast 2030
$4.18B
Projected ZTNA market by 2030.
CAGR 2025 → 2030
25.5%
Compound annual growth — one of the fastest-growing security segments.
Source — MarketsandMarkets, ZTNA Market Report (Jul 2026)
The problem
Symptom 1
Any public IP and port is discoverable in minutes by mass scanners.
Symptom 2
A VPN grants network-level trust — one compromised laptop pivots freely.
Symptom 3
DMZ firewall rules, certificate rotation and bastion access reviews consume weeks per year.
Exposure
3.9M
SSH endpoints publicly reachable on port 22 across the IPv4 space.
Time
<5min
Median time from an IP going live to the first automated scan hitting it.
Breach cost
$4.45M
Average total cost of a data breach globally.
Attack vector
#1
Compromised VPN and remote-access services top the initial-access charts year after year.
The uncomfortable truth
You cannot patch fast enough. You cannot rotate keys fast enough.
The only winning move is to stop being discoverable.
Sources — IBM Cost of a Data Breach 2024 · Shodan internet survey · Verizon DBIR 2024
Our solution
Zero Trust Network Access, run for you. You keep your apps and servers exactly where they are — we take the ports off the internet.
What we do
Every connection is authorised per user and per device, and only to the one service it needs.
Every session is re-evaluated as it runs, so trust is re-earned rather than assumed.
Encrypted tunnels that default to direct peer-to-peer routing for speed.
How it is delivered
No hardware to buy or rack, which removes the physical attack surface with it.
Live in minutes instead of months, so the rollout does not stall the roadmap.
Distributed points of presence backed by a 99.99% uptime SLA.
Architecture
Users and servers both dial out to the ZTARC hub + controller. The hub decides. The spoke opens a path to one service — and never a port to the world.
Clientless browser access and the ZTARC client both connect outbound to the ZTARC hub + controller, which authenticates and continuously authorises each request under least-privilege policy. The ZTARC spoke inside the private network dials out to that hub as well — it never accepts an inbound connection — and it fronts the web server and the local AI server. No inbound ports are exposed.
Policy engine
Every request carries
A cryptographic key tied to a user or workload.
Time, geography and risk score, evaluated per session.
The one question asked
May this identity reach this service, under these conditions, right now?
deny · by · default
One service at a time
Core principle
Access is granted to a specific service, not to the underlying network. Compromising one workload does not imply access to any other.
Comparison
| Capability | ZTARC (ZTNA) | Legacy VPN |
|---|---|---|
| Least-privilege access | Yes | No |
| Continuous authentication | Yes | No |
| Deployment complexity | Easy | Hard |
| Scalability | Unlimited | Limited |
| Access visibility | Full audit log | Limited |
Use cases
Use case 01
Access flow
Network topology
What you get
Use case 02
Access flow
Network topology
sysadmin@laptop:~$ ssh [email protected]
Connecting to 10.100.0.5 via secure mesh…
tunnel active · policy verified
Welcome to prod-server-01 (Ubuntu 24.04 LTS)
What you get
Deployment
Integrate your identity provider in minutes.
Register your application and infrastructure resources.
Apply Zero Trust policy across all users, devices and spoke.
Continuous visibility and reporting.
Positioning
Protect everything. Trust nothing.
Book a 30-minute technical walkthrough. Bring one SSH server or one internal web app — we will have it reachable, without inbound ports, before the call ends.