---
description: Review of ZTXGate Software: system overview, features, price and cost information. Get free demos and compare to similar programs.
image: https://gdm-localsites-assets-gfprod.imgix.net/images/software_advice/og_logo-55146305bbe7b450bea05c18e9be9c9a.png
title: ZTXGate | Reviews, Pricing & Demos - SoftwareAdvice AU
---

Breadcrumb: [Home](/) > [Access Governance Software](/directory/4665/access-governance/software) > [ZTXGate](/software/560006/ZTXGate)

# ZTXGate

Canonical: https://www.softwareadvice.com.au/software/560006/ZTXGate

> ZTXGate is a Zero Trust Network Access (ZTNA) platform that combines the operational feel of a modern SaaS control plane with the deployment posture, data sovereignty, and blast-radius isolation of on-premises software. Every customer runs on a dedicated single-tenant instance — no shared control plane, no shared identity store, no shared audit log, no noisy-neighbor risk. A central hub coordinates fleet-wide operations across those instances — signed release rollout with staged channels, license renewal, telemetry, remote yank, and auto-rollback — but never brokers user traffic, never holds session state, and never becomes a critical path. If the hub is unreachable, every tenant keeps working. If a customer is fully disconnected, the hub is switched off and licensing continues to operate through offline-signed blobs. From the operator's chair, the experience is indistinguishable from SaaS: a fleet dashboard, per-tenant health, release channels, urgency overrides, "check now" actions, one-click yank. From the customer's chair, it is a hard tenant boundary.&#10;&#10;Identity is federated to the customer's existing stack. The admin portal authenticates users through OIDC SSO with a per-provider registry, PKCE, group-to-role mapping, and a convert-to-local break-glass path. Workforce provisioning is handled through SCIM 2.0 on a separate hardened listener with per-token bearer authentication, CIDR allow-listing, and rate limiting. Cross-protocol identifier linkage ensures an OIDC-authenticated user and a SCIM-provisioned user are recognized as the same person, eliminating the split-identity failures that undermine most ZTNA rollouts.&#10;&#10;Device posture is a first-class policy input. ZTXGate integrates natively with Microsoft Intune plus Microsoft Defender for Endpoint and with SentinelOne Singularity, behind a provider-agnostic interface that additional MDM/EDR sources plug into. Operators configure risk-to-score mapping, compliance-state gates, auto-binding on federated identities, bulk CSV binding, and an explicit unknown-posture mode (strict / permissive / stale-ok) so the fail-mode is a deliberate choice.&#10;&#10;Biometric step-up is pluggable per resource. ZTXGate ships with its own push authenticator (ZTXBAS), and integrates natively with Okta Verify Push and Duo Push through vendor APIs. Policy selects the backend per resource; API credentials are encrypted at rest.&#10;&#10;Access itself is granted just-in-time. Every session is scoped to a specific (user, device, resource) triple with configurable TTL, idle timeout, and reauthentication windows. Optional request-approve workflows gate sensitive resources on a named approver with per-approver decision windows and email notifications. Sessions revoke automatically when identity, posture, trust level, source network, or policy changes. Protected applications remain cloaked behind the gateway — nothing is reachable without a valid, policy-matched session.&#10;&#10;Underlay-based source-CIDR conditions (evaluated against the tunnel endpoint IP, not the tautological tunnel IP), named CIDR groups shared across policies, and IPv4/IPv6 endpoint support round out the policy surface.&#10;&#10;All access decisions, session lifecycle events, and administrative actions are written to an isolated audit store and forwarded to any SIEM via syslog or CEF, with in-portal filtering and CSV export.&#10;&#10;ZTXGate deploys in public cloud, private cloud, sovereign cloud, and fully disconnected environments with a single artifact and identical behavior.
> 
> Verdict: Rated \*\*\*\* by 0 users. Top-rated for **Overall Quality**.

-----

## About the vendor

- **Company**: ZTXGate

## Commercial Context

- **Starting Price**: USD 4.00
- **Pricing model**: Per User (Free Trial)
- **Pricing Details**: 30 days free trial, self-hosted only, full feature set including ZTXBAS, up to 25 users. Trial gateways install on any Debian- or Ubuntu-based VM the customer provides, via a signed .deb package (single-command install with apt install); ZTXGate issues a time-limited trial license.
- **Target Audience**: 11–50, 51–200, 201–500, 501–1,000
- **Deployment & Platforms**: Cloud, SaaS, Web-based, Linux (Desktop), Linux (On-Premise)
- **Supported Languages**: English
- **Available Countries**: Angola, Argentina, Aruba, Australia, Austria, Bahamas, Bahrain, Belgium, Bermuda, Bosnia and Herzegovina, Botswana, Brazil, Bulgaria, Canada, Cayman Islands, Chile, China, Colombia, Costa Rica, Croatia and 68 more

## Features

- Access Controls/Permissions
- Access Management
- Activity Dashboard
- Activity Tracking
- Audit Trail
- Automated Scheduling
- Biometrics
- Compliance Management
- Multi-Factor Authentication
- Network Security Software
- Policy Creation
- Policy Management
- Reporting & Statistics
- Role-Based Permissions
- Security Auditing
- Self Service Portal
- Single Sign On
- Third-Party Integrations
- User Management
- Workflow Management

## Support Options

- Email/Help Desk
- Knowledge Base
- 24/7 (Live rep)
- Chat

## Category

- [Access Governance Software](https://www.softwareadvice.com.au/directory/4665/access-governance/software)

## Related Categories

- [Access Governance Software](https://www.softwareadvice.com.au/directory/4665/access-governance/software)
- [Network Access Control (NAC) Software](https://www.softwareadvice.com.au/directory/4433/network-access-control/software)

## Links

- [View on SoftwareAdvice](https://www.softwareadvice.com.au/software/560006/ZTXGate)

## This page is available in the following languages

| Locale | URL |
| en | <https://www.softwareadvice.com/product/560006-ZTXGate/> |
| en-AU | <https://www.softwareadvice.com.au/software/560006/ZTXGate> |
| en-GB | <https://www.softwareadvice.co.uk/software/560006/ZTXGate> |
| en-IE | <https://www.softwareadvice.ie/software/560006/ZTXGate> |
| en-NZ | <https://www.softwareadvice.co.nz/software/560006/ZTXGate> |

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":"SoftwareAdvice Australia","address":{"@type":"PostalAddress","addressLocality":"Sydney","addressRegion":"NSW","postalCode":"2060","streetAddress":"Level 18 40 Mount Street North Sydney NSW 2060 Australia"},"description":"Software Advice helps businesses in Australia find the best software. Compare software options and learn more from our research and user reviews.","email":"info@softwareadvice.com.au","url":"https://www.softwareadvice.com.au/","logo":"https://dm-localsites-assets-prod.imgix.net/images/software_advice/logo-white-d2cfd05bdd863947d19a4d1b9567dde8.svg","@id":"https://www.softwareadvice.com.au/#organization","@type":"Organization","parentOrganization":"G2.com, Inc.","sameAs":[]},{"name":"ZTXGate","description":"ZTXGate is a Zero Trust Network Access (ZTNA) platform that combines the operational feel of a modern SaaS control plane with the deployment posture, data sovereignty, and blast-radius isolation of on-premises software. Every customer runs on a dedicated single-tenant instance — no shared control plane, no shared identity store, no shared audit log, no noisy-neighbor risk. A central hub coordinates fleet-wide operations across those instances — signed release rollout with staged channels, license renewal, telemetry, remote yank, and auto-rollback — but never brokers user traffic, never holds session state, and never becomes a critical path. If the hub is unreachable, every tenant keeps working. If a customer is fully disconnected, the hub is switched off and licensing continues to operate through offline-signed blobs. From the operator's chair, the experience is indistinguishable from SaaS: a fleet dashboard, per-tenant health, release channels, urgency overrides, \"check now\" actions, one-click yank. From the customer's chair, it is a hard tenant boundary.\n\nIdentity is federated to the customer's existing stack. The admin portal authenticates users through OIDC SSO with a per-provider registry, PKCE, group-to-role mapping, and a convert-to-local break-glass path. Workforce provisioning is handled through SCIM 2.0 on a separate hardened listener with per-token bearer authentication, CIDR allow-listing, and rate limiting. Cross-protocol identifier linkage ensures an OIDC-authenticated user and a SCIM-provisioned user are recognized as the same person, eliminating the split-identity failures that undermine most ZTNA rollouts.\n\nDevice posture is a first-class policy input. ZTXGate integrates natively with Microsoft Intune plus Microsoft Defender for Endpoint and with SentinelOne Singularity, behind a provider-agnostic interface that additional MDM/EDR sources plug into. Operators configure risk-to-score mapping, compliance-state gates, auto-binding on federated identities, bulk CSV binding, and an explicit unknown-posture mode (strict / permissive / stale-ok) so the fail-mode is a deliberate choice.\n\nBiometric step-up is pluggable per resource. ZTXGate ships with its own push authenticator (ZTXBAS), and integrates natively with Okta Verify Push and Duo Push through vendor APIs. Policy selects the backend per resource; API credentials are encrypted at rest.\n\nAccess itself is granted just-in-time. Every session is scoped to a specific (user, device, resource) triple with configurable TTL, idle timeout, and reauthentication windows. Optional request-approve workflows gate sensitive resources on a named approver with per-approver decision windows and email notifications. Sessions revoke automatically when identity, posture, trust level, source network, or policy changes. Protected applications remain cloaked behind the gateway — nothing is reachable without a valid, policy-matched session.\n\nUnderlay-based source-CIDR conditions (evaluated against the tunnel endpoint IP, not the tautological tunnel IP), named CIDR groups shared across policies, and IPv4/IPv6 endpoint support round out the policy surface.\n\nAll access decisions, session lifecycle events, and administrative actions are written to an isolated audit store and forwarded to any SIEM via syslog or CEF, with in-portal filtering and CSV export.\n\nZTXGate deploys in public cloud, private cloud, sovereign cloud, and fully disconnected environments with a single artifact and identical behavior.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductScreenshot/760d0324-1b86-4113-b2c9-dc693155a8f3.png","url":"https://www.softwareadvice.com.au/software/560006/ZTXGate","@id":"https://www.softwareadvice.com.au/software/560006/ZTXGate#software","@type":"SoftwareApplication","applicationCategory":"BusinessApplication","publisher":{"@id":"https://www.softwareadvice.com.au/#organization"},"offers":{"price":"4","@type":"Offer","priceCurrency":"USD"},"operatingSystem":"Cloud, Linux, Linux on premise"},{"@id":"https://www.softwareadvice.com.au/software/560006/ZTXGate#breadcrumblist","@type":"BreadcrumbList","itemListElement":[{"name":"Home","position":1,"item":"/","@type":"ListItem"},{"name":"Access Governance Software","position":2,"item":"/directory/4665/access-governance/software","@type":"ListItem"},{"name":"ZTXGate","position":3,"item":"/software/560006/ZTXGate","@type":"ListItem"}]}]}
</script>
