Skip to main content
SXGuard — Swiss Security
...
SXAccess Solutions Overview

Secure Access For A Distributed Business

One encrypted private network across your members, devices, offices, and cloud infrastructure — with device requirements and central control over who reaches what.

Book a Demo
What SXAccess delivers

Five Things You Get On Day One

Each one is a capability the platform provides out of the box, not a module to buy separately.

  1. 01

    Secure Private Access

    Authorized members and devices reach private business resources from wherever they are working. Rather than publishing internal services to the internet or admitting people to an entire network, you decide which resources each person is permitted to reach.

  2. 02

    Device Requirements

    Access can depend on more than a credential. Five device requirements — Operating System, Process, SXAccess Client Version, Country & Region, and Device Network Range — can be switched on per access rule, and are re-evaluated while the session is open rather than tested once at sign-in.

  3. 03

    Least Privilege by Design

    Access is granted only where it is required. Administrators control connectivity between members, devices, groups, networks, services, protocols, and ports — which narrows unnecessary network access and creates clear boundaries between people and protected resources.

  4. 04

    Encrypted Connectivity

    Communication between authorized devices and infrastructure travels over encrypted private connections. Members reach internal systems across remote, office, cloud, and hybrid environments while those resources stay private.

  5. 05

    Flexible Network Connectivity

    Connectivity extends beyond individual devices. Through controlled routing, you provide authorized access to private subnets, office networks, cloud environments, internal servers, and other private resources that cannot join the overlay themselves.

Core Access Capabilities

Thirteen capabilities, grouped by the question each one answers.

Who Is Allowed In?

Secure Authentication

Nothing Joins Unauthenticated

Members and devices authenticate before they can participate in the private network. Authentication establishes membership; the access rules then determine what that membership can reach.

Fingerprint reader embedded in a circuit board

Member & Device Access

Control Who Can Connect

SXAccess centrally manages the members and devices participating in the private environment. Administrators manage authorized members, connected devices, groups, and access rules from one console rather than from individual network appliances.

Support engineer working across two screens in an open office

Group-Based Management

Organize Access at Scale

An access rule is written once against a group instead of separately for every member or machine. As people and devices change, group membership is updated while the existing access rules keep working unchanged.

  • Engineering Members
  • Finance Members
  • Remote Employees
  • Contractors
  • Development Servers
  • Production Resources
Networked figures grouped around a single highlighted member

What Are They Allowed To Reach?

Access Rules

Define Who Can Access What

Administrators control communication between members, devices, groups, and protected resources. Only the connectivity permitted by an applicable access rule is allowed. Everything else is not reachable.

  • Member or member group
  • Device or device group
  • Destination resource
  • Network
  • Protocol
  • Port

Device Requirements

Make Access Conditional on the Device and the Connection

Each check is attached per access rule rather than applied network-wide, so contractor and production access can be strict without imposing the same requirements on everything else. Checks are re-evaluated while the session is open, so a device that falls out of compliance loses the access it no longer qualifies for.

  • Operating System
  • Process
  • SXAccess Client Version
  • Country & Region
  • Device Network Range

How Does The Connection Behave?

On-Demand Connection Rules

The Connection Comes Up When It Is Needed

Connection behaviour is defined per network type, with separate rules for Wi-Fi and cellular. A Wi-Fi rule can name the networks it applies to, or the networks to leave alone — so a trusted office network can be excluded while every other network connects automatically.

Phone showing a Wi-Fi connection indicator

Automatic Reconnection

Moving Networks Without Losing the Session

When the network path changes — Wi-Fi to cellular, one network to another, a link dropping and returning — SXAccess re-establishes connectivity without tearing down the session. Members move between networks without having to reconnect by hand.

Network paths converging and branching across a dark field

Diagnostics

Something to Send When Something Goes Wrong

A diagnostic bundle can be generated from the client in a few steps, with sensitive values removed and an upload reference to pass to whoever is helping. Teams without a dedicated helpdesk get something useful to send their IT provider.

Two people reviewing a connectivity report on a tablet

How Far Does The Network Reach?

Private Network Connectivity

Secure Communication Across Devices

SXAccess establishes encrypted private connectivity between authorized endpoints, so employees and systems communicate securely across different networks and locations.

  • Internal applications
  • Development servers
  • Production servers
  • Administrative systems
  • Business services
  • Private infrastructure

Routes

Reach Resources Beyond Individual Devices

Not every resource can run an agent. Routes allow authorized members and devices to reach resources inside private networks through an authorized Routing Device. Routed resources remain governed by the same access rules as directly connected devices — reachability and permission stay separate decisions.

  • Office subnets and branch networks
  • Cloud networks and private cloud environments
  • Private servers
  • Databases
  • Internal applications
  • Legacy systems
  • Other private services

Distributed Infrastructure Connectivity

Connect Members, Offices and Cloud Environments

Because the overlay treats every member the same way, the connection patterns a distributed business needs are all the same mechanism. Distributed infrastructure connects while permitted communication stays centrally controlled.

  • Remote member → Office network
  • Remote member → Cloud resource
  • Office → Office
  • Office → Cloud
  • Cloud → Private network
  • Network → Network

How Do You Run It?

Central Management

Manage Access as Your Business Changes

Administrators adapt access as members, devices, applications, and infrastructure change, without redesigning connectivity each time. SXAccess provides one place to administer:

  • Members
  • Devices
  • Groups
  • Access rules
  • Device and connection conditions
  • Networks
  • Routes
  • Connectivity configuration
Administrator reviewing a management dashboard on a desktop screen

Activity Logs

Understand What Happened

Important activity and administrative changes are recorded in a centralized Activity Log. Administrators review recorded activity to understand what happened, when it happened, and which actions were associated with a change — operational visibility for review and troubleshooting.

Team reading through recorded activity on a tablet and printed reports

Core Use Cases

Each of the following has a dedicated scenario — the challenge, the approach, and how it works in practice.

Employee reaching private applications through SXAccess
Use Case 1

Secure Employee Access

Employees need private applications, servers, and internal systems from wherever they work. SXAccess gives them authenticated, encrypted access to their authorized resources — and only those — instead of admitting them to the corporate network.

Read more detail about Secure Employee Access
Access rule scoping a role to one destination
Use Case 3

Enforce Least-Privilege Access

Needing one resource should never mean reaching all of them. Access rules restrict access by destination, protocol, and port, so each role gets exactly the connectivity its work requires.

Read more detail about Enforce Least-Privilege Access
Administrator reviewing the SXAccess Activity Log
Use Case 4

Review System Activity

Administrators need to know what changed and when. The centralized Activity Log records member, device, connection, access rule, and configuration activity in one place.

Read more detail about Review System Activity
Device requirement check restricting access by location
Use Case 5

Restrict Access By Device And Location

A trusted member on an unsupported machine, or connecting from somewhere unexpected, is still a risk. Device requirements make access conditional on the device and the connection and keep re-evaluating while the session is open.

Read more detail about Restrict Access By Device And Location
New infrastructure joining the existing private network
Use Case 6

Adapt To Infrastructure Changes

People, devices, servers, and networks change constantly. Groups, routes, and access rules are updated centrally so new infrastructure joins the private network that already exists.

Read more detail about Adapt To Infrastructure Changes

Connect What Matters. Limit Everything Else.

Give members secure access to the applications, systems, and networks they need — without handing them the rest of your infrastructure.

Secure connectivity. Precise access. One private network.