Skip to main content
SXGuard — Swiss Security

Enforce Least-Privilege Access

Access to one resource should never mean access to everything.

Access rule scoping a role to one destination

The Challenge

Traditional access is granted at the network level. Once a user is connected, they can often reach many systems, even when the work in front of them involves a single application, server, or service.

That surplus connectivity is not neutral. It widens what a mistake can affect, and it gives a compromised device a much larger set of systems to talk to than its owner ever needed.

The Solution

SXAccess defines permitted communication between members, devices, groups, and specific resources — down to the protocol and port.

Rather than granting network access and hoping the rest holds, connectivity exists only where an access rule creates it.

This makes least privilege something you configure, rather than something you aspire to.

Granular Access Rules

Control exactly who reaches what.

Protocol & Port Control

Limit how a resource can be reached.

Default Restriction

Connectivity exists only where permitted.

How it works

From Rule to Enforcement

  1. Define Source and Destination

    Identify the member, device, or group that needs access, and the resource they need to reach.

  2. Define Allowed Connectivity

    The access rule specifies the permitted communication, including service, protocol, and port. For example: Developer → Development server → SSH → allowed, while Developer → Production database → not allowed.

  3. Enforce the Access Rule

    SXAccess carries traffic that matches a configured access rule. Services and resources outside that access rule remain unreachable for that member or device.

Security & Business Value

Least privilege narrows the connectivity between people, devices, and the systems that matter most — which is the difference between an incident affecting one server and an incident affecting a subnet.

It also makes access reviews tractable: access rules describe roles and resources in business terms, so what someone can reach is readable without tracing IP ranges.

  • Precise Access Control
  • Protocol & Port Restrictions
  • Reduced Unnecessary Access
  • Clear Access Boundaries

Connect What Matters. Limit Everything Else.

Give members secure access to the applications, systems, and networks they need — without handing them the rest of your infrastructure.

Secure connectivity. Precise access. One private network.