Zero Trust Network
Access (ZTNA)
Zero Trust Network Access (ZTNA) to your private applications, granted per application on identity and context rather than by opening up the network, and operated as a managed service. Part of the Cloud Gateway Secure Access family.
What is Secure Private Access?
Secure Private Access (SPA) is Cloud Gateway’s managed Zero Trust Network Access (ZTNA) solution: controlled access to approved private applications, granted on the basis of identity, context and policy rather than by placing the user on the network. A user reaches the specific applications they’re authorised to use, and nothing more.
It’s the modern alternative to extending the network to every remote user. Where a traditional VPN connects a device into the network and trusts it once it’s on, ZTNA grants access application by application, checked against identity and context on each connection, so a single compromised device can’t roam the wider network.
SPA is one of two access patterns in Cloud Gateway’s Secure Access family. SPA secures the way users reach your private applications; Secure Internet Access (our Secure Web gateway offering) secures the way they reach the internet and SaaS. They share one service model and one operating approach, and can be taken together or separately.
Cloud Gateway designs the access policy with you, integrates the platform with your identity and applications, and operates it: handling incidents, changes, configuration and vendor coordination, so your team doesn’t run the platform day to day.
This is distinct from Business Everywhere: Remote Access, which provides network-level VPN transport for cases that still need it. SPA is the per-application, zero-trust model; the two can run alongside each other during a transition. For an explanation of ZTNA as a technology, see our guide to ZTNA.
Benefits of Secure Private Access
Users reach the specific private applications they’re authorised to use, rather than being placed on the network with broad reach. A compromised device can’t move laterally to everything else.
Access is granted on identity and context each time, rather than trusting a device because it once connected, the core of the zero-trust model.
Cloud Gateway designs the policy, integrates the platform and operates it: incidents, changes, configuration and vendor coordination handled as a service.
Move private-application access to a zero-trust model over time, running SPA alongside existing Remote Access during the transition rather than switching everything at once.
Take SPA alongside Secure Internet Access under one service model and one operating approach.
Designed, integrated and operated by Cloud Gateway, with vendor support coordinated on your behalf.
What's included
Cloud Gateway delivers Secure Private Access as a managed service: we agree the technical design and access policy baseline during onboarding, integrate the platform with your identity provider and the applications in scope, and operate it against an agreed support model.
Standard service activity includes onboarding and activation; incident management for the in-scope service; service request handling within an agreed catalogue; change enablement through a governed change process; configuration management of the managed service; review of vendor advisories where they materially affect the service; operational monitoring of service availability and health; and a standard operational report at an agreed cadence.
Standard is the operational baseline of the Secure Access family. It is a managed access service, not a SOC, SIEM or managed detection and response service. Advanced governance, custom reporting and customer self-service or co-management are higher-tier options.
Our case studies
Organisations
we’ve helped
Common questions about Secure Private Access
What is Zero Trust Network Access (ZTNA)?
ZTNA is a model for granting access to specific applications based on identity, context and policy, rather than placing a user on the network and trusting the device. Access is verified on every connection. Cloud Gateway’s Secure Private Access is a managed ZTNA service.
How is ZTNA different from a VPN?
A VPN connects a device into the network and grants broad access once connected. SPA grants access to specific applications only, verified on identity and context each time, so a compromised device can’t reach the wider network. SPA reduces the attack surface and provides clearer access records than a traditional VPN.
What's the difference between Secure Private Access and Business Everywhere: Remote Access?
Secure Private Access is the zero-trust, per-application model. Business Everywhere: Remote Access is network-level VPN transport, for traditional needs and for applications that can’t yet move to identity-aware access. Many organisations run both and migrate applications to SPA over time.
Do I have to replace my VPN to use ZTNA?
No. ZTNA solutions can run alongside an existing VPN, with applications moved to zero-trust access over time. Some legacy applications may continue to need VPN-style access, which Business Everywhere: Remote Access provides.
Is ZTNA a security monitoring or SOC service?
No. Our solution is a managed access service. The Standard service provides operational monitoring of service health, not continuous security alert triage, SOC monitoring or managed detection and response.
What's the difference between Secure Private Access and Secure Internet Access?
Secure Private Access secures access to your private applications; Secure Internet Access secures access to the internet and SaaS. Both are part of the Secure Access family and share one service model. For how security fits across the wider platform, see Protect.
Related reading
Most customers who take SPA extend the platform over time: Secure Internet Access for internet and SaaS control, Managed Firewall for boundary and site security, all under one operating model.
Give users the applications they need,
not the run of the network
Legacy VPN trusts the device and opens the network. Cloud Gateway delivers zero-trust access application by application, designs the policy with you and operates it as a service, so access is verified every time and your team isn’t running another platform. One platform, one UK team, one point of accountability.