Cloud Secure Edge Docs
Replace your legacy VPN, filter internet content, and control access to your SaaS applications.
Primary use cases
Replace your legacy VPN
Give remote users access to internal resources through a Service Tunnel, without the overhead of a traditional VPN.
Set up a Service Tunnel SIA Basic/AdvancedBlock internet content
Filter compliance and malicious content on managed devices, and inspect downloads before they reach the endpoint.
Configure filtering SPA AdvancedSet up ZTNA
Grant access to individually named resources rather than to a network, with every request evaluated against policy.
Set up Zero Trust accessGain visibility and control
Protect SaaS apps
Add device trust on top of your existing single sign-on, so a sanctioned app is only reachable from a device you trust.
Protect a SaaS app SIAManage shadow AI and IT
Discover the public and AI applications your users are actually reaching, then decide which to sanction, restrict, or block.
Discover applications in use SPA Basic/AdvancedMonitor device security posture
Score each device against the security standard you set, and see which devices fall short before they are granted access.
Check device postureLearn the platform
Understand how CSE works
How Cloud Secure Edge brokers access, its deployment models, and the vocabulary used throughout these docs.
Read the concepts ArchitectureExplore the platform components
The Command Center, the Edge Network, the Connector, the Access Tier, and the apps that run on user devices.
See the components APIManage CSE programmatically
Drive configuration through the REST API, the Terraform provider, and the Python library and CLI.
Open the API guideManage and monitor
Connect networks and tunnels
Publish Service Tunnels and manage the DNS, routing, and connectivity behind them.
Configure a tunnel DirectoryManage users and devices
Integrate an identity provider, enrol devices, and control which users consume a licence.
Manage your directory PoliciesConfigure access policies
Device trust scoring and the access policies that evaluate every request before it is allowed.
Configure a policy