01 / DIODES02 / VPN03 / STACKS04 / COMMON THREAD05 / CONTACT
Why TerraZone

One platform where others
need a stack of point products.

Physical diodes, legacy VPNs, and multi-vendor stacks each solve one slice of the problem - and leave gaps between them. truePass is a single software-defined Zero Trust platform built on patented Reverse Access™, replacing that patchwork with one architecture, one policy model, and one audit trail. Here's how it compares.

01 Isolation

truePass Gravity vs. physical data diodes.

Physical diodes enforce one-way flow at the hardware level. They solve yesterday's problem - moving data in one direction across an air gap - but modern OT needs interactive, identity-aware connectivity. truePass Gravity delivers a software-defined virtual diode that preserves isolation while adding everything a diode can't do.

CapabilityPhysical data diodetruePass Gravity
Isolation principleOne-way at the wire (laser/optical)OT-initiated outbound only — software-defined
Interactive TCP (RDP/SSH/Web/API)Not supported - replication onlyFull interactive sessions under policy
Identity & access controlNone - sees direction, not usersPer-request: AD / MFA / RBAC
File transfer & content controlOne-way transfer onlySecure proxy + CDR sanitization
Audit & investigationLogs scattered across componentsUnified audit trail, single pane of glass
DeploymentHardware install, weeks–monthsSoftware, deploys in days
Zero Trust compliantNo - cannot verify identityYes — identity, policy, audit

The takeaway: A physical diode isn't Zero Trust compliant - it controls direction but never identity. Gravity keeps the isolation principle and adds interactive access, identity enforcement, and a unified audit trail, with no hardware to install. See the Replace Diodes use case →

02 Remote access

truePass Gate vs. legacy VPN.

A VPN puts a user on the network after a single authentication, leaving an inbound port exposed and a flat tunnel to ride. truePass Gate replaces that model with clientless or client-based Zero Trust access to individual applications - nothing exposed, nothing standing.

CapabilityLegacy VPNtruePass Gate
Network exposureInbound VPN port, publicly scannableNo inbound ports - outbound 443 TLS only
Access scopeFull network once connectedOne application at a time
Identity enforcementNetwork-level, at the tunnelPer-request, with MFA every session
Lateral movementFlat tunnel - easy to pivotNo lateral path from a session
Client footprintAgent required on every deviceClientless or client-based - your choice
App visibility to attackersServices discoverable behind tunnelApps invisible until identity proven
Audit trailPartial, tunnel-levelPer-user, per-session, SIEM-ready

The takeaway: A VPN grants network access; Zero Trust grants application access. Gate removes the exposed port, the flat tunnel, and the standing access a VPN depends on. See the Replace VPN use case →

03 Architecture

truePass platform vs. multi-vendor stacks.

The common alternative is assembling point products - a diode here, a VPN there, a separate PAM, a separate segmentation tool, a separate file-security gateway. Each has its own console, its own policy model, and its own logs. truePass delivers the same capabilities as one platform, activated as modules.

DimensionMulti-vendor stacktruePass platform
Vendors to manageMany - contracts, renewals, supportOne — add capability via modules
Policy modelDifferent per productOne unified Zero Trust policy
Audit & visibilityScattered logs, manual correlationSingle audit trail across modules
Integration gapsSeams between tools = attack surfaceNo seams - one architecture
Underlying technologyMixed, varying maturityAll on patented Reverse Access™
Deployment & changeCoordinate across vendorsActivate modules, no re-architecture
Total cost of ownershipStacked licensing & ops overheadConsolidated - clearer ROI

The takeaway: Every seam between products is a place for policy to drift and attackers to hide. One platform on one patented architecture removes the seams - and the overhead of managing a dozen vendors. Explore the truePass platform →

04 The common thread

One architecture. No inbound ports. No seams.

Whatever you're replacing, the same three principles set truePass apart.

Patented Reverse Access™

Outbound-only connectivity means no inbound ports and no exposed services - an architecture patented in 22 countries that competitors can't replicate.

Identity at every request

Not direction, not a subnet, not a one-time tunnel login - every session and action is verified against identity, device, and context, with a unified audit trail.

One platform, not a stack

Gravity, Gate, Grid, and Guard share one policy model and one console. Add capability by activating modules - never by adding vendors.

One platform.

Not a stack of point products.

A 30-minute conversation with our architects. We'll map what you're replacing - diodes, VPNs or a multi-vendor stack - to the right combination of truePass modules, and propose a tailored Proof of Concept.

Architecture & module mapping
Tailored Proof of Concept
Deployed in weeks, not months
Talk to an architect

I agree to receive marketing communications from TerraZone ltd by email, SMS, WhatsApp and other electronic channels, in accordance with the Privacy Policy. I may unsubscribe at any time.