Pillar I
Pre-authentication & attack surface elimination
Deny-by-default stealth posture: unauthenticated parties see a black hole.
Ports unlock only after out-of-band pre-auth — SMS IP dispatch, messaging bots, or FIDO2 Passkey / WebAuthn — and only for that source IP.
Pillar II
Centralized control plane & session management
Time-bound access per user, concurrent session caps to stop credential sharing, and multi-device orchestration that maps identity to the right routers and firewalls.
Pillar III
Post-connection Zero Trust
Connect is stage-one verification only — no broad subnet privilege.
Users land in a role-tailored service catalog; SSO is built-in or federated to your IdP; Layer 4 mTLS covers user-to-machine and M2M paths.
Pillar IV
Integrated event & alert messaging
Real-time relays filtered by severity and role groups.
Dispatch via SMS or enterprise messaging bots so the SOC can respond inside the process it already runs.
Pillar V
Modular architecture — no rip-and-replace
Adopt Verazentrix in phases on MikroTik, Fortinet, Sophos, Cisco, pfSense, OPNsense, and other supported gear.
Start with the control plane, the ZTNA catalog, or both — without replacing the perimeter you already trust.