# XplicitTrust > Zero Trust Network Access (ZTNA) platform. End-to-end encrypted mesh tunnels peer-to-peer between devices, identity-aware access policies, continuous device posture checks, and a control plane hosted in Germany. Sold through partners; built so any IT team can run it from day one. XplicitTrust replaces legacy VPN concentrators and SASE bundles with a single product. No edge appliances, no per-site connectors, no multi-SKU stack to renew. Founders are network-security veterans from Astaro (now part of Sophos); the company is headquartered in Karlsruhe, Germany. Tunnels are end-to-end encrypted and run directly device-to-device whenever network conditions allow. Relays are deployed in the EU and around the world as fallback for NAT-traversal, but never hold session keys and never see plaintext. Identity is delegated to your existing IdP via OAuth 2.0 / OpenID Connect; XplicitTrust does not store passwords. Device posture, identity, and policy are re-evaluated continuously, not just at session start. ## Key facts - Product type: Zero Trust Network Access (ZTNA), peer-to-peer mesh overlay - Tunnel topology: end-to-end encrypted; relays are blind - Control plane: hosted in Germany, operated under European law - Identity: any standards-compliant OAuth 2.0 / OpenID Connect IdP - Clients: macOS, Windows, Linux, iOS, Android - Pricing model: per-user licensing, monthly or annual, partner-led; 30-day free trial; free non-commercial subscriptions on request - Compliance support: helps customers produce evidence for NIS-2, ISO 27001 + BSI IT-Grundschutz, CRA, GDPR, DORA - Sales motion: 100% channel; partners run the commercial relationship - Founders: network-security veterans from Astaro (now part of Sophos) - Headquarters: Karlsruhe, Germany ## Product - [Product overview](https://xplicittrust.com/en/product): admin console with policies, users, devices, posture, topology and connections views; the client experience; the cryptographic stack - [Solutions](https://xplicittrust.com/en/use-cases): replace legacy VPN concentrators and bastion hosts, adopt Zero Trust gradually with Learning Mode and microsegmentation, connect multi-site / contractor / OT / cloud workloads in one mesh - [Digital Sovereignty](https://xplicittrust.com/en/sovereignty): control plane in Germany, identity stays with your IdP, GDPR by design and in spirit, European channel, Zero Trust as defense in depth against legal-access attempts - [Security & Compliance](https://xplicittrust.com/en/security): how XplicitTrust supports your auditors (NIS-2, ISO 27001 + BSI IT-Grundschutz, CRA, GDPR + DORA) and how the product is engineered (SDL, secure CI/CD, SBOM per release, Coordinated Vulnerability Disclosure) - [Pricing](https://xplicittrust.com/en/pricing): per-user licensing, monthly or annual, partner-led; 30-day free trial; free non-commercial subscriptions on request - [Download](https://xplicittrust.com/en/download): clients for macOS, Windows, Linux, iOS, Android - [Whitepaper · Zero Trust Network Access](https://xplicittrust.com/en/whitepaper): 14-page whitepaper on modern VPN under the Zero Trust principle; legacy VPN limits, NIST SP 800-207, digital sovereignty, XplicitTrust architecture, side-by-side comparison, TCO. Form-gated download; available in English and German. ## Solutions in detail - Modernize legacy access: retire VPN concentrators that throttle traffic, give legacy ERP/CRM modern access controls, front RDP with identity-aware access and posture checks, replace site-to-site IPsec mesh with one identity-based overlay. - Adopt Zero Trust gradually: Learning Mode observes existing traffic so policies are written from real flows; identity-based microsegmentation keeps blast radius small; posture evaluation is continuous, not session-start only. - Connect anything to anything: multi-site overlay without per-site appliances, contractor and third-party access without shared VPN credentials, OT/IoT subnets reachable without flattening the network, branch and home office and cloud workloads in one mesh. ## Compare - [How XplicitTrust compares](https://xplicittrust.com/en/compare): side-by-side analysis vs. Cisco Secure Client, Fortinet FortiClient ZTNA, WatchGuard, SonicWall, Sophos ZTNA, OpenVPN, Palo Alto Networks GlobalProtect, ZeroTier, Tailscale, Cloudflare Access, Zscaler, Check Point Harmony SASE (formerly Perimeter 81), Twingate, NetBird, and JumpCloud Go. Covers identity model, where the data lives, channel motion, and operational footprint. ## Company - [About](https://xplicittrust.com/en/about): founders, mission, the Astaro lineage, Karlsruhe roots - [Partners](https://xplicittrust.com/en/partners): channel partner program, MSP enablement, on-demand and prepaid billing - [Blog / News](https://xplicittrust.com/en/blog): product news, engineering posts, compliance and sovereignty perspectives - [Imprint](https://xplicittrust.com/en/imprint) · [Privacy Notice](https://xplicittrust.com/en/privacy-notice) ## German content The full site is available in German at the same URLs under `/de/`. - [Startseite](https://xplicittrust.com/de/) - [Produkt](https://xplicittrust.com/de/product) - [Lösungen](https://xplicittrust.com/de/use-cases) - [Digitale Souveränität](https://xplicittrust.com/de/sovereignty) - [Sicherheit & Compliance](https://xplicittrust.com/de/security) - [Im Vergleich](https://xplicittrust.com/de/compare) - [Pläne & Preise](https://xplicittrust.com/de/pricing) - [Unternehmen](https://xplicittrust.com/de/about) - [Partner](https://xplicittrust.com/de/partners) - [Whitepaper](https://xplicittrust.com/de/whitepaper) ## Documentation and security - [Product documentation](https://docs.xplicittrust.com/): admin guide, deployment, troubleshooting - [security.txt](https://xplicittrust.com/.well-known/security.txt): security disclosure contact and PGP key ## Optional - [Full site content as one document](https://xplicittrust.com/llms-full.txt): every page above flattened into markdown for one-shot ingestion - [Sitemap (XML)](https://xplicittrust.com/sitemap.xml)