Voice went home without going through a VPN.
A global business-process firm moved voice, intranet and back-office applications out to a remote workforce from the browser, with the call quality intact.

Where they started.

The customer is one of the largest business-process outsourcing and IT management firms in the world. It runs accounting, HR and customer-interaction work for multinational clients from sites in several countries.
Most of that work is a phone call. When the workforce went remote, the voice application had to go with it, along with file sharing, the intranet and SAP. A large part of that workforce sits on the client side, where installing software on every desk was not on the table.
Voice is also the least forgiving workload to put behind a security product. A tunnel that backhauls a call through a concentrator adds delay the customer on the other end can hear, so the requirement was written as zero-latency voice, not as encrypted voice.
What was in the way.
- Clientless loginA large share of the workforce sits on the client side, so access could not depend on getting software installed on every machine.
- Scattered accessVoice and the other applications, SAP included, had to be reachable and governed from one place rather than one tool each.
- The whole deskFile sharing and the intranet had to travel with the voice application, not be left behind in the office.
- LatencyVoice traffic could not take a detour through a concentrator; delay on a call is audible to the customer.
What was put in place.
Each control below has its own page. If a row makes a claim, the link is where you check it.
- Browser firstAgents sign in from a browser, so a new site or a new cohort is onboarded without shipping software to every desk.More
- Voice publishedThe voice application is published like any other, over an encrypted session that runs device to application rather than through a hub.More
- One consoleVoice, intranet, file sharing and SAP are granted from a single policy console, with an activity log covering all of them.More
- Posture checksA device is examined before it joins a session, so an agent's machine is assessed at login rather than after an incident.More
- Place and hourRemote logins are bound to a geography, a device and a window of the day, which is how a shift roster becomes an access policy.More

What a contact centre getswhen the tunnel disappears
Three consequences of publishing the call instead of routing it. The first is that the business kept running.
Continuity, quickly
New cohorts and new geographies came online as a configuration change, not a hardware order.
Access and identity together
Authentication and application access arrived as one system instead of two products meeting in the middle.
Reach that stops
An agent's session ends at the application it was granted; there is no network behind it to wander into.
“We’ve developed a sustaining relationship with InstaSafe because of the simplicity and effectiveness of their offerings. Their solutions have seamlessly integrated with our infrastructure, and have done very well to secure our networks. Their solutions are easy to setup, easy to scale, and often extremely easy to use, especially for a large part of our remote workforce, many of whom are not acquainted with unnecessary complexities of VPNs”
Seven more stories, filtered by sector and by the problem they started with.
All customer stories//Ready when you are//
Put your voice stack behind a check.
Bring your own latency budget. We will walk through where the session actually goes and what it costs you in milliseconds.
Regulated, air-gapped, or on-premise? See deployment options