Partner program

The access refresh is a channel cycle. Take it.

Every VPN in a regulated Indian account now sits against a compliance calendar that ends 13 May 2027. Four partner tracks, registered deals protected on your name, and a product whose demo finishes the technical evaluation in the first call.

  • Four partner tracks
  • Deals registered on your name
  • 202 event log types · 7 SIEM formats
  • Bengaluru-built, deployed on five continents

Why now

Three clocks are running at once.

This is not a market-growth argument. Three specific pressures are landing on Indian enterprises inside the same eighteen months, and all three route budget through the channel.

The compliance clock

The DPDP Rules were notified on 13 November 2025. From 13 November 2026 the Data Protection Board can receive complaints, run inquiries and impose penalties. Full substantive compliance is due 13 May 2027, covering security safeguards, breach reporting and data principal rights. Penalties reach ₹250 crore per violation. Access control is in scope, and every regulated account is re-scoping it now.

13 Nov 2026 → enforcement powers · 13 May 2027 → full compliance

The service shift

Managed security is the fastest-growing part of Indian security spend, outpacing traditional product sales. Buyers have stopped purchasing tools and started purchasing outcomes. The vendor that makes multi-tenant delivery easy wins the partner's attention.

Outcomes bought as a service, not tools bought as a licence

The capacity gap

India is short of qualified security professionals by a margin no hiring plan closes this year, and a credible in-house SOC is a permanent cost centre. Enterprises that cannot staff Zero Trust internally have exactly one option, and it is you.

CERT-In allows 6 hours to report an incident

The tracks

Four ways to build on this. Pick the one that matches how you already sell.

We do not run a single program with tiers bolted on. The tracks are separate because a distributor's economics and an MSSP's economics have nothing in common.

Reseller

ForVARs and system integrators who own the customer relationship and the paper.

  • Margin on new business and on renewal
  • Deal registration that protects the opportunity on your name
  • Pre-sales engineering on live deals
  • The POC run jointly, not handed over

You ownThe commercial relationship, the implementation, and the renewal.

Enablement

What you get, in the order you will need it.

  • Deal registration

    Register the opportunity, get it protected on your name, and know where it stands.

  • Partner portal

    Deal status, collateral, quotes and co-branding assets in one place, instead of an email thread with a partner manager.

  • MDF and co-marketing

    Campaign funds, joint webinars, event support, and co-branded material for your own verticals.

  • Technical enablement

    One commercial session and one technical session, both short enough that your team will actually finish them.

  • A named partner manager

    One person, reachable, who knows your open deals.

  • Pre-sales on live opportunities

    Our SE joins your customer call. We do not hand you a datasheet and wish you luck.

What you carry into the room

Four arguments that survive a technical evaluation.

The demo is the pitch.

The console is the product, and it demonstrates in thirty minutes against the customer's own applications, whether cloud, on-premise or hybrid. Most access deals stall in a six-week technical evaluation. Ours tends to end in the first call, because there is nothing to take on faith.

See the demo they will see

Their traffic never transits us.

The architecture is split-plane: the control plane makes decisions, the data plane is theirs, and user traffic goes device to application without passing through our infrastructure. In a DPDP or RBI conversation this closes the data-residency objection outright. The global SASE platforms cannot give the same answer, because their architecture routes customer traffic through their own edge.

Take the data path apart

The depth is published.

8 authentication profiles. 6 MFA methods. 7 application types. 25 device posture checks, named. 144 rules. 202 event log types. 7 SIEM export formats. All of it public, all of it linkable. When the customer's security architect asks whether it does X, you send a URL instead of booking a discovery call.

The published depth

One console, one line item.

ZTNA, application access, identity, SSO, MFA, device posture, privileged session recording and database access run on the same policy engine. That is one renewal to defend instead of five, a shorter procurement cycle, and more attach per account than a point product gives you.

What runs on the one engine
  • Founded 2012
  • Gartner-recognised, ZTNA
  • DSCI Excellence Awards
  • ISO 27001
  • SOC 2
  • Built to NIST SP 800-207

The room you will be in

The five objections you will hear. And what answers them.

Pick the one you are expecting. You get the response, and the page to send afterwards.

Where does our data go?

It does not go to the vendor. The control plane decides and the data plane is yours. Traffic goes device to application and never transits our infrastructure.

The split-plane architecture

We already have a VPN, it works.

It works until an audit asks who accessed what, from which device, in what posture. A VPN grants network access. This grants application access, and records it.

VPN against Zero Trust access

We are a Zscaler / Netskope shop.

Those route customer traffic through the vendor's own edge. If the account is DPDP- or RBI-sensitive, that is the conversation to have, and it is an architecture question rather than a feature question.

Where the two architectures differ

Will it handle our device estate?

25 named posture checks, re-evaluated during the session rather than only at login. A device that falls out of posture mid-session loses access mid-session.

The 25 checks, named

How long is the deployment?

The demo runs against their own stack in the first call. Pilot scope is set from what they saw, not from a discovery questionnaire.

Book the call with them

Where the deals are

Five sectors, six trigger events.

Access budget does not move on a schedule. It moves on an event. These are the ones worth setting an alert for.

  • BFSIRBI cyber security framework, SEBI CSCRF
  • Government and PSUSovereign data handling, tender-driven cycles
  • IT and ITESHeavy contractor rotation, short access lifespans
  • Manufacturing and logisticsThird-party and plant access
  • HealthcarePatient data under the same DPDP clock
  • A VPN licence renewal, the cleanest entry point there is
  • An audit finding on access control or privileged access
  • A DPDP gap assessment that reaches identity and access
  • Contractor or BPO onboarding at scale
  • Migration of an internal application to cloud
  • M&A, where two access estates merge without merging the networks

On record

Already distributing this.

Distribution and channel

Cloud platforms

  • Amazon Web Services
  • Microsoft Azure
  • Oracle Cloud

One policy across on-premise and cloud. See the integrations

How to join

Four steps. No committee.

  1. Apply

    A short form. Company, region, the accounts you already serve, and the track you want.

  2. Qualification call

    Thirty minutes with the partner team. We tell you honestly whether your customer base fits.

  3. Enablement

    Two sessions: one commercial, one technical. Portal access and collateral at the end of it.

  4. First registered deal

    Register it, we join the customer call with you, and you find out on a live opportunity whether this works.

Register the opportunity and it is yours to close.

Partner FAQ

The questions partners actually ask.

Do you sell direct into accounts I register?

Registration exists to answer exactly this. A registered opportunity is protected on your name, and the protection is written into the partner agreement rather than left to goodwill.

What margin should I expect?

Bands are set per track and discussed on the qualification call, against the accounts you actually serve. We would rather quote you a real number for your region than publish an average that fits nobody.

Can I manage multiple customers from one console?

Yes. The MSSP track is built on multi-tenant management, with policy and posture separated per tenant.

Who owns the renewal?

You do, on the reseller and MSSP tracks. Renewal margin is part of the model, not a one-time new-business bounty.

Do you support POCs?

Yes. Our SE joins the customer call and runs the pilot with you, and the POC scope comes from the demo rather than a questionnaire.

What if my customer is outside India?

The platform is deployed across five continents and the program is global. International opportunities route through the same registration process as domestic ones.

Apply

Tell us what you sell, and to whom.

Four fields beyond your details. We read it, and if your customer base fits we book thirty minutes to say so. If it does not fit, we say that too, instead of enrolling you into a portal you will never open.

  • A person reads this, not a scoring rule.
  • You hear back either way, including a no.
  • Nothing is auto-enrolled. No portal login until we have spoken.
  • Applying costs you a form. It does not cost you a pipeline review.
Which track?
Enter your first name.
Enter your last name.
Enter your company name.
Use your company address. Partner agreements are issued against a domain.
Tell us where you sell.
This is the part we actually read. A line or two is enough.

Bring us a deal you think we cannot win.

That is a better first conversation than a program overview. Tell us the account and the objection, and we will show you the demo we would run.