Platform · the decision layer
The Trust Engine (deep-dive)
The policy evaluation layer behind every InstaSafe session — what it weighs, what raises risk, and what it does when risk crosses the line.
What is the Trust Engine?
trust_engine
Administrators compose the conditions. It returns one verdict, per session.
The Trust Engine is the policy evaluation layer of the InstaSafe controller — not a marketing name for a firewall rule. Administrators compose conditions; it resolves them into one verdict, per session.
21combinations of identity, device, location, time and risk
12trigger types feeding the risk score
4automatic responses when it crosses threshold
- Conditions are composed, not chosen from a listIdentity, device posture, location, time window and risk score combine — an administrator writes the rule that says which combination opens which resource, and for how long.
- One verdict, not five pass/fail resultsThe inputs are weighed as a set and resolved once. A perfect identity does not rescue a failing device, and a compliant device does not rescue an impossible journey.
- Risk is continuous, so the verdict is tooThe score keeps moving during the session. A session that started clean and stops being clean is re-answered mid-flight rather than left alone until it expires.
- Every decision is written downAllow, step-up, restrict or terminate — each verdict lands in the event log with the inputs that produced it, so an auditor reads the reasoning, not just the outcome.
$ evaluate priya@acme.co → erp-core → identity directory match · mfa satisfied → device bound · posture 25/25 → location SG · 41 min after last IN login → risk 78 / 100 · impossible travel → threshold 70 $ verdict → STEP-UP · challenge issued · event logged
1verdict per session
202event types recorded
0decisions left unlogged
//Ready when you are//
Ditch the VPN. Keep your apps invisible.
Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.
Regulated, air-gapped, or on-premise? See deployment options