| What it is | Software. An inline inspection engine that installs as a package on OPNsense or pfSense CE, or as Zedmos NGFW from an image onto x86 hardware you own. | Zedmos NGFW |
| Where inspection happens | On the appliance that routes the traffic. No packet, payload or session record is sent to Zedmos; there is no vendor cloud in the path. | Platform |
| Management | One multi-tenant console, self-hosted as a container under your own domain, or hosted by Zedmos at console.zedmos.com from Frankfurt. Same product either way. | Zero Trust Console |
| When management is unreachable | Every firewall keeps enforcing the policy it holds. The console is not in the packet path. A lapsed licence makes the console read-only and never drops traffic. | Licensing |
| Licensing | Per firewall, no hardware in the licence. Free tier (three firewalls, thirty days), Team tier per firewall, MSP tier multi-tenant, unlimited and billed monthly in arrears. Prices quoted, not published. | Licensing |
| Jurisdiction | A German company in Tuttlingen, Baden-Württemberg. The engine is developed, reviewed and released in Germany under German and EU law; a self-hosted console keeps firewall logs in your own GDPR controllership. | About Zedmos |
| Exploit record | Zero entries in the CISA Known Exploited Vulnerabilities catalogue (version 2026.09.11). Published on a page that stays up whatever the number becomes. | security.exploit-record |
| Support period and compliance | Security updates for at least five years per product line (EU Cyber Resilience Act, Annex III Class II), a CycloneDX SBOM with every release, and a disclosure policy with dates on it. | Trust & compliance |
| Inspection | 200+ protocols classified, IDS/IPS in the same engine, TLS inspection with JA3/JA4 fingerprinting, QUIC and encrypted DNS under control, 16 policy actions, 26 threat categories. | Capabilities |
| AI gateway and DLP | 61 content detectors in 7 groups, prompts and uploads inspected before they leave, and a local language model for unstructured text, on your hardware rather than in a vendor cloud. | AI Gateway & DLP |
| SASE and SD-WAN | WireGuard, OpenVPN and GRE overlays provisioned from the console, a backup hub with automatic failover, per-application egress across uplinks, and remote users on a standard WireGuard client with no per-seat licence. | SASE & secure connectivity |
| Identity | Users and groups from Active Directory, Azure AD or SCIM; policy selects on them by name. Remote users are identified from the moment they connect. | Secure access |
| White-label and OEM | The console, the firewall interface and appliance builds can carry a partner's brand; a complete second-brand build has already shipped. The engine, its updates and its SBOM stay named. | White-label |
| Certification | Four engineer credentials (ZCA-101, ZCP-201, ZCS-SASE-301, ZCS-MSP-302) with published blueprints, every exam free to sit, every credential publicly verifiable without an account. | Zedmos Academy |