Use Cases

Platform

Resources

Why Secfense

Company

Pre-access protection for internet-facing services

Reduce your attack surface. Keep your business connected.

Reduce your attack surface. Keep your business connected.

Secfense Ghost makes your VPNs, portals and other internet-facing services unreachable to unverified sources. Your employees and partners retain access, while your existing infrastructure and traffic path stay in place.

Secfense Ghost makes your VPNs, portals and other internet-facing services unreachable to unverified sources. Your employees and partners retain access, while your existing infrastructure and traffic path stay in place.

SUPPORTED TECHNOLOGIES:

SUPPORTED TECHNOLOGIES:

FORTIGATE

FORTIGATE

CISCO ASA

CISCO ASA

PALO ALTO

PALO ALTO

IVANTI

IVANTI

CITRIX

CITRIX

F5

F5

CHECK POINT

CHECK POINT

AND MORE

vpn.your-company.com
UNREACHABLE
No route exists for unverified sources
vpn.your-company.com
UNREACHABLE
No route exists for unverified sources

The objection, answered first

Publicly reachable services give attackers a place to start.

Publicly reachable services give attackers a place to start.

Internet-facing VPNs, portals and admin interfaces can be scanned and probed before anyone logs in. For services intended for employees, contractors or partners, that exposure creates unnecessary risk. Secfense Ghost restricts reachability to verified sources, reducing opportunities for reconnaissance and exploitation.

Ivanti Connect Secure · exploited pre-auth

Citrix NetScaler · CitrixBleed

FortiGate SSL-VPN · recurring RCEs

GlobalProtect · CVE-2024-3400

Next quarter · ???

Where Ghost fits

Reduce exposure wherever access is meant for a known group.

Reduce exposure wherever access is meant for a known group.

Protect the services your employees, contractors and partners rely on, while reducing their exposure to the public internet.

Employee and contractor access

Keep your existing VPN client. Make remote access reachable after organizational verification.

Keep your existing VPN client. Make remote access reachable after organizational verification.

Partner portals

Restrict reachability to the partners who need to use your portal.

Restrict reachability to the partners who need to use your portal.

Admin interfaces and applications

Reduce public exposure for services intended for a defined group of users.

Reduce public exposure for services intended for a defined group of users.

Ghost works through a firewall, gateway or load balancer that you control. Your existing applications and traffic path stay in place.

How it works

Verify. Connect. Access expires.

Verify. Connect. Access expires.

Users verify their membership before your service becomes reachable. They then connect through the tools they already use.

01

01

Verify membership

The user verifies membership in your organization through corporate email or a PKI certificate.

The user verifies membership in your organization through corporate email or a PKI certificate.

02

02

Connect as usual

Ghost temporarily allows access from the verified source IP. The user connects directly through the existing traffic path.

Ghost temporarily allows access from the verified source IP. The user connects directly through the existing traffic path.

03

03

Access expires

When the access period ends, Ghost removes the temporary allowlist entry. Access requires verification again.

When the access period ends, Ghost removes the temporary allowlist entry. Access requires verification again.

Supported technologies

Supported technologies

Supported technologies

Secfense Ghost works with your existing VPNs and gateways. It updates the gateway allowlist after a user verifies their membership in your organization. Your existing VPN client and traffic path stay in place.

Using another gateway or an internet-facing application? Contact us to confirm support for your setup.

No revolution, just smart evolution

Reduce exposure without redesigning your network.

Reduce exposure without redesigning your network.

01

01

Configure protection at your network edge

Configure protection at your network edge

02

02

Keep your applications and traffic path

Keep your applications and traffic path

03

03

Allow access from verified sources

Allow access from verified sources

A focused deployment

A focused deployment

A focused deployment

Ghost integrates with the firewall, gateway or load balancer that controls access to your service. We review your setup and configure the integration for your environment.

Your stack stays

Your existing applications and VPN clients stay in place. Ghost updates access rules at your network edge after verification.

Your infrastructure

Deployed in your environment, on-prem or in your cloud. User traffic never routes through anyone else's cloud, ours included.

No network redesign

No new tunnels, no re-architected routing, no agents to mass-deploy across the fleet. Topology stays as it is.

Nothing new for users to learn

One lightweight step before connecting: corporate e-mail confirmation or a certificate already on the device. The VPN client they know stays the same.

Ghost vs SASE / ZTNA suites

One problem solved in hours beats every problem solved someday.

One problem solved in hours beats every problem solved someday.

SASE is a network transformation program. Ghost is a control you switch on. Both can coexist; only one closes your exposure gap this afternoon.

Secfense Ghost

Secfense Ghost

Typical SASE migration

Typical SASE migration

Time to value

Time to value

About 2 hours

About 2 hours

6 to 18 months

6 to 18 months

Existing VPN & gateways

Existing VPN & gateways

Stay, get protected

Stay, get protected

Replaced or re-architected

Replaced or re-architected

Network changes

Network changes

None; allowlist-based

None; allowlist-based

Full traffic re-routing

Full traffic re-routing

Where user traffic flows

Where user traffic flows

Directly to your gateway

Directly to your gateway

Through the vendor's cloud

Through the vendor's cloud

Where it runs

Where it runs

Your infrastructure

Your infrastructure

Vendor SaaS

Vendor SaaS

Scope

Scope

One job: pre-access exposure

One job: pre-access exposure

Everything, eventually

Everything, eventually

Secfense access security

Access security before and at login.

Access security before and at login.

Before login · Secfense Ghost

Control who can reach your services before the login page or gateway responds.

Control who can reach your services before the login page or gateway responds.

At login · MFA and passkeys

Protect authentication when users sign in to your applications.

Protect authentication when users sign in to your applications.

Together, they address exposure and account access while keeping your existing applications in place.

Vendor briefs

Technical briefs for your security and network teams.

Technical briefs for your security and network teams.

Explore how Ghost integrates with supported gateways and how verification controls reachability before login.

FortiGate SSL-VPN

FortiGate SSL-VPN

Ivanti Connect Secure

Ivanti Connect Secure

Citrix NetScaler Gateway

Citrix NetScaler Gateway

Palo Alto GlobalProtect

Palo Alto GlobalProtect

Cisco ASA / Secure Firewall

Cisco ASA / Secure Firewall

F5 BIG-IP APM

F5 BIG-IP APM

Don't see your exposed product here?

Using Exchange, SharePoint, Jira, Confluence or another internet-facing service? Talk to us to confirm integration options for your environment.

Using Exchange, SharePoint, Jira, Confluence or another internet-facing service? Talk to us to confirm integration options for your environment.

Regulatory tailwind

Attack surface reduction is now a legal requirement.

Attack surface reduction is now a legal requirement.

SASE is a network transformation program. Ghost is a control you switch on. Both can coexist; only one closes your exposure gap this afternoon.

NIS2 · Art. 21

NIS2 · Art. 21

Requires risk-proportionate technical measures, including access control and network security. Removing public reachability of remote-access systems is a direct, demonstrable reduction of risk exposure.

Requires risk-proportionate technical measures, including access control and network security. Removing public reachability of remote-access systems is a direct, demonstrable reduction of risk exposure.

DORA · ICT risk management

DORA · ICT risk management

Financial entities must minimize their ICT attack surface. Ghost removes public reachability and gates every route on verified organizational identity: corporate e-mail domain or PKI certificates.

Financial entities must minimize their ICT attack surface. Ghost removes public reachability and gates every route on verified organizational identity: corporate e-mail domain or PKI certificates.

The objection, answered first

How does Ghost control reachability?

How does Ghost control reachability?

How does Ghost control reachability?

Ghost enforces default-deny rules at your network edge. A user verifies membership in your organization through corporate email or an organization-issued PKI certificate. Ghost then temporarily adds the verified source IP to the gateway allowlist. Knowing the service address alone does not grant access.




Security by obscurity

Security by obscurity

Secfense Ghost

Secfense Ghost

Protection = secret knowledge

Protection = secret knowledge

Protection = organization-verified identity (e-mail or PKI)

Protection = organization-verified identity (e-mail or PKI)

Static: same trick for everyone

Static: same trick for everyone

Dynamic: per-user, per-session, time-boxed

Dynamic: per-user, per-session, time-boxed

Breaks the moment the secret leaks

Breaks the moment the secret leaks

Nothing static to leak; access is per-user, time-boxed, revocable

Nothing static to leak; access is per-user, time-boxed, revocable

Fails silently

Fails silently

Every access attempt is verified and logged

Every access attempt is verified and logged

Deployment considerations

What should you know before deployment?

What should you know before deployment?

Not a patching substitute

An unreachable gateway buys you time and removes opportunistic exploitation, but vulnerable software should still be patched. Ghost shrinks the window; it doesn't close the bug.

Not a full ZTNA platform

Ghost governs who can reach the gateway, not per-application micro-segmentation behind it. If you're heading toward ZTNA, Ghost is a step on that path, not the whole path.

Not magic for every network

Environments behind CGNAT or heavily shared egress IPs need one of Ghost's alternative deployment modes. We'll tell you which one applies to you before you commit to anything.

Contact Us

Find out where Ghost fits in your environment.

Find out where Ghost fits in your environment.

Find out where Ghost fits in your environment.

Tell us which services need remote access and who needs to use them. We’ll review your setup, confirm integration options and show how Ghost can reduce public exposure.

Tell us which services need remote access and who needs to use them. We’ll review your setup, confirm integration options and show how Ghost can reduce public exposure.




Secfense Inc.

350 Townsend Street #670, San Francisco, CA 94107, US

Secfense Sp. z o.o.

Dolnych Młynów 3/1 , 31-124 Kraków, EU, VATID: PL6762546545

© Copyright 2026 Secfense. All rights reserved.

Secfense Inc.

350 Townsend Street #670, San Francisco, CA 94107, US

Secfense Sp. z o.o.

Dolnych Młynów 3/1 , 31-124 Kraków, EU, VATID: PL6762546545

© Copyright 2026 Secfense. All rights reserved.

Secfense Inc.

350 Townsend Street #670, San Francisco, CA 94107, US

Secfense Sp. z o.o.

Dolnych Młynów 3/1 , 31-124 Kraków, EU, VATID: PL6762546545

© Copyright 2026 Secfense. All rights reserved.