SASE, SSE & Zero Trust Network Access
Zero Trust Network Access, Secure Web Gateway, CASB and Firewall-as-a-Service delivered from Dollu PoPs and integrated with Dollu SD-WAN - identity-based access to every application, for every user, from anywhere.

40+
PoPs delivering SSE
< 20 ms
Typical user-to-PoP latency
0
Inbound VPN ports exposed
What is SASE, SSE & Zero Trust Network Access?
Dollu SASE, SSE & Zero Trust Network Access replaces the perimeter model - VPN concentrators, backhauled internet and implicit trust for anything inside the network - with identity-based access enforced close to the user. Security Service Edge functions run at Dollu PoPs across India, Europe, the UK, the US and APAC: Zero Trust Network Access brokers connections to private applications, Secure Web Gateway inspects internet traffic, Cloud Access Security Broker governs SaaS use, and Firewall-as-a-Service applies network policy. Combined with Dollu SD-WAN this becomes a full SASE architecture managed by one provider.
ZTNA is the centrepiece for most customers. Users authenticate through your identity provider - Microsoft Entra ID, Okta, Google Workspace or on-premises AD federated via SAML/OIDC - and device posture is checked before access. Instead of joining the network, the user is connected only to the specific application they are authorised for, through an outbound connector next to the application. There are no inbound firewall ports, no lateral movement across a flat VPN, and no difference in experience whether the application is on premises, in Dollu Cloud or in a hyperscaler.
Internet and SaaS traffic is secured in the same fabric. Secure Web Gateway provides URL and content filtering, TLS inspection, malware scanning, sandboxing and data-loss prevention for outbound web traffic. CASB discovers shadow IT, applies policy to sanctioned SaaS via API and inline controls, and enforces data protection in Microsoft 365, Google Workspace, Salesforce and other platforms. FWaaS applies port, protocol and application policy for branch and remote traffic without on-site firewalls. Policy is written once, in one console, against users, groups, devices and applications.
Delivery from Dollu PoPs is what makes the difference in practice. Users and branches connect to the nearest PoP with typical latency under 20 milliseconds, traffic is inspected once and forwarded over the Dollu backbone to private applications, Dollu Cloud, hyperscaler interconnects or the internet. Dollu SD-WAN sites are steered into the same PoPs, so branch users and remote users receive identical policy. The service is operated 24×7 by Dollu security engineers with change control, monthly reporting and integration into Dollu MDR and SOC.
Why choose Dollu for sase & zero trust.
The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.
Retire the VPN
Users get direct, authenticated access to specific applications with no client-to-network tunnel, no exposed VPN gateway to attack and no lateral movement if a device is compromised.
Faster for users, not slower
Traffic is inspected at the nearest Dollu PoP and forwarded over the backbone rather than backhauled to a data centre, so SaaS and internet performance usually improves after migration.
One policy for office, home and road
Branch users on Dollu SD-WAN and remote users on the agent hit the same PoPs and the same policy, so there is one set of rules to write, audit and explain.
See and control SaaS use
CASB reveals unsanctioned applications, applies data-protection rules to sanctioned ones and blocks risky sharing, without deploying agents on every path.
Built for third parties and contractors
Grant partners, BPO agents and contractors access to a single application from unmanaged devices with posture checks and session recording, and revoke it in one click.
Capabilities in detail.
Everything included with SASE, SSE & Zero Trust Network Access - the platform features, options and controls you get from day one.
- 01
Zero Trust Network Access
Agent and agentless (browser) access to private web, SSH, RDP, VDI and thick-client applications via outbound connectors; per-application policy by user, group, device posture, location and risk; continuous session evaluation.
- 02
Secure Web Gateway
URL and category filtering, TLS inspection with granular exemptions, anti-malware and cloud sandboxing, file-type controls, inline data-loss prevention and acceptable-use reporting for all outbound web traffic.
- 03
Cloud Access Security Broker
Shadow-IT discovery from traffic logs, risk scoring of thousands of SaaS applications, API-based scanning of Microsoft 365, Google Workspace, Salesforce and others, and inline controls on uploads, downloads and sharing.
- 04
Firewall-as-a-Service
Layer 3–7 policy for branch and remote traffic enforced at Dollu PoPs, including IPS, application control and geo-blocking, removing the need for on-premises firewalls at small sites.
- 05
Identity and device integration
SAML/OIDC federation with Microsoft Entra ID, Okta, Ping, Google Workspace and AD FS; SCIM group sync; posture from Intune, Jamf, CrowdStrike, SentinelOne and Defender; MFA and step-up authentication.
- 06
SD-WAN and network convergence
Dollu SD-WAN sites tunnelled into the nearest SSE PoP with policy-based steering; private application traffic forwarded over the Dollu backbone; hyperscaler interconnects and Dollu Cloud reached without internet exposure.
- 07
Data protection
DLP policies across web, SaaS and private applications with predefined templates for PCI, PII and PHI, exact-data matching, watermarking and quarantine workflows.
- 08
Operations and reporting
24×7 policy management with change control, user-experience monitoring, monthly reports on access, threats blocked, SaaS risk and DLP incidents, and event streaming to Dollu MDR/SOC or your SIEM.
How it works.
From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.
- Step 01
Discover
We map users, devices, applications, SaaS estate and current VPN and proxy flows, and integrate your identity provider and endpoint management to establish posture signals.
- Step 02
Design policy
Access policies are written per application group and user role, web and SaaS policies per business unit, and a migration order is agreed starting with the highest-value or highest-risk applications.
- Step 03
Pilot
A pilot group runs ZTNA, SWG and CASB alongside the existing VPN. Connectors are deployed next to applications, posture rules are tuned and user experience is measured.
- Step 04
Migrate
Users and applications move in waves; SD-WAN sites are steered into SSE PoPs; VPN gateways and legacy proxies are decommissioned once traffic confirms nothing depends on them.
- Step 05
Operate
24×7 operations, change control, monthly reporting and quarterly policy reviews, with new applications onboarded through a standard request process.
Who uses this and why.
Typical deployments across carriers, enterprises, platforms and contact centres.
Hybrid and remote workforces
Secure access to private applications and SaaS from home, hotels and shared offices with consistent policy and better performance than VPN backhaul.
Contact centres and BPOs
Work-from-home agents and third-party BPO staff reach CRM, dialler and agent desktops from managed or unmanaged devices with posture checks, DLP and session recording for compliance.
Multi-site enterprises on SD-WAN
Branches breakout locally to Dollu SSE PoPs for internet and SaaS, with private applications reached over the backbone, replacing branch firewalls and hub backhaul.
Mergers, partners and contractors
Grant granular, time-bound application access to acquired companies, suppliers and contractors without joining networks or issuing VPN credentials.
Retail and field operations
Store and field devices access only their applications, guest and payment traffic is segmented, and small sites need no on-premises firewall.
Technical & commercial specifications.
Key parameters at a glance. Ask us for the full service description and SLA document.
| Functions | ZTNA, SWG, CASB, FWaaS, DLP, remote browser isolation (optional) |
|---|---|
| Delivery | 40+ Dollu PoPs across India, EU, UK, US, APAC; anycast steering |
| Access modes | Agent (Windows, macOS, iOS, Android, Linux); browser-based agentless |
| Applications | Web, SSH, RDP, VDI, thick client via connector; SaaS via API and inline |
| Identity | SAML/OIDC: Entra ID, Okta, Ping, Google, AD FS; SCIM; MFA |
| Posture | Intune, Jamf, CrowdStrike, SentinelOne, Defender; certificate checks |
| SD-WAN | Native steering from Dollu SD-WAN; IPsec/GRE from third-party edges |
| Data protection | DLP templates for PCI, PII, PHI; exact-data match; quarantine |
| Reporting | Monthly access, threat, SaaS risk and DLP reports; SIEM export |
| Support | 24×7 security operations; P1 response ≤ 15 min; named engineer |
How Security is priced.
Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.
We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.
- DDoS and managed firewall per protected site or circuit
- SASE and zero trust per user
- MDR per endpoint or by log volume
- Assessments and penetration tests as fixed-scope projects
- 12–36 month terms on managed services
- Billing
- Monthly recurring in advance; projects invoiced on milestones
- Commitment
- 12–36 months for managed services; none for assessments
SASE & Zero Trust - your questions answered.
The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.
Still have a question?
Ask our solutions teamRelated services.
Services customers commonly combine with SASE, SSE & Zero Trust Network Access.
Start with one application.
Pick a critical application and a pilot group; we will have Zero Trust access running alongside your VPN within two weeks so you can compare experience and security side by side.
