- Home
- Zero Trust
- Zero Trust Network Access
- Smallstep Enterprise Relay
Smallstep Enterprise Relay
ZTNA relay using mTLS & hardware-bound certs for device-based access control.

Smallstep Enterprise Relay
ZTNA relay using mTLS & hardware-bound certs for device-based access control.
Go Beyond the Directory. Track the Entire Market.
Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.
Smallstep Enterprise Relay Description
Smallstep Enterprise Relay is a Zero Trust Network Access (ZTNA) solution built on the MASQUE protocol standard (RFC 9298). It functions as a transparent network relay — distinct from traditional VPNs — using mutual TLS (mTLS) and hardware-bound device certificates to control access to both internal networks and SaaS applications. Access decisions are based on device identity rather than user credentials or sessions. Devices must present a valid, hardware-attested certificate to gain access; otherwise, they are blocked automatically. Authentication occurs silently in the background with no user-facing prompts, login screens, or browser extensions required. Traffic routing is controlled through configurable match/exclude domain rules, and access to target applications is enforced via IP allow lists and mutual TLS. The relay provides dedicated outbound egress IPs, enabling IP-based allow listing on SaaS platforms and internal services. Platform support includes: - Apple devices (iOS 17+, iPadOS 17+, macOS 14+, tvOS 17+) via the native Managed Relay MDM payload - Windows and Linux via the Smallstep agent The product extends ZTNA coverage beyond browser-based access to include CLI tools, SSH, APIs, AI-initiated workflows (MCP clients), and other non-browser applications. It can be deployed in cloud or on-premises environments, including air-gapped and hybrid configurations.
Smallstep Enterprise Relay FAQ
Common questions about Smallstep Enterprise Relay including features, pricing, alternatives, and user reviews.
Smallstep Enterprise Relay is ZTNA relay using mTLS & hardware-bound certs for device-based access control. developed by Smallstep. It is a Zero Trust solution designed to help security teams with ZTNA, Zero Trust, Zero Trust Security.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Agentless cloud security platform for risk detection & prevention
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox