Sign in

Find your organisation

Every organisation has its own Inlinea address. Type the first word of yours, or the whole address, and we will take you there.

Take the tourBook a demo

Architecture

A glass box, not a black one.

Every customer runs its own environment: an edge, the Inlinea server, the Control Center, the Workspace, the ZERA gateway and the session engine. Follow one request through them and see which component decides what.

The request path

One connector dials out. Nothing opens inbound.

An HTTPS request from a browser to a private application, step by step, and the agent path beside it.

Inlinea server
  1. Browser
  2. Edge
  3. ZERA gateway
  4. Encrypted private network
  5. Connector
  6. Application

Step 1 of 10

The browser resolves the resource's address to your tenant and opens an HTTPS connection.

One connector dials out. Nothing opens inbound at the private site.

Components

What runs in your tenant

ComponentResponsibility
EdgePublic entry, platform TLS and hostname routing; forwards protected hostnames to the gateway without reading them
Inlinea serverAPI, identity, policy, signalling, relay and STUN; the one place policy is decided
Control CenterThe administrator application; a client of the server with no database of its own
WorkspaceThe end-user portal; shows only what the person is approved to open
ZERA gatewayResource TLS, user authentication, policy enforcement and the encrypted private path to the application
Session engineRenders RDP, SSH, VNC and Telnet for Secure Sessions; reachable from the gateway only

Trust boundaries

Which component decides what

ComponentTrustsCannot do
EdgeHostnames and certificatesReach a private application: it has no mapping to one
ZERA gatewayIdentity, policy and the service mapping from the serverOpen a path before the policy decision; the decision comes first
Encrypted network clientThe authenticated peer at the destinationReach anything the policy did not grant
Destination connectorThe private network it was enrolled intoDecide which browser user is authorised; that was decided before it was dialled
BrowserThe resource's certificateAddress the private application directly; it is not exposed

Network surfaces

Ports a tenant exposes

PortProtocolPurpose
80TCPRedirect to HTTPS
443TCPPlatform HTTPS, the Workspace, the Control Center, and protected hostnames passed to the gateway
3478UDPSTUN, for direct device paths
51820UDPThe encrypted private data plane

Custom TCP and UDP services use a reserved, published port range you decide on. The session engine listens on the gateway's loopback only.

Questions buyers ask

Is anything shared between customers?
Images are shared; environments are not. Each customer's server, Control Center, Workspace, gateway and session engine run in that customer's own tenant with their own data.
Why does the gateway terminate TLS?
To know who is asking and to apply policy to the request. That is the design of agentless access: the gateway in your tenant is the policy enforcement point for the browser path.
Where is the full detail?
The Trust Center publishes the security overview, what we can and cannot see, every outbound connection and the data residency facts.

Open the application. Never the network.