Comparisons

Compare

If you are here you already have something, or you are close to buying something. These pages set QuantumNova against the specific product you are weighing, and they try to be useful rather than flattering. Where the other product is the better fit, we say so, because you will find out anyway.

In these pages

  • Tailscale
  • ZeroTier
  • OpenVPN
  • Fortinet
  • Sophos
  • Zscaler
  • Endpoint protection
Seven comparisons

The comparisons

01

Both are mesh networks that are genuinely good at what they do, and both start free. The question is what happens when you need endpoint protection, a signed company policy a user cannot switch off, and an audit trail somebody else will read.

02

Self-managed, well understood, and free at small scale. The comparison is about who maintains it in three years and what the audit asks you for.

03

Large platforms with wide functional overlap. Both have real post-quantum work shipping. The honest comparison here is not features, it is whether adding to an existing contract beats a new supplier.

04

Per-application access that removes the private network from the picture entirely. A different architecture, not a worse one, and the right question is whether you want the network or not.

Not a head to head. The category, and where a consolidated agent sits inside it.

Plain terms

What we are not going to pretend

01

We are not the cheapest.

QuantumNova is sold in capacity tiers: you buy a tier of 50, 100, 250 or 500 devices and pay for that capacity, at 10 EUR a device a month in the smallest tier and 9.25 in the largest, plus 30 EUR per gateway. Tailscale starts at 8 dollars per user and is free for up to six. NetBird starts free. Cloudflare Zero Trust is free up to fifty users. If your requirement is a private network between machines and nothing else, several of those will cost you less, and the pages say so.

One signed agent

The price stops being comparable when you count what it replaces. QNova Client is, in one signed agent:

  • 01a VPN
  • 02endpoint protection
  • 03remote support
  • 04a password manager
  • 05encrypted file transfer

Most of the products above are one of those five, and the other four arrive as separate contracts with separate renewal dates.

02

We are not a security operations centre.

None of the comparisons should be read as us watching your network for you. The platform produces the risk score and the evidence. Your people read them.

03

We are small.

Fortinet and Sophos have been doing this for decades and have support organisations to match. What we have is that the post-quantum layer is already running rather than on a roadmap, and that our kernel drivers are attested by Microsoft, which is the specific thing that usually answers the small-supplier objection.

What is different

The one thing that is genuinely different

Everything between a device, a gateway and the control plane is post-quantum by default. The tunnel handshake, the key exchange, the signatures on policy and the file transfer, aligned to FIPS 203, FIPS 204 and CNSA 2.0, hybrid by design so the security is never worse than the classical baseline it replaces.

By default

Not a tier, not an add-on, not a roadmap item.

There is also a documented cryptographic inventory by subsystem, which is the artefact a regulator or an auditor tends to ask for before anything else, and which is awkward to produce after the fact.

Where to start

How to read these pages

Start from the constraint you cannot move. If it is budget, some of these comparisons will end badly for us and the page will say so. If it is a regulator, an audit, a network that is not allowed to touch the public internet, or five renewals you are tired of tracking, the comparison usually goes the other way.

Scroll to Top