QS-WAN · Compare

The Zscaler alternative for networks that can't send traffic to a vendor cloud

Zscaler runs the cloud your traffic passes through, and that’s the design, not an accident of it. QS-WAN inverts it: the control tower and the gateways run on your own infrastructure, including air gapped, so keys, policy and packets stay inside your boundary. Move if that’s a requirement. Stay if it isn’t.

Their design

What Zscaler is, and what it's good at

Zscaler is a cloud platform. Client Connector “forwards user traffic to the Zscaler Zero Trust Exchange”, and for private applications ZPA “brokers direct, one-to-one connections between authorized users and specific apps”, so that “users never access the corporate network, and apps are never exposed to the public internet”.

What they do well

What they’re good at is the hard part.

Nothing at your perimeter has to listen

Their reference architecture says App Connectors “never accept connections initiated from the internet”, so the connector dials out over TLS.

One microtunnel, one user, one application

A microtunnel is built for one user and one application, and an app with no public record and no open port is an app nobody can scan for.

A nearby edge you never had to build

A user in a country you have never visited gets a nearby edge without you building one.

The difference

The architecture difference, in one question

Where is the decision made, and on whose machine?

Their data sheet answers it: “the user’s traffic is forwarded to a Zscaler cloud data center over the internet”, and “the connection between an authorized user and a private app is stitched together in the cloud”. ZPA Private Service Edge moves the stitching into your building, and is “hosted by the customer organization but managed by Zscaler”, registering “with the Zscaler cloud” to “download the relevant policies and configurations”. Their Azure reference architecture adds, in a note on double encryption: “if you want to ensure that traffic data is never accessible within the Zscaler cloud, even when transiting the ZPA Service Edge, you must use your own PKI.”

Your boundary Laptop Private app Office LAN crosses the line Session broker Sessions assembled here Default CA, or your PKI Hosted and run for you No inbound port opened connectors dial out, they never accept Control tower Certificate authority Company policy, signed Software you run Key material stays inside X25519 + ML-KEM-768, ML-DSA-87 What becomes yours Patching, backups and availability of the tower Where the decision point runs, and where the key material lives. Not how traffic is carried, and not internet bound traffic.
Decision made outside your boundary

The diagram compares two architectures. A dashed box marks your network boundary and holds a laptop, a private app and an office LAN. In the first, the broker that decides and assembles each session sits outside that boundary, so the control channel from each machine crosses the line to reach it. That broker is hosted and run for you, its certificate authority is either a default one or your own public key infrastructure, and nothing at your perimeter has to accept an inbound connection, because the connectors dial out. In the second, the control tower runs inside the boundary, so enrolment, certificate issuance and the signed company policy stay on your side of the line, and the key material stays with them, a hybrid key exchange of X25519 and ML-KEM-768 with ML-DSA-87 authentication. That model hands you a bill as well: patching, backups and availability of the tower become yours. The diagram compares where the decision point runs and where the key material lives. It says nothing about how traffic is carried, and nothing about internet bound traffic.

QS-WAN has one answer available. The control tower is software you install, on premise, in a private cloud, or on a network with no route out. Enrolment, certificate issuance, key exchange and policy signing happen there. Hosting it yourself, on premise or air gapped, is a supported deployment rather than a variant you have to argue for, and in that deployment nothing registers anywhere outside your boundary. Gateways sit beside the LANs you already run, so air gapped networking isn’t a mode you switch on. It’s what’s left when the tower has no uplink to lose.

Your week

What changes in your week

Ownership moves, and the pager moves with it

You patch the tower, back it up and own its availability, and that bill arrives before any benefit does.

Policy becomes a signed object with scope

The company policy is 16 rules, scoped per gateway, user or device, and a device override changes only the ids it sets.

Segments become things you draw

You create VLANs and LANs, reserve their address ranges, and draw directional edges between them on a map. Zero trust is a separate control from the tunnel mode, so a VLAN can run split tunnel and still be default deny.

Changing an algorithm becomes a scheduled operation

Crypto agility is eight key exchange options, eight certificate authorities and three ciphers, switchable fleet wide or per gateway, with certificates re-signed and redistributed for you. You plan a window for it rather than clicking it.

Scope

What's outside their scope, stated carefully

Posture

What their agent already carries, and where we differ

Their agent already does more than carry a tunnel: Client Connector feeds device posture for "context-based adaptive access control", and carries their endpoint DLP. And post-quantum isn't an empty column on their side, because they publish hybrid PQC key exchange and describe inspecting "PQC-encrypted TLS sessions".

So the difference isn't who owns the letters. It's where the key material sits. The QS-WAN tunnel negotiates X25519 plus ML-KEM-768, with ML-DSA-87 authentication and AES-256-GCM, and the certificate authority runs under your roof rather than being provisioned for you.

Moving

What moving would actually involve

Stand the tower up, and decide who backs it up

Nobody does this in an afternoon. You stand up the control tower and decide who backs it up.

Put a gateway where your LANs already are

You put a gateway where your LANs already are, so infrastructure you already own is used rather than replaced.

Enrol a pilot group and run both paths side by side

Then you enrol a pilot group and run both paths side by side until names and routes settle. If you were also using them for internet-bound traffic, that half does not travel with you.

Stay put

Don't switch if

Your real problem is internet and SaaS traffic

Their proxy inspects TLS inline across a global cloud. DNS profiles per VLAN, filtering by category against 4.8 million domains, counted on 2 September 2026, don’t replace a secure web gateway estate.

You have no infrastructure and no wish to acquire any

No data centre, no private cloud, nobody who wants a control plane: their model fits better and ours fits worse.

You bought them to give contractors access without a network

One to one brokering to a named application, invisible from the internet, is a clean answer for third parties. Putting people onto segments you drew is a worse fit for that job.

Your platform mix doesn't match ours

Windows is the complete column, macOS ships with CIS benchmarks running, and Android is there. Linux has gaps and iOS is next rather than now.

Questions

What people ask before they move

Is there a Zscaler alternative that runs fully air gapped?

That's what QS-WAN is built for. The tower installs on your own infrastructure and signs policy and issues certificates locally. Zscaler's data sheet says their on premise broker still registers with the Zscaler cloud to download policies.

Does any traffic or metadata leave for a QuantumNova cloud?

Not when you host the tower yourself, which is the deployment this page is about. Enrolment, certificates, key exchange and policy signing all happen on the machine you run, including on a network with no route out.

Is your post-quantum layer really different from theirs?

Different job. Theirs is published as recognising and inspecting post-quantum TLS passing through their cloud. Ours is the tunnel between your gateways and your devices, with a certificate authority you control.

What does hosting the control plane cost me?

Somebody else's operations team. Patching, backups and availability become yours. What you get back is keys, certificates and policy that never leave your boundary.

Bring the design you're running today

We will show you where the tower would sit on your own layout, free, with nothing to sign.

Scroll to Top