Give people access to internal systems from anywhere
Secure remote access is the problem of people working outside the office while the systems they need stay inside it. The usual answers are to expose those systems to the internet, which is a permanent attack surface, or to run a VPN that treats everybody the same once they are through the door. Neither is what you wanted.
The situation
Someone is at home, at a customer site, or in a hotel, and they need the thing that lives on the server in the office. That is the whole problem, and it has not changed in twenty years.
What changed is the size of it. It is no longer the sales team on a Thursday. It is most of the company, most of the week, on devices you did not buy, over connections you do not control.
Why the usual answers do not fit
Publishing the system to the internet solves it in an afternoon and leaves you with a permanent front door. Every unpatched day is a day it is reachable from everywhere.
A classic VPN puts people inside the network, and then the network trusts them. One set of stolen credentials is one device with the same reach as an administrator sitting in the building.
Per-application gateways avoid both, and then you are maintaining a separate publishing rule for every system, forever, and the exceptions accumulate faster than the documentation.
Your systems stay where they are. Nothing new is exposed to the internet.
Your systems stay where they are. People reach them through one encrypted connection, from whatever network they happen to be on.
The device connects to a gateway that sits next to the equipment you already have, and the tunnel between them is post-quantum by default. From that point the person reaches what policy says they may reach, and nothing else.
Access is a decision, not a door.
Access modes, country and IP allow lists, and schedules per VLAN mean a contractor who should only reach one system, on weekdays, from one country, reaches exactly that. Multi-factor authentication is enforced from the same policy rather than bolted on beside it.
The rules do not depend on where the person is.
The same policy applies in the office and on hotel wifi, because the policy follows the identity and the device, not the network they happen to be sitting on.
You can see it.
The network map shows the shape of it, so “can this person reach that server” stops being a meeting and becomes something you look at.
This is usually the situation when
- You have internal systems and people who are not in the building.
- Your team is distributed across more than one place, permanently or some of the week.
- You have external contractors who need to reach one part of the network and nothing else.
What secure remote access solutions usually get wrong
Most secure remote access software is sold as a tunnel and priced as a platform. You end up with the connection solved and the three questions after it still open: who may reach what, on which device, and how you prove any of it happened six months later.
The secure remote access tools that survive an audit are the ones where the answer to those three questions lives in the same place as the connection, rather than in a spreadsheet next to it.
What your people see
One app. They open QNova Client, it connects, and they work.
There is no dashboard for them to learn and no client-side configuration to get wrong, which matters more than it sounds: the remote access projects that fail usually fail on the ninety-nine per cent who never asked for any of this.
What it replaces
The same signed agent also carries endpoint protection, remote support, the password manager and encrypted file transfer. If remote access is what brought you here, it is worth knowing the other four arrive with it rather than as four more contracts.
What it takes, and what it leaves alone
One gateway in the path, alongside the network equipment you already have. Every subscription starts at three gateways.
Devices get QNova Client. Access rules are defined in the console.
Your systems stay where they are. Nothing new is published to the internet.
The features this use case relies on
See it running on your own network
It is free, there is nothing to sign, and nobody is going to sell you anything.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.