CraftSASE · SD-WAN + SSE

The perimeter is gone.
The goals remain.

Stop stitching boxes. CraftSASE unifies SD-WAN and the security service edge — ZTNA, SWG, CASB, FWaaS — under declared access goals, correlated with your network operations by Ritam.

Every user, site and app gets the access it should have — verified continuously, routed optimally, and explained causally when something drifts.

BFSIManufacturingDistributed enterpriseSovereign PoPs · on-prem control
Access posture · LiveENFORCING
312 sites · 14,200 users1 site degraded · rerouted, SLA claim queued
The problem

Your WAN and your security stack are strangers.

Access today is an accumulation: MPLS contracts, VPN concentrators, branch firewalls, a web proxy, a CASB trial — each with its own policy language, console and blind spots. The user experience falls through the gaps, and so do the attackers.

5–8
point products between a user and an app — each a console, each a policy silo
flat
VPN trust — one phished credential exposes the whole segment
2 teams
network owns the path, security owns the policy — nobody owns the outcome
weeks
to bring up a new site with full security parity
Bolting security onto the WAN is not SASE. If the path decision and the access decision are made by different systems, every incident starts with two teams comparing dashboards.
The thesis

Access, managed by goals — not appliance configs.

You declare who may reach what, at what experience level, under what posture. CraftSASE compiles that into path selection, zero-trust policy and inspection — and Ritam holds it true, flagging drift with the cause attached.

Appliance era — stitched
Goal-driven — unified
Policy lives in 6 consoles, drifting apart
You declare a goal — “vendors reach app X only, sessions recorded”
VPN grants the network; attackers move laterally
ZTNA grants the app — per session, per posture, nothing else visible
Branch experience degrades; ticket bounces NOC ↔ SOC
ARGUS names the cause — path, policy or provider — in <60 s
New site = firewall build, proxy config, VPN setup
New site pulls its whole posture from the declared goals — same day
The platform

SD-WAN + SSE — one policy, one path decision.

Two co-equal pillars on one substrate. The networking pillar decides how traffic moves; the security pillar decides what may move at all. Because both run on the same graph, every access decision is also a routing decision — and vice versa.

Connect

SD-WAN edge

Application-aware path selection — broadband, LTE/5G, MPLS, any mix
Per-app SLA steering — voice, SaaS and core apps each get their path
Zero-touch provisioning — a site is a policy pull, not a truck roll
WAN goals tracked live — latency, loss, jitter per site and app
Protect

Security service edge

ZTNA — per-app, per-session access; the network stays invisible
SWG — web filtering and TLS inspection at the edge PoP
CASB — sanctioned and shadow SaaS, visible and governed
FWaaS — one firewall policy, enforced everywhere, versioned like code
Ritam binds the two. A degraded app experience resolves to its real cause — congested path, tightened policy or provider fault — in one correlated view, because path and policy live on the same graph.
Declare the access

Own the number.

You set the access goals you're accountable for; CraftSASE tracks target vs realised, and Ritam flags what's at risk — with the causal trace already attached.

Access goalTargetNowStatus
Sessions within experience goal> 99.5%99.7%On track
ZTNA coverage (users on legacy VPN)0 users214At risk
Site availability> 99.95%99.97%On track
SaaS p95 latency< 200 ms168 msOn track
Shadow-IT flows governed100%100%On track
1 goal at risk — 214 users still on legacy VPN; migration wave 4 scheduled, ARGUS confirms no app dependencies block the cutover.
Vertical-tuned

Access means something different in each vertical.

BFSI, manufacturing and distributed-enterprise access models out of the box.

BFSI

Access is transaction trust

For a bank, every branch, ATM network, work-from-home analyst and third-party vendor is an access decision under RBI and DPDP scrutiny. Zero trust isn't a slogan — it's the audit position.

Declared access goals
Branch link availability> 99.95%
ZTNA policy coverage100% of users
Vendor session recording100%
Core-app access latency< 40 ms
In practice: A branch's primary link degrades during peak hours. CraftSASE shifts core-banking traffic to the backup path, holds vendor sessions on the recorded gateway, and ARGUS traces the degradation to a provider-side fault — evidence attached for the SLA claim.
One mis-scoped vendor session is a finding; one branch outage during business hours is front-page news.
Manufacturing

Access is plant continuity

For a manufacturer, SASE reaches into the OT boundary: plants, suppliers and remote engineers touching systems where a bad access decision stops a line.

Declared access goals
Plant-to-cloud latency< 60 ms
OT segment isolation100% enforced
Remote-engineer MTTR access< 5 min
Site uptime> 99.9%
In practice: A supplier's technician needs emergency access to a PLC vendor portal at 2 am. ZTNA grants a scoped, time-boxed session to that one system — not the flat VPN of old — and the session log lands in the audit trail automatically.
The alternative is a site-to-site VPN that trusts everything behind it — one phished supplier from a stopped line.
Distributed enterprise

Access is the network now

For a retail chain, a logistics fleet or a services firm, there is no perimeter left: hundreds of sites, SaaS-first apps, and a workforce that's everywhere. The WAN and the security stack must be one decision.

Declared access goals
Site bring-up time< 1 day
SaaS app experience (p95)< 200 ms
Shadow-IT visibility100% of flows
Per-site security parity100%
In practice: A new store opens Monday. The edge device arrives Friday, calls home, pulls its policy — SD-WAN paths, ZTNA scopes, web filtering — and the store opens with the same security posture as headquarters. No truck roll, no firewall build.
Every site that runs its own security stack is a snowflake; every snowflake is the next incident.
One incident, end to end

From “the branch is slow” to the exact cause — in one view.

A single access symptom, traced across path, policy and provider to one root cause. No NOC-vs-SOC standoff — ARGUS follows the session across every hop.

SENSE

Core-app latency at 12 branches breaches the experience goal — sessions flagged at risk

TRACE

ARGUS walks path and policy together: not congestion — a TLS-inspection rule change from last night

ACT

Ritam queues the rollback for the mis-scoped rule and steers affected apps to the bypass class

PROVE

Goal back in range in minutes; the change, cause and fix logged for the audit trail

days
Stitched stack — tickets bouncing between WAN and security teams.
<60 s
CraftSASE — ARGUS causal RCA across path and policy.
1
Investigation starts at the user's session, ends at the responsible rule or link.
How it plugs in

Sovereign PoPs. Your control plane, on your premises.

Global SASE clouds route your traffic through someone else's jurisdiction. CraftSASE runs its inspection PoPs in-country — or fully on-prem — with the control plane wherever your data-residency posture requires.

Sovereign PoPs

Inspection and enforcement in-country — DPDP and sector residency mandates hold by architecture, not exception.

On-prem control plane

Policy, keys and session logs stay on your premises. Air-gap capable for government and defense estates.

Migrates at your pace

Runs alongside existing MPLS and VPN during transition — site by site, cohort by cohort, no flag-day cutover.

One session, every plane — correlated: User → Policy → Path → Provider → App. One RCA, not four vendors on a bridge call.
The measurable delta

What goal-driven secure access delivers.

From appliance sprawl to owned outcomes — measurable from the first quarter.

<60 s
Access RCA
path + policy correlated, ARGUS causal — vs days of triage
1 day
Site bring-up
zero-touch edge, full security parity from first boot
0
Lateral trust
ZTNA grants the app, never the network
1
Policy plane
one declared posture across every site, user and app
[__%]
WAN cost reduction
MPLS right-sized against broadband + 5G — per account
[₹ __]
Consolidated spend
point products retired into one edge — per account

[ ] bracketed values to confirm against account baseline.

How to engage

A de-risked path — delivered with your SI.

Every stage is co-funded, KPI-gated and reversible. For large accounts we deliver through your Tier-1 SI partner.

01Weeks 1–2

Access architecture workshop

Map your sites, users, apps and current VPN/MPLS estate. Declare the access goals that matter and baseline latency, availability and policy sprawl.

You bring: Site & app inventory · current WAN/VPN contracts

02Months 1–2

Edge PoC

SD-WAN + ZTNA live on 3–5 real sites and one user cohort. Goals tracked live. If the agreed KPIs don't move, you exit at zero further cost.

You bring: Co-funded PoC · pilot sites

03Months 3–9

Estate rollout

Site-by-site migration off legacy VPN and MPLS, access goals enforced estate-wide, ARGUS correlation live. SI-delivered, at your pace.

You bring: Subscription · zero additional CapEx

Delivered via TCS · Wipro · Infosys · Accenture — coexists with your MPLS and VPN estate during migration, never a flag-day rip-out.
One engine, one enterprise

The programmable enterprise suite.

One AIOps engine underneath — Ritam. Prove one surface, extend without re-integrating.

See it live

The access console.

Access goals, site health, and the correlated path-and-policy trace behind every session.

CraftSASE — console screenshot
See it on your estate

Bring us your worst branch.

An edge PoC on your real sites — watch access goals go live without a flag-day migration.