◆ Datasheet · CraftSASE

Goal-Driven Secure Access Service Edge

Network and security, converged — secure access from anywhere, managed by goals

CraftSASE converges the network and security edge into one cloud-delivered service: application-aware SD-WAN for connectivity, and a full Security Service Edge (SSE) — ZTNA, secure web gateway, cloud access security broker, and data loss prevention — for zero-trust access. Sites, remote users, and cloud workloads reach what they need over a single fabric, with security applied inline at the edge rather than backhauled to a data centre. Security and network teams declare the outcomes they own — application experience, zero-trust posture, threat containment — and MatreComm's orchestration layer holds them true, approval-gated. CraftSASE is multi-vendor, and orchestrated by the same goal-driven control plane as the rest of the MatreComm portfolio.

SD-WAN + SSE
converged in one fabric
Zero-trust
by default
Cloud-edge
inline security, no backhaul
Any vendor
overlay

Platform Overview

CategorySASE — SD-WAN (network) + SSE (security) converged in one cloud-delivered edge
ScopeTwo pillars, deep: application-aware SD-WAN and Security Service Edge (ZTNA, secure web gateway, cloud access security broker, data loss prevention)
Control modelDeclare goals (app experience, zero-trust posture, threat containment) → the orchestration layer holds them, approval-gated
BuyerCISO / network-security — secure connectivity for branch, remote workforce, and cloud
Multi-vendorOverlay across leading SD-WAN and next-gen firewall platforms — no rip-and-replace
RelationshipThe SD-WAN + SSE core; for firewall, LAN switching/WiFi, and branch asset management, see CraftBranch

The SASE Fabric — Two Pillars

SD-WAN — Application-Aware Connectivity

SSE — Security Service Edge

  • Application-aware routing with dynamic path selection and real-time link scoring
  • Secure overlay to regional points of presence for site-to-site and site-to-cloud connectivity
  • Sub-second failover with cellular backup paths and active-active links
  • Tiered service classes with class-based QoS and per-application SLA enforcement
  • Zero-touch onboarding — ship the device; it self-provisions
  • ZTNA — zero-trust network access, per-user/-device/-app policy, no implicit trust
  • Secure Web Gateway — URL filtering, sandboxing, malicious-site blocking, TLS inspection
  • CASB — SaaS discovery, shadow-IT visibility, sanctioned-app control
  • DLP — content inspection, policy-based blocking, exfiltration prevention across web and SaaS
  • Identity — federation, conditional access, MFA integration, device posture check

Goal-Driven Operation

The orchestration layer correlates the network and security domains, so a user-experience problem and its security context are one diagnosis — not a separate network ticket and security ticket. When a session-experience issue is detected, the platform isolates whether it's a connectivity problem or a security control, proposes a fix, and — on approval — re-steers the session while holding the full security posture and audit trail intact.

Honest autonomy — known-safe re-steers and policy actions execute on approval from a queue; every action is authenticated, tenant-isolated, and logged with a full audit trail.

One policy model — a single intent ("this group reaches these apps, with this posture") is enforced consistently across both connectivity and security controls, not maintained twice.

Interfaces & Integration

CategoryProtocols / Integrations
FabricSecure overlay, sub-second failover, regional PoP interconnect, cellular backup
Security servicesZTNA, secure web gateway, CASB, DLP, TLS inspection, threat-intel feeds
IdentitySAML/OIDC, Azure AD (Entra), Okta, AD/LDAP, conditional access, MFA
Device managementNETCONF/YANG, REST APIs, SNMP, SSH/CLI adapters (multi-vendor)
ITSM & SIEMServiceNow/Jira, Splunk/Sentinel, Slack/Teams, webhook events

Multi-Vendor Interoperability

An overlay across the SD-WAN and security hardware you already run — no rip-and-replace. The platform integrates with leading SD-WAN CPE and next-generation firewall / SSE vendors, plus major identity providers (Azure AD, Okta, AD/LDAP, Google Workspace).

Deployment & Scale

Deployment modelsCloud-delivered edge (PoP-based), site device, remote-user agent, hybrid
OnboardingZero-touch device provisioning, golden-config templates, remote-user self-enrolment, drift detection & auto-remediation
PlatformCloud-native, multi-tenant, horizontally scalable, high-availability, regional PoPs
RolloutPerformance-guaranteed pilot on a set of sites/users → fleet rollout

Security & Governance

Zero-trust modelNo implicit trust, per-session ZTNA, identity- & posture-based access, least privilege
Orchestration securityAuthenticated, tenant-isolated, PII-masked, fully audit-logged
Access controlRBAC, SSO/SAML, MFA, segregation of duties, maintenance windows
Action safetyDry-run, approval gates, rollback, immutable audit trail

Standards & compliance

SASE / SSE (ZTNA, SWG, CASB, DLP) · IETF IPsec, BFD, NETCONF/YANG · SAML / OIDC · TLS 1.2+ · RBAC & audit for regulated environments · identity federation with major providers.

For the fuller converged branch — adding firewall, LAN switching/WiFi, and branch asset management — see CraftBranch.

Prefer the PDF?

Download the printable datasheet from the resources library.

Get the PDF →
See it on your estate

See CraftSASE against your network.

Book a demo or scope a proof of concept with our engineering team.