Goal-Driven Secure Access Service Edge
Network and security, converged — secure access from anywhere, managed by goals
CraftSASE converges the network and security edge into one cloud-delivered service: application-aware SD-WAN for connectivity, and a full Security Service Edge (SSE) — ZTNA, secure web gateway, cloud access security broker, and data loss prevention — for zero-trust access. Sites, remote users, and cloud workloads reach what they need over a single fabric, with security applied inline at the edge rather than backhauled to a data centre. Security and network teams declare the outcomes they own — application experience, zero-trust posture, threat containment — and MatreComm's orchestration layer holds them true, approval-gated. CraftSASE is multi-vendor, and orchestrated by the same goal-driven control plane as the rest of the MatreComm portfolio.
Platform Overview
| Category | SASE — SD-WAN (network) + SSE (security) converged in one cloud-delivered edge |
| Scope | Two pillars, deep: application-aware SD-WAN and Security Service Edge (ZTNA, secure web gateway, cloud access security broker, data loss prevention) |
| Control model | Declare goals (app experience, zero-trust posture, threat containment) → the orchestration layer holds them, approval-gated |
| Buyer | CISO / network-security — secure connectivity for branch, remote workforce, and cloud |
| Multi-vendor | Overlay across leading SD-WAN and next-gen firewall platforms — no rip-and-replace |
| Relationship | The SD-WAN + SSE core; for firewall, LAN switching/WiFi, and branch asset management, see CraftBranch |
The SASE Fabric — Two Pillars
SD-WAN — Application-Aware Connectivity
SSE — Security Service Edge
- Application-aware routing with dynamic path selection and real-time link scoring
- Secure overlay to regional points of presence for site-to-site and site-to-cloud connectivity
- Sub-second failover with cellular backup paths and active-active links
- Tiered service classes with class-based QoS and per-application SLA enforcement
- Zero-touch onboarding — ship the device; it self-provisions
- ZTNA — zero-trust network access, per-user/-device/-app policy, no implicit trust
- Secure Web Gateway — URL filtering, sandboxing, malicious-site blocking, TLS inspection
- CASB — SaaS discovery, shadow-IT visibility, sanctioned-app control
- DLP — content inspection, policy-based blocking, exfiltration prevention across web and SaaS
- Identity — federation, conditional access, MFA integration, device posture check
Goal-Driven Operation
The orchestration layer correlates the network and security domains, so a user-experience problem and its security context are one diagnosis — not a separate network ticket and security ticket. When a session-experience issue is detected, the platform isolates whether it's a connectivity problem or a security control, proposes a fix, and — on approval — re-steers the session while holding the full security posture and audit trail intact.
Honest autonomy — known-safe re-steers and policy actions execute on approval from a queue; every action is authenticated, tenant-isolated, and logged with a full audit trail.
One policy model — a single intent ("this group reaches these apps, with this posture") is enforced consistently across both connectivity and security controls, not maintained twice.
Interfaces & Integration
| Category | Protocols / Integrations |
|---|---|
| Fabric | Secure overlay, sub-second failover, regional PoP interconnect, cellular backup |
| Security services | ZTNA, secure web gateway, CASB, DLP, TLS inspection, threat-intel feeds |
| Identity | SAML/OIDC, Azure AD (Entra), Okta, AD/LDAP, conditional access, MFA |
| Device management | NETCONF/YANG, REST APIs, SNMP, SSH/CLI adapters (multi-vendor) |
| ITSM & SIEM | ServiceNow/Jira, Splunk/Sentinel, Slack/Teams, webhook events |
Multi-Vendor Interoperability
An overlay across the SD-WAN and security hardware you already run — no rip-and-replace. The platform integrates with leading SD-WAN CPE and next-generation firewall / SSE vendors, plus major identity providers (Azure AD, Okta, AD/LDAP, Google Workspace).
Deployment & Scale
| Deployment models | Cloud-delivered edge (PoP-based), site device, remote-user agent, hybrid |
| Onboarding | Zero-touch device provisioning, golden-config templates, remote-user self-enrolment, drift detection & auto-remediation |
| Platform | Cloud-native, multi-tenant, horizontally scalable, high-availability, regional PoPs |
| Rollout | Performance-guaranteed pilot on a set of sites/users → fleet rollout |
Security & Governance
| Zero-trust model | No implicit trust, per-session ZTNA, identity- & posture-based access, least privilege |
| Orchestration security | Authenticated, tenant-isolated, PII-masked, fully audit-logged |
| Access control | RBAC, SSO/SAML, MFA, segregation of duties, maintenance windows |
| Action safety | Dry-run, approval gates, rollback, immutable audit trail |
Standards & compliance
SASE / SSE (ZTNA, SWG, CASB, DLP) · IETF IPsec, BFD, NETCONF/YANG · SAML / OIDC · TLS 1.2+ · RBAC & audit for regulated environments · identity federation with major providers.
For the fuller converged branch — adding firewall, LAN switching/WiFi, and branch asset management — see CraftBranch.
Prefer the PDF?
Download the printable datasheet from the resources library.
See CraftSASE against your network.
Book a demo or scope a proof of concept with our engineering team.