# ThetaSecure > ThetaSecure is an enterprise Zero Trust security platform providing five integrated products — ZTNA VPN, Identity & Access Management, Browser-Based Remote Access, RADIUS AAA, and DNS Filtering — all deployable on-premises with full data sovereignty. Built for organizations that need enterprise-grade security without sending data to the cloud. ## Products - [TS Connect](https://www.thetasecure.com/products/ts-connect.html): WireGuard-powered Zero Trust Network Access (ZTNA) replacing legacy VPNs. Per-application access control, device enrollment & approval, always-on VPN, enterprise MSI deployment (SCCM/Intune), native clients for Windows/macOS/Linux/iOS/Android. Also includes browser-based remote access (SSH, RDP, VNC) with session recording and granular session controls. - [TS Identity](https://www.thetasecure.com/products/ts-identity.html): On-premises Identity & Access Management with OAuth2/OIDC/SAML SSO, advanced MFA (TOTP, WebAuthn/FIDO2, SMS, Email, DLogin QR-code passwordless), SCIM 2.0 directory sync from Active Directory and Azure AD, 100+ RBAC permissions, adaptive SignIn Policies. Includes built-in RADIUS AAA server (RFC 2865/2866) for WiFi and VPN gateway MFA. - [TS Filter](https://www.thetasecure.com/products/ts-filter.html): AI-powered DNS filtering blocking malicious domains, phishing, and malware. Content filtering across 80+ categories, roaming client protection. Currently in development — join the waitlist. ## Platform Overview - [Homepage](https://www.thetasecure.com/): Full platform overview, all products, solutions, and why ThetaSecure - [About](https://www.thetasecure.com/about.html): Company background, mission, founded 2025, based in Bangalore, India - [Contact](https://www.thetasecure.com/contact.html): Sales inquiries and demo requests — hello@thetasecure.com ## Technical Architecture - **Backend:** Go microservices (Gin framework), ArangoDB, ClickHouse audit store, Redis, MQTT event bus - **VPN Protocol:** WireGuard (Noise IKpsk2, ChaCha20-Poly1305 encryption) - **Web Gateway:** Guacamole protocol (SSH/RDP/VNC over WebSocket) - **Auth Standards:** OAuth2, OpenID Connect, SAML 2.0, WS-Federation, SCIM 2.0 (RFC 7643/7644), FIDO2/WebAuthn - **Deployment:** Docker Swarm on-premises, offline installer tarball, no cloud dependency for auth - **Frontend:** Svelte 5, TypeScript, Tailwind CSS ## Solutions - **Remote & Hybrid Work:** WireGuard ZTNA with device approval for distributed teams (TS Connect) - **On-Premises Deployment:** Full Docker Swarm stack in your own datacenter — ArangoDB, ClickHouse, Redis all on-prem - **Web Access & Jump Server Replacement:** Browser-based SSH/RDP/VNC with session recording, part of TS Connect - **Network Infrastructure MFA:** Built-in RADIUS AAA in TS Identity adds MFA to WiFi, VPN gateways, and switches - **Compliance & Audit:** Immutable ClickHouse audit trails, 90-day session recordings, fine-grained access controls - **AI Security Assistant:** Natural language interface for querying audit data (Ollama/on-prem, Anthropic, OpenAI) ## Optional - [Documentation](https://docs.thetasecure.com/): Full product documentation - [LinkedIn](https://www.linkedin.com/company/thetasecure): Company updates