Skip to main content
ION / Zero Trust Access Platform

NIS2-ready access control. Continuous trust. Zero compromise.

ION is a modular zero trust access platform under active development. It ensures the right user, on the right device, under the right conditions, gets access only to the right resource — with continuous validation every 90 seconds, full audit trails, and post-quantum cryptography built in from day one.

NIS2

Compliance built in, not bolted on

Deny-by-default policy engine, continuous re-evaluation, full audit trail, and incident notification support — mapped directly to NIS2 Articles 21 and 23.

Pricing

Pricing that reflects your infrastructure

Built for real-world environments where devices, workloads, and systems scale beyond headcount. You pay for what you actually secure — not just who logs in.

What ION does

Not another VPN with a dashboard. A complete zero trust platform with identity, device trust, policy, encrypted connectivity, and recovery — in one system.

01

Continuous session validation

Sessions re-evaluate every 90 seconds against identity, device posture, and policy. A denied evaluation terminates the tunnel immediately. Trust is active, never static.

02

Short-lived credentials

Session certificates live for 2 minutes. Device certificates rotate every 90 seconds. If a credential is compromised, the blast radius is measured in seconds, not months.

03

Encrypted WireGuard tunnels

Real point-to-point encrypted connectivity — not TLS proxying. Every connection between client and resource travels through a properly authenticated WireGuard tunnel.

04

Device posture enforcement

Continuous health checks: OS version, disk encryption, device status, security updates. Poor posture triggers re-authentication or quarantine — automatically.

05

Recovery and quarantine workflows

Compromise response is designed in, not improvised. Suspicious devices are isolated, sessions revoked in cascade, with a clear path from quarantine back to trusted status.

06

Post-quantum cryptography

Hybrid composite signatures (ECDSA P-384 + ML-DSA) and key exchange (X25519 + ML-KEM-768) from the start. FIPS 203, 204, and 205 compliant. Harvest-now-decrypt-later resistant.

Built for NIS2

NIS2 mandates risk-based security measures including access control, incident handling, supply chain security, and auditability. ION addresses these requirements architecturally — not through documentation alone.

Article 21

Access control and risk management

Deny-by-default policy engine, explicit access decisions, continuous device posture evaluation, and role-based access control with tenant isolation at every layer.

Article 21(h)

Cryptography and encryption

Hybrid post-quantum by default. FIPS 203/204/205 algorithms for key exchange and signatures. All transport encrypted end-to-end via WireGuard.

Article 23

Incident notification and audit

Every trust decision, policy evaluation, session grant, and revocation is logged with full context. 24-hour early-warning capability via structured event streams. 72-hour notification support via exportable audit logs.

Sovereignty

EU-first, self-hosted by design

Managed EU deployment or fully on-premises. No US vendor lock-in. GDPR-aligned data handling. Your infrastructure, your jurisdiction, your data.

The ION portal

ION lives at ion.zero-trust.be — a dedicated, independently secured environment. This marketing site and the product platform are fully separated by design.

UNDER CONSTRUCTION
Portal address
ion.zero-trust.be

The sign-in experience is fully branded and supports multi-factor authentication with hardware key and biometric options, integrating with your existing identity provider.

Who ION is built for

ION is built for any organisation that wants stronger access control. Critical and NIS2-regulated sectors benefit the most because the audit trail, device trust, and policy model map directly to their obligations.

01

Any organisation with sensitive access

SMEs, service providers, internal teams, and growing companies that want less blind trust around users, devices, SaaS, admin access, and internal resources.

02

Critical and NIS2-regulated sectors

Healthcare, energy, transport, water, digital infrastructure, suppliers, and other regulated environments where access control, incident response, and auditability are no longer optional.

03

Public and sovereignty-sensitive environments

Public sector teams and European organisations that need controlled deployment, full audit trails, and less dependency on foreign access platforms.