Architecting Sovereign SASE in Your Infrastructure with Versa
Versa’s Sovereign SASE is built on a fully integrated, carrier-grade single software stack designed to meet the needs of both service providers and enterprises. In this session, Systems Engineer Adrien Olalainty will provide a technical deep dive into Versa’s SASE architecture, and explore how organizations typically evolve to a fully integrated Sovereign SASE solution.
Presented by Adrien Olalainty, Systems Engineer. Recorded live at Networking Field Day 37 in San Francisco, CA on March 19, 2025. Watch the entire presentation at https://techfieldday.com/appearance/versa-presents-at-networking-field-day-37/ or visit https://techfieldday.com/event/nfd37/ or https://www.Versa-Networks.com/ for more information.
Transcript
Now I will try to go a bit more into the architecture, what will look like when you move it to So and Sassy. Uh, but before I do that, let me, uh, talk a bit, uh, first of all, the components of Versa, sassy, what is the versa sassy components and will make more sense when we will move to the architect. The first one will be the Versa Waste.
So versa waste. Um, I guess the already the big strengths of Versa solution is that we have a single stack, a single solution where we have the SD one security, but also routing and switching all ing into a single image. So whether you traffic goes into a switch, goes into SD, one, router goes into, uh, Stasi Gateway, uh, it'll run into Versa os Um, in this os we have SD one security rooting because it's not like entry level product, it's the advanced SD one solution with a lot of customization options.
Uh, we have ation, satellite link optimization, and a lot of customization options with the, with the SD one solution security. Also, we have, uh, advanced security with everything you would expect from a NextGen firewall solution or URL security, UL, um, filtering anti malware IPS, uh, but also all the SSE, uh, capabilities that you expect more towards the cloud like csb, DLP. And so all of this together has several benefit.
So one with physical, like unified security enforcement. So whichever component your traffic lands into, you will have the same, uh, policy enforcement because it's same os and you apply the same policies there. Um, single UI for management or single pane of glass where you can manage and, and, uh, monitor all the different components that you have.
And, uh, SWAN also will be a single pass architect that allows, so single pass architect two means that, hey, I don't have multiple components to manage. Uh, as Bailey was saying, if I take, uh, one vendor for IPS one vendor for Cs B one vendor for SD one, then I need to group all this together and find out we integrate this to the software, a maintenance and so on. So it adds, um, complexity, uh, which can also create, you know, is not working as expected, will open new vulnerabilities because of that.
And, uh, it can be also quite inefficient with a single solution. And there a solution in this where everything is a single image. You have a single pane architecture where everything goes into a single flow.
When the traffic comes in, we'll first try to identify what is the context of, um, of this traffic. What, who is the user? Uh, who is the, what's the device?
Does it have the right posture? Is it compliant? Where it's coming from, at what time?
And so why I have my context. Uh, we do it only once. It's not, um, it's not every component that has to, to do this context analysis.
So we give this concept to every other security pieces. So based on the traffic, I would actually decide which security components I want to to use. So I, I will go into demo how to do that.
We'll all look in parallel, um, the traffic and the allowed or not. And if all of them allow the traffic, then we will decide where to forward it, look into the SG one optimization and, and optimize the traffic and send it to the destination. Uh, this is the data plane component.
This is, uh, the one that will be handling the user traffic. Uh, this, the Versa OS on the left data plane can be deployed, physical virtual in the cloud, um, many of options there. Then we have the control plane, which is versa control.
All the three other components on the right will be what we call the, uh, basically the head and the management of the solution. So we have the control plane, which is a Versa controller. So this is basic, basically a PGP root reflector so that we can scale, uh, very efficiently as a control plane.
And this will propagate the SD information, uh, also the IB SEC piece, uh, things like that. Then we have the management plane, which will be consel. So this one will be the UI where you will see a single pane of glass configuration dashboard and so on.
And finally, the intelligence plane. So this one will be versa, AIOps. So again, it's a single solutions.
So we have data lake, which will receive all the logs for all the different services, and we can run AI on top of that to see hey, you know, correlate the logs of the different components and try to identify anomalies to try to predict in advance what could happen, what could go wrong in the future, and try to help respond the response, say, Hey, you have those problems based on ai, I think you should do this to solve this. And each of these components will be deployed on premise or in the cloud. Uh, it's really a big and choose very versatile, uh, option of, uh, how, how much you want to, to control, uh, where you asking your, your component.
And now running into the architecture, what that will look like. So if I run SE as a service, then I would have pretty much, uh, everything in the cloud hosted by Versa. So here's the different SSD gateways will be hosted by Versa, uh, operated by Versa.
So we'll be making sure that they're open and running, that the, the links or yeah, being charged of everything related to the gateways. Uh, each of those gateways, they have all the components that we mentioned earlier about routing, switching, security. So here is pretty much a big SD one fabric where every gateway is connected together.
How do I connect to this? So then if I have, um, SD one network versa, and I will def automatically connect to all these different gateways. So it'll make a SD one fabric, uh, with those, um, with those gateways.
So the gateway will be pretty much the SD one hubs of, um, of the SD one fabric. So every different, all the branches will automatically, uh, connect to the hubs. Nothing to configure.
It's automatic, it's optimized, and it's very redundant, resilient, because you have not only two, uh, hubs, but yeah, as many pops as you have, they will connect to all of them. If you have a third party, uh, router, then you can also connect to, to versa ses. So typically that will be with IP stack.
So you connect to 1, 2, 3 different, uh, gateways to forward the traffic. And then we have the remote users, which will connect with Versa agent. So the Versa agent is a smart agent, which would, which would, uh, automatically detect which gateway to connect to.
So of course, you could pick by yourself which one you want, but also you could also tell him, Hey, first for me. And then it'll decide which one is a closet gateway, which one is the, with the best latency, with the right, if you load, and it'll compile all this information to, to decide for you which one to connect to. Um, and once you reach the gateways and to redirect you, once we have connectivity to, to the private infrastructure, then we will redirect the traffic.
If you want to go to internet, we will redirect the internet. And, and so now moving into private. So this one will be similar.
So as Anush was saying, it's there is, there could be a lot of flavor of, of this one. For example, in this one, we say, Hey, we just take a full gateway. Instead of, uh, in the first case, we have gateways which are shared from multiple customers to optimize the performance, uh, uh, across multiple console.
But hey, I want a full gateway. I want my own connections, links that are dedicated to me. Uh, then we can have dedicated gateways for a customer, uh, in the Versa pops.
So in this example, we showed with Versa pops, but as Andrew was saying, we could even produce those three gateways would even be put directly in the HQ o data center of, of an enterprise. And, and at the same time, if you want to complement, uh, complement your, your fabric with like, uh, let's say you have main location, and then you have a few user here and there, you can add another gateway in this location, but from the Versa cloud, which will be a shared gateway. So you could already pick and, uh, and, and choose, um, for each version what you want to do.
And now moving into store and SE now this is the one where everything is hosted, um, by an enterprise or by a service provider. Uh, so now the, yeah, the customer is in charge of everything. So every, every link, every rack, everything belongs to him.
So he can deploy everything as as he wants. Um, and it all behaves the same way. So you still still have your SD one, you still have your, your non SD one sites.
You still connect everything the same way, but it also enables more use cases. So I will go into this in a moment. Uh, but for example, um, in the first use cases, we are connecting to the, if we go to the, if the cloud-based option, we connect to this gateways using IP stack because we have to connect with IP stack.
It's, the requirement is not a choice. But now that I'm hosting the gateways myself, then do I want to run IP stack? Maybe not.
Maybe I don't need to. Maybe I, I can connect different things and as long as I get can get the traffic through those gateways, I could apply security. So I could connect things like 5G Network, for example, and, and secure it using the gateway.
It happens more options. I, I, I will go in more details in a, in a few slides. Uh, let's take now the use case of High Yemen enterprise.
I have no SSE and I want to move into one of the SSE options. Uh, first one will be SSE as a service. So this one we already mentioned.
So I have my different gateways I need to connect with through IPSec, uh, running my sites, my branches, uh, connecting to the gateways using IP stack. I have to confuse them. Usually this is not monitored.
Uh, this is just, yeah, plain IP stick connectivity, um, of course could be errors. It can be difficult to maintain, uh, and, and so on. Instead, I could go to Reign Es.
So going to yo case Bruno, this could be, uh, an enterprise that wants to go into store reign, SSE and only SSE, not SD one. Uh, but I want to host SSE in my own cloud, in my own data centers. So in this use case, I have, for example, my hq, my two data centers, and I'm hosting my gateways in there.
I could also have my own cloud where I, I host gateways in different locations, but now I already have all my different sites connected with M-P-L-S-I-P-V-P-N. So now, if I'm a branch and I want to go to internet, I know I could configure, I, I could just say, okay, to go to internet, I need to go through one of those three sites, and then I will get redirected towards my gateway and be secured towards internet. So now I don't need even IP stack anymore, just, just by deploying the gateway there and rooting the traffic through it, then I can secure all my traffic automatically.
Um, similar in the other way, uh, if I have a, I'm a roaming user, I connect to the gateway automatically. I have, I have full access to all the internal network. I, I can just land on one gateway, whichever it is in the fabric using SD one, I land in the right site.
And then I, I mean, the MPLS network, I can access the internal network. So this will be, for example, a I scenario where I, I have only SSC, and I'm not going to SD one yet, for example. Um, something like that.
Um, next one will be Reign. So now even one step further, I have already my reign. SSCI want to have, uh, SD one as well.
Now, it makes it even easier where all my sites automatically will connect to all my different, uh, uh, gateways. I could see I, I see my MPLS here, but now, instead of having only MPLS, I could have my fabric on top of MPLS and in Tenet and everything, uh, you know, with sdwan optimized monitors, uh, to have, yeah, resiliency and the optimization of my traffic. Uh, this will be an enterprise, but as a service provider, I could take this even one step further.
So I have, I have those different pops and this network, uh, connecting to it, I could say, Hey, let's just make it multi-tenant. So this is pretty much the same thing. But now every gateway is, is multi-tenant.
And as a service provider, it means that I can create my own sais solutions that I will offer to my, to my customers. So it's not that they're set ups anymore, it's my own pops. It's me managing all those components, and I could offer it to my customers.
So I will have SD one customers, which will integrate automatically to it. I could have MPLS customers where I would say, Hey, you have your CCPs, uh, for, for this ip, VPN, just get this add-on, and I can automatically add security to your traffic. Automatically, the traffic will go to the gateway and, and be secured, uh, towards internet.
Um, everything allows consistent security policies. So if I, yeah, we, wherever a traffic lens on a gateway on the branch, um, the same or as same security policy that we, that will be applied, uh, and everything that be customized service provider, I could say, Hey, you know, I, I will enhance the solution with my own security spread intelligence, but I will fit into the solution. I could customize the agent to have my own, you know, branding my own logo, my own colors on the agent so I can really create my own SSIS solution, offer it to, to my customer.
And now going back into the other use case that we started before adding even more, uh, again, storing SSIS is opening a lot new new set of option where the only thing I need now is to get to the traffic through the gateways. And for example, one use case that we have, uh, worked on is connecting for the pool 5G network. Uh, but not just, not just, uh, connecting it.
Uh, so what we did, we, we call it ION team. And we say, Hey, so this is very particular for ML of this kind of, uh, uh, this kind of, uh, uh, features. Uh, but we say, Hey, my, I'm a user with a SIM card.
So we'll pre-populate basically the, the sim card on the solution and say, here is a list of SIM cards of this, this customer A here is a list of this cards, SIM cards of customer B. Uh, this MZ belongs to this student, belongs to this user group. All this will be, uh, configured into the single pane of glass.
When a user connects, it would authenticate, uh, to the 5G network. And all we need now is to get the information of this authentication. So we, we can do it from Kafka, from, uh, cadu accounting.
Basically, we'll get the information that, uh, this IP address is this MC, which belongs to this tenant and to this user group. We receive this information, and we will propagate it to all the sasi gateways that when the traffic lands into the gateway, now we know we belongs to, we can connect it to the right SD one network to access internal applications. And we know the user group and the tool to apply the right security policy specific to this user.
And, and finally, uh, one more set of capabilities that we didn't address of par, which is Advanced Security Cloud. So far, we are talking about the gateways as the only security component where everything will go through. Uh, but not everything should be in line.
Uh, so for example, 10 boxing will be out of bound Air bi. I will be out of that. We also API based C, B, and DLP, where every time a file is uploaded to Dropbox, I would be notified that there is a new file.
So that person would go and analyze the file directly in the cloud. So all this is not done in line, not done by the gateway. It integrates with the gateway, of course, but it, it's separate.
So this will run more of, this is more of a container type of solution where we want it to be more elastic. The gateways need to be really about efficiency and low latency, whereas advanced cloud is really more about elasticity, uh, which we, we achieved through containers. So also this component can be chosen to be used from the cloud, whichever model you have been chosen so far.
You could take, you could do a, do a s, C from the cloud if it's something you want to, or you can even deploy, uh, a SC into your environment so that you, you keep it fully, fully survey. And next, I will be moving into the demo. Adrian, uh, before we launch to the demo, Ron Westfall, uh, Futurum, I really, uh, like, uh, sassy on sim, find it.
That will be an important driver for expanding, you know, the addressable market, not only for Versa, but also for, you know, MSP, uh, partners. And are there any, I guess, um, thoughts on how is this impacting, you know, versus a sales cycle? Is selling sovereign, sassy something that is taking up more, uh, time, uh, to communicate across?
Or is it pretty much, uh, akin to what you've already been selling? Uh, in terms of the, the, you know, the already established, uh, SSE offerings? So it's ultimately, it's quite similar because it's, uh, still talking about the SASSIS solution and, you know, tell, telling about what the solution can do, of course, because it's sovereign, then there is a lot of, uh, there is more integration effort where we need to say, Hey, what's your infrastructure and how we will integrate with it?
Or for example, if we takes ion same examples, then how will you tell us, uh, the authentication of the skin card information of the steam cards? How will you forward the traffic to, usually this is more of the, uh, service provider taking care of this. We don't really need to do that, but they also need to take care of how will I forward my data, uh, to the sassy gateway.
So the solution is the same, but yeah, of, of course, there is a bit more integration, uh, to discuss. Uh, quick question for you, Adrian. Jason Ner, um, on the, the MM and O side, do you guys have certain, let's say, certified providers that, that you guys know that this works with?
Um, and the, uh, the other question is, is like the, the IMSI like integration pretty standard across a, across most providers. It's something I'm, I'm fam unfamiliar with. Mm-hmm.
So I, I was told not to share, uh, references, but yeah, we have, uh, we have a few already in good, uh, yeah, deployed or in very good stage of the, of the advancement. And of course it has been evol eing. So yeah, it, it has been evaluating and we are moving towards something unified where yes, soc the goal is to have something reusable for all the MNOs.
Okay. If there is no other question, I will move into the demo. So this is concerto, this is the single pane of glass where you can, uh, manage versa sais solution.
Uh, so we have, yeah, various menus, uh, that we can show. So everything is very customizable. Uh, so you, yeah.
'cause we have very advanced air back where you can hide any menus that you want for your users so that they only see what is relevant for them. The first one will be the monitoring with all the different dashboards and logs, uh, of what's happening in the network. We have aggregated all of them, of course, in a single, uh, single menu where you have secure, secure access that will be the remote users connecting to your gateways.
We'll have the secure SD one, which will be, uh, OnPrem SD one that, uh, that you will have in the different sites. And then the security will aggregate those, the SD one on site security if you have enabled it, and the cloud security. So everything will be aggregated in, into, into the same menu.
Uh, let's begin with remote access users. So you will see the list of users that have connect on your network, have selected the timeframe at the beginning, and then I, I will see my different gateways where all they located and yeah, who are the users, where, where they come from, where did they connect to which gateway. I will see the basically summary of the different users.
I will see over time, you know, how many users have been connected at the same time, just to make sure that, uh, are not uploading my gateways or things like this. How many attempts to connect in case, uh, in case there are failed attempts, but also which are the gateways which, uh, have been the most used, where the users are coming from. And so this kind of information on SD one, you will see also a summary of all your sites.
You will see here the different appliances that you have or the app or the down or the, yeah, see all the information about the interfaces, all the telemetry of the different sites. So yeah, a lot of information there as well, without going into much detail, but you will see every, every issue, you will be able to deep dive into the slide and see, and see what's happening. And then the security, so on-prem, security, cloud security, everything will be aggregated into overview where you will have aggregated data.
Then we would have like shared dashboard, like, uh, for example, this will be like u filtering, you know, sweat filtering. This is common for on-prem security and cloud security. So this will be aggregated, but we'll also have, um, cloud specific, uh, so more like SSE specific dashboard like shadow white discovery, like, uh, AI based security.
Uh, based on ai, I can say, Hey, I see a risk for this type of, uh, for this user. So maybe I want to apply a different security, uh, to this user because of weird behaviors that he had, like, uh, Superman travel and, and I want to, to have less confidence to him. Also, everything related to, yeah, a I based, uh, class BDLP, email protection, air BI or everything will be, uh, aggregated into these different menus.
But if I look at the overview, you will see what you would expect, uh, uh, yeah, by all actions over time, low deny and, uh, yeah, top applications, top pure ls, top uh, top everything of everything happening in your network and of also top threat. So if I want to do, to know if I'm at risk, then we will, you will have an negative view of, uh, where, where is, uh, my issues. So here, there is a gateway that say, Hey, I had phishing events, uh, windows exploit.
Uh, I will have a information of threat activity over time of threats and so on, uh, across my network. Um, that would be monitoring. Then if I want to configure, for example, a policy, so I have different ways to configure, but if I create a new one, for example, to you would first decide what's the match material of your traffic?
Identifies the traffic. That will then match with the context of the traffic coming in. What is the application, uh, that I have?
What is the application group? So this is based on DPI, automatic recognition of the, of the traffic. What are the user that are accessing the traffic?
What is the endpoint poster of the traffic? So you could say, based on us, based on compliance, based on risk for from ai, um, different information, but it confirm geolocation more like regular, uh, security information. And based on that, I can select my actions.
So do I allow the traffic, do I deny the traffic or do I apply security modules? So I could say, Hey, I apply for this traffic, I want to apply IPS, I want to apply, uh, IP filtering. I want to apply CASB.
And yeah, I will select my different, uh, modules that I want to enable. And for each of those, we have, uh, versa predefined recommended profiles, so that if you just install, uh, the Versa solution, you already have recommended profiles to, to get you quick and quick and, uh, running. Uh, and then you can also create user defined profiles.
So as an, as a big enterprise or as an sp, uh, you could create your profiles so that you could share them across all the, all the different customers, uh, that will reuse your predefined profile as well. Then you have csb, DLP, sandboxing. And so, uh, then I wanted to show some more like that, the type of, uh, menu.
So for example, let's say what I was sharing before, like, uh, I have installed the s in my data center, how do I connect it with my MPLS? Uh, so here I will have, for example, uh, what the menu called line interface, where I will decide, hey, I have this, uh, gateway in my network. Here is a learning interface of my gateway.
I will say, like, I would say the gateway. Which one is the interface? Which is the villain, the ip, the VRF, and pre pretty much say, Hey, how do I connect to my, to my, uh, MPS network?
So usually that will be with BTP. So we'll have a route exchange between the gateway and your I-P-V-P-N, and so that, yeah, that the traffic can flow through easily between other components. Uh, and finally the last one I wanted to show will be, uh, tenant management.
So this will be for the callier, obviously, that would apply to, uh, an MSP, uh, with a server who, which will want to manage their customers. But it could also be like, uh, like an enterprise, like a, yeah, large enterprise or government entity that want to have an IOT talent, uh, to really segregate, uh, the, the, the traffic for iot. Then I could manage my, my tenant say, okay, first I could select, okay, does it do SD one?
Does it do SSTI can, you know, enable, disable the capabilities, uh, for, for my tenant or, or my customer. And for sst, for example, what I wanted to show was that, okay, I can select what would be the bandwidth for this user, uh, and things like this. And I could select, for example, my iot tenant.
I could give him like a dedicated gateway. So I will have my list of gateways that I deployed in my different, uh, in my different data centers. And I will say, Hey, okay, so this iot talent, I want to enable this, this, this, uh, gateway that will be very dedicated to him.
While the other gateways, I will perform my regular user traffic. So I could really manage my, uh, status solution, adding gateways, creating group groups. This would be like, uh, yeah, you can create regions so that, uh, you can group your gateways into regions.
If I add some, uh, gateway so that then I can decide, hey, I have my new gateway. I can say, Hey, this tenant can use this amount of bandwidth on my gateway so that you can also contain, uh, the talent of the customers from cannibalizing, uh, the bandwidth of each other. So we would have like a committed bandwidth, which is guaranteed, but also like allocated bandwidth where you could burst above, uh, your committed bandwidth so you can manage other subscriptions of the gateways.
Also, also doing this, you could decide what, what is IP pool that you'll use for? And so on. Really, really going into the management of what you would, uh, yeah, management of your, for your different customers.
Um, hi, I have a question. Carol Ries, I'm, I'm still struggling with the air gap concept. Um, when you have access to various cloud providers and various SSE services, why do you think that sovereign is air gapped?
I mean, I'm missing it. So the concept of air gapped is always very, um, enterprise or SP specific, um, in this scenario, right? This concerto, the director controller analytics, the entire ecosystem is on their network, and hence none, no one, no other customer of versa, of course, but not even versa can access that.
So that air gap part is because these five components apart from the data plane, are also sitting over there. So when he was displaying the analytics and this, this concerto, this entire, uh, uh, ecosystem or entire software stack, I shouldn't call ecosystem is sitting on the hardware of their choice data center of their choice, and it's separated from everyone. So that's what we meant by air gap.
Unless, unless you had any other related question about why, why, what's, what's the definition of air gap that, that we say over here? I have, I have a comment, but I don't wanna Go ahead. Go ahead.
So like, air gap is one of those very heavily charged words, especially if you come from A-U-S-D-O-D context, air gapped really means air gapped. This doesn't really mean air gapped in that context. It, it's what we used to call building a network.
It's on your own equipment, you control it, you manage it, you're still engaged with the, uh, technology provider for software updates, bug fixes, you know, CVE resolution and so forth. So I think that's a mental thing that like, fair Enough, We understand your caveats around what you mean by air gapped, but like I get, I can the context. Yeah, that's fair.
I can tell you without sharing more information online, that, um, when it comes to defense organizations, sure. They, they do take it to that level. And, and when I'm, when I'm building my own network infrastructure, that's absolutely one way I can do that.
So yeah, I don't need to persuade me of that. Got it. But yes.
Um, so when we say air gap, complete disclaimer, it's not about that true pure sense of air gap that you were talking about. Uh, but when, then when certain organizations pro, uh, procure the solution from us, they go with that pure, uh, air gap solution to the personnel level. Um, yeah.
Yes. Uh, I liked the observation made earlier about, uh, the personas that you're dealing with that's evolving. And, uh, are you basically, uh, now talking to, um, I guess, uh, just like a new, um, sets of personas like the Chief AI officer?
Yes. Okay. Yes.
Any, any, yeah. Uh, uh, Yes, it's a very, uh, a very interesting, uh, interesting question. So Chief AI Officer is a new, new title in the first place.
Um, so what we are seeing is, um, you will be surprised sometimes even the CHRO is on the table because how do, how do these employees behave and what AI tools they want to use, they want to deploy, it's becoming a huge concern. So chief ai, officer CO are these days tied to the hip? Because now you're talking about, um, um, security from a perspective of AI too.
And a lot of times in the conversations, very similar rooms like these, they have not come to the table with any kind of sovereignty in mind, but as soon as this conversations, uh, arise and they talking to each other, not even to us, and they're like, whoa. And then we say, Hey, can we, can we talk to you about sovereign assay? And they're like, now, now we are talking even more.
So the most interesting part for a vendor like us is to even get them to understand what kind of capabilities does a solution have? Because since last 10, 10 plus years, they are used to, oh, sassy, I consume it from cloud, I pay by the user, I consume it from the cloud. We didn't touch upon a whole lot over here too, but the, uh, uh, Adrian did a little bit is we do it in an aggregated way too.
You have your entire network, entire set of, uh, requirements. Just consolidate it on our on, on, on your SSE, but on a bandwidth basis, you don't even have to go pay me for the user, because that's not what, what our go-to market model is. But that's a, that's a different, uh, subject.
Um, there was another question that came on SS e and sim, I guess, uh, um, I, I'll, I'll quickly touch upon that. So, um, the, the mobile solution, so you take the Sovereign Sass e but now the biggest use case is Clientless mobile users. So what we do is we integrate it with the whole packet core of the service providers.
Adrian is spot on that it is mainly for service providers, obviously, because they're the wireless service providers, and it's all integrated within the core network. So now we are not talking about every user starting an IP SEC tunnel to the gateway and doing it that way. It goes to 1, 1 1 location, their core network, and then it's, uh, all the policy enforcement is done over there.
But that's a game changer because now you have the MZ mapping and all that, uh, stuff that you've implemented with Service Bros. So, um, go ahead. Just to maybe take this in a slightly different direction.
With your engagements here with large enterprises or, or even small medium, what are you seeing in terms of requirements for controlling chat AI tool access? Um, they are two extremes. The one extreme, which I don't think is sustainable, uh, or at least not sustainable now, is just block it.
You know, I, I don't want, I don't want my guys to use it, but it is tremendous pressure that SMB mid-market, maybe BA based on the vertical, you will get away with that strategy. Every large enterprise is almost almost out of that realm, right? So in that space, these kind of solutions become even more important because now they're saying, I'm going to selectively block it.
Uh, or, or otherwise, I'll give you an example. Um, there is a development engineering development organization to optimize my code. I'm putting the whole code on chat g PT as an example, and I'm thinking, I'm, I've done my job with an optimal code, but guess what you've done?
You've given them the whole ip, right? So those kind of use cases fall into the CASB, uh, mm-hmm. Uh, use cases for the sovereign SASS e as well.
So then the other, other chapter to that book is the, the sovereign AI controls with having some on-prem models and, um, which data goes where. Mm-hmm. And this, this, um, infrastructure becomes a brokerage, uh, you know, clearinghouse at that point.
Okay, you know what, these go internally. This, it's not so, uh, risky. I'm letting it go outside.
It's just asking for how to make the best coffee for the, for the, you know, for the upcoming, uh, holiday party. No problem. So, um, that is actually also one of the chief AI officer comment was very interesting.
It's because now they're putting together the, these, um, uh, controls in place for which they need as much control on what happens, uh, with them, rather than just relying on the cloud vendor. How much guidances do you give customers on which hardware to run if they wanna deploy? Ah, uh, very, very precise.
So we have two flavors. If they wanted to go with a Versa branded hardware, we have one-to-one mapping for what you need in terms of feature functionality capabilities, and, um, and, uh, uh, uh, the throughput, um, depending on the features. And then if they wanted to go on the cloud, uh, there is a virtualization tax, uh, uh, right?
And then the third option, of course is the off the shelf hardware, which we've been as versa have been doing forever. So we have very well defined guidelines. To answer your question, it's fairly precise.
Okay. So the sovereign sass e you know, customer can feel comfortable, yes, I'm gonna deploy it in my infrastructure, so I need to make sure that Yes. Now one very important asterisk or or caveat that we tell them is if you be, if you go wild, wild west, the Nest next WI Bank, um, um, uh, virtualization platform that you want to try, we won't guarantee the performance.
Okay? And more, more often than not, they're, they're, they're very, uh, everyone understands that you can't just put it on any, any hardware and it'll just work, right? So we guide them with these three flavors, and depending on their needs, generally, if they, if they, sometimes they go with the private VPC in AWS or somewhere, then we have guidance for that then or Versa, branded is plug and play and then there is off the shelf, but we provide precise guidance.
Okay. Is it just, uh, requirements like in terms of hardware or computer or compute resources, or do you actually work with certain vendors and have like versus certified? Uh, both, Both.
But, but let me, let me split that hair a little bit. Let's say if your, you know, SSL decryption needs and your specific data analysis needs is different, then it's a little bit more open. Uh, for example, there is one big organization that is, that's heavily ZTNA only, that's much easier use case when it comes to, um, um, uh, as compared to say A DPI use case on IPSI ideas and so on.
So to answer your question, we have Versa certified, uh, appliances, both Versa branded and and other vendors that fits in. We have e extreme amount of benchmarking of what services that, uh, that you want to enable on those. And then when it comes to some basic use cases, you could open it up to a lot other platforms and, um, even the cloud vendors.
So that's, those are the two, two simple li lines of demarcation where, what kind of services you need, but we have Versa branded and off the shelf. And do you have, um, a program where you would work with a service provider to certify Yes. Hardware?
Yes, we do that. We do that all the time. Uh, but that needs scale and service providers the right profile for that.
Generally an enterprise would not tell us to do that, uh, unless they have some humongous contracts with a specific vendor and we don't support. But look, we've been around for 12 years and the VOS fundamentals have been same. So the advantage of that is there are a lot of, lot of common vendors that are already certified.
Very rarely will come across with someone who says you wanna come something completely different at that point, will work with them to certify, depending on the scale, of course, it becomes a business decision at some point. Then Alongside, uh, prompt poisoning, uh, returning that question, another hot topic, at least at the recent NWC 25 event, uh, is, uh, API security. And from your perspective, is this something that's also integral to Yes and API, these, these gateways actually sit right in front of the API gateways.
So a lot of times when I said nearness to your application, right? That is one of the nuanced flavor that I want my SSC gateway to be sitting right where my rest of the network is even, even, um, the Sion SIM solution, right? The packet, I'm having my Versa gateway sit right next to my packet core, so that day, every packet coming comes in, of course, once I can upsell my service, but every packet is being secured in a certain way at, to a certain degree.
Pretty reassuring. So I know it just turned red. So I will give you back the floor, Tom.
But, uh, thank you. And, and I'm around here for more questions.