Zero-trust network access · Commercial vs open

Zscaler's zero-trust access model — the free, self-hosted version.

Zscaler is a leading commercial platform for reaching private apps without a VPN. The same core protections — apps hidden from the internet, identity-based least-privilege access — run on OpenZiti, self-hosted and free, with your traffic never leaving your control.

Capability
Zscaler (ZPA)
Your setup — Ziti Self-hosted · Free
Reach private apps, no VPN
ZscalerZscaler Private Access
ZitiZiti services — same outcome, no VPN
Apps hidden from the internet
ZscalerApp Connectors — no inbound exposure
ZitiDark services — no open ports at all
Identity-based least privilege
ZscalerPer-app access policy
ZitiPer-service policy, cryptographic identity (mTLS)
Encryption
ZscalerEncrypted through Zscaler's cloud
ZitiEnd-to-end mTLS across your own overlay
Where your traffic goes
ZscalerTransits Zscaler's global cloud
ZitiStays on your own infrastructure — no third party
Cost model
ZscalerPer-user subscription
ZitiFree & open-source — you own it

Fair comparison: Zscaler is turnkey and globally managed, with integrated inspection, DLP, and support built in. Ziti is free software, but someone has to run it — controller, routers, updates. The cost moves from a subscription to operations and expertise (which is what we provide).

The point

Same zero-trust principles, self-hosted. You own the whole path, nothing transits a vendor's cloud, and there are no per-seat fees — you pay for the setup and management, not a license.

Mapped from Zscaler's public ZPA documentation and OpenZiti. Comparison is directional, not a certification claim.