FLAGSHIP · 01

TruWorkspace
Zero Trust™

Every device, every user, every app — and every AI agent — continuously verified. Zero Trust security delivered as a fully managed service, built on Canada's only sovereign private cloud.

ModelZero Trust Network Access
Deploy4–6 weeks
Scale25 → 2,500 users
Managed24 / 7 Canadian SOC
A Canadian team weighing modern collaboration options
FROM PERIMETER TO IDENTITY
The problem

Your people are everywhere. Your data is in the cloud. Your old security model was built for neither.

Perimeter-based security was built for a world where everything lived behind the office firewall. That world is gone. Today your team works from anywhere, your apps live in the cloud, and AI tools are already inside your business — whether IT knows about them or not. Traditional VPN and firewall architectures weren't built for this. Zero Trust was.

The TruPoint approach

Verify everything. Assume nothing. Manage it all for you.

TruWorkspace Zero Trust wraps every user, device, and application in continuous verification. Identity, device health, network context, and data behavior are checked on every access request — not just at login. We deploy it, we manage it, and we prove it's working through your compliance dashboard.

The architecture

Three continuous disciplines. One managed service.

The TruWorkspace architecture is built around three things that happen continuously — not just at login, not just during an audit.

01Continuous Verification

Who are you — and should you be here?

Every request is checked against identity, device health, network context, and risk signals. Continuously — not just once at login.

SSEIAMUEM
Cloudflare + Entra + Intune
02Continuous Protection

Is anything threatening you right now?

Threats are hunted across endpoints, data, and browsers in real time — detected, contained, and responded to before they spread.

XDRDLPRBI
ESET + Purview + Cloudflare
03Continuous Compliance

Are you audit-ready and insurable?

Live evidence is collected against your frameworks so you're always audit-ready — and so your cyber insurance renews.

GRCSIEMSAT
ISMS + vCISO · via TruCompliance
POLICY · EVALUATED · EVERY REQUEST
What's included

Six capabilities. One managed service.

Each capability is named for what it does for your business — the technology that delivers it is the evidence, not the headline.

01

Security Service Edge (SSE)

Your network perimeter, rebuilt in the cloud. Cloudflare One routes all device traffic through a security layer that inspects every connection before it reaches your apps or data — whether that's Microsoft 365, a private server, or a SaaS tool your team signed up for last week.

  • Cloud Access Security Broker (CASB)
  • Remote Browser Isolation (RBI)
  • DNS filtering + DLP at the network layer
02

Identity & Access Management (IAM)

Identity is your new perimeter — and it's enforced on every request, not just at login. Microsoft Entra ID governs who gets access to what, using risk signals, device health, and location context to approve or block continuously.

  • Passwordless MFA · passkeys · Windows Hello
  • Conditional access policies
  • Identity governance and lifecycle
03

Unified Endpoint Management (UEM)

Devices that don't meet your security baseline don't get in. Microsoft Intune enforces device compliance before access is granted. NinjaOne keeps every device patched, monitored, and healthy — automatically.

  • Corporate MDM · BYOD MAM
  • Automated patching across all platforms
  • CIS-hardened device baselines
04

Extended Detection & Response (XDR)

Advanced threats don't announce themselves. ESET XDR continuously hunts across your endpoints, feeds telemetry to our SIEM, and triggers our Canadian SOC to respond — typically within one hour of detection.

  • Behavioural NGAV · EDR telemetry
  • SIEM integration + SOC-led response
  • 24/7 Canadian analysts, not offshore tier-1
05

Data Loss Prevention (DLP)

Zero Trust controls what leaves, not just what comes in. Microsoft Purview and Cloudflare SSE enforce DLP at the application and network levels — blocking unauthorized sharing of sensitive data, whether it's headed to a personal email, a USB drive, or an AI tool.

  • Application-level DLP (Purview)
  • Network-level DLP (Cloudflare SSE)
  • Immutable backup · <24h RPO
06

AI Security Suite

Your team is already using AI. The question is whether IT has any visibility. We provide controls for workforce AI use, protect AI-backed applications, and extend Zero Trust to AI agents — so your business can move fast with AI without handing over its data.

  • AI prompt DLP — blocks sensitive data in prompts
  • Shadow AI discovery — see what tools are in use
  • Agentic AI controls (MCP, API least-privilege)
In plain language

Two acronyms doing the heavy lifting.

CASB and RBI come up constantly in Zero Trust conversations. Here's what they actually do for your business — no jargon.

A firewall for your cloud apps

Cloud Access Security Broker (CASB)

Your traditional firewall guards the office, but it can't see inside Microsoft 365, Salesforce, or the apps your team signed up for last Tuesday. A CASB continuously polices your cloud applications — enforcing who can view, download, or share your data, and shutting down Shadow IT before it becomes a breach.

  • Blocks sensitive data downloads on personal devices
  • Discovers and controls unsanctioned apps (Shadow IT)
  • Detects account takeover behavior in real time
Browse the web without touching it

Remote Browser Isolation (RBI)

Every website your team visits is a potential threat vector. Remote Browser Isolation runs the browser session inside a secure cloud container. Ransomware, malware, and phishing attempts detonate safely in the cloud — nothing executes on your device. When the tab closes, the container is destroyed.

  • Zero-day and ransomware protection at the browser
  • Phishing links open in isolation, not on devices
  • Full DLP controls on isolated sessions — no copy-paste, no download
Outcomes

What changes, and what it's worth.

VPN replaced
100%

Clients typically retire legacy VPN within 30 days of cutover, reclaiming licence spend and removing a top breach vector.

Attack surface reduction
~80%

Measured against open-port and identity-assertion baselines using Cloudflare Analytics + Entra ID risk signals.

User friction

Passwordless + SSO removes 40+ logins per user, per week. Support desk password-reset tickets typically drop by 70%.

How we deploy

Four to six weeks. No big-bang migration.

W1

Discovery & baseline

Architecture review, identity audit, device inventory. We document the as-is and agree the target state.

W2

Identity & edge pilot

Entra ID tenant hardening, Cloudflare tenant provisioned, pilot user group cut over to ZTNA.

W3-4

Endpoint enrolment

Intune co-management, ESET + NinjaOne rolled out across all corporate devices. BYOD wave follows.

W5-6

Cutover & SOC handoff

Legacy VPN decommissioned, runbooks finalized, 24/7 SOC monitoring begins. TAM relationship begins.

Hands working on a laptop in a modern office
CLIENT · PROFESSIONAL SERVICES · 140 USERS

Our team gave up their VPN in two weeks and our insurance broker renewed us with a premium reduction the next quarter. TruPoint stripped out three legacy products and replaced them with one architecture we actually understand.

Daniel KwanDirector of IT, Canadian professional services firm · 140 users
Next step

Let's map your Zero Trust path.

30-minute discovery. We'll show you where you are and what a 6-week cutover would look like.

Book a Discovery Call See TruCompliance