Secure Access Service Edge

An office security management platform that integrates zero trust network access, office data protection, and terminal management.

Why SASE?

Secure Access Service Edge (SASE) allows enterprises to enable zero trust access over an internal network. SASE can also help prevent data leaks, control and audit operations, and accelerate secure access. This way, enterprises do not need to invest in complex and expensive security hardware.

  • Flexible Access

    SASE provides software-as-a-service (SaaS) access points that are globally distributed. SASE also allows you to build self-managed access points based on business requirements in the cloud, data centers, or hybrid environments. This way, employees can access office applications anywhere and anytime in a flexible and secure manner.

  • Simplified Security O&M

    The one server and one agent architecture of SASE reduces the costs of security O&M. Enterprise administrators need to only maintain a security management center, and employees need to only install the SASE client. This implements end-to-end data monitoring in an efficient manner, improves the efficiency of security O&M, and simplifies the installation of the SASE client.

  • Intelligence and Efficiency

    SASE introduces multiple foundation models including Qwen models to greatly improve the accuracy of DLP strategies in security O&M scenarios. In addition, the intelligent routing feature ensures optimal routes for employees to improve their work experience.

Scenarios

Zero Trust Network Access (ZTNA) - Secure Global Office

SASE provides a VPN-free solution for enterprises to implement zero trust network access around the world based on the zero trust network access architecture and the globally distributed network nodes of Alibaba Cloud. You can use SASE for remote work and acceleration, and the management of outsourcing projects, service providers, shops, supermarkets, and after-sales service sites.

Identity-driven Security Policy
Supports the integration with mainstream identity services and single sign-on (SSO) authentication systems. You can configure zero trust policies based on the organizational structure of your enterprise or employee accounts in Windows Active Directory (WindowsAD) or Lightweight Directory Access Protocol (LDAP), DingTalk, WeCom, Lark, or IDaaS.
Global Office Acceleration
Accelerates the access to office applications based on the globally distributed network nodes, high-quality Border Gateway Protocol (BGP) network resources, and Alibaba Cloud services such as Cloud Enterprise Network (CEN) and Global Accelerator (GA). This allows all employees to access office applications with ease.
Fine-grained Access Control
Supports identity-based access control policies. You can configure security policies based on domain names and ports, or IP addresses and ports.
Agentless Access
Provides the agentless zero trust access mode for outsourcing projects or third-party service providers. This allows employees to directly access office applications on internal networks by using browsers.
Visualized Network Monitoring
Supports the end-to-end network diagnostics feature. Security administrators can view the real-time status of each network node in a digitalized manner.

Private Access

Module
Type
Price
Private Access Basic Edition USD 5.5 per account quota-month
(The minimum account quota that you can purchase is 100, you can purchase Private Access in increments of 10)
Buy Now
Value-added Service Log Storage USD 40 per 500 GB-month
(You can purchase Log Storage in increments of 500 GB.)
Buy Now

Sensitive Data Leak Prevention (DLP) - Protection of Core Assets

SASE provides an integrated office data protection solution for the core assets of enterprises based on the internal practices of Alibaba Group. You can use SASE to quickly build a data security governance and operations system.

Risk Governance
Allows administrators to detect domain names and software that may cause risks and manage peripherals. This allows administrators to prevent data leaks that may exist in non-office channels, improve the approval process, and quickly apply security control policies.
Asset Plotting
Automatically scans the core assets of enterprises and analyzes the distribution of assets. This helps the data security operations team monitor the real-time status of sensitive data.
Intelligent Classification
Provides the intelligent classification feature based on foundation models such as Qwen models. Recommended policies are generated based on the results of asset plotting. Security engineers can manually modify policies or enable the system to automatically modify policies based on subsequent monitoring results.
Management of Outbound Sensitive Data Transfer
Allows administrators to configure security policies and the sequence of request approval and data transfer based on the sensitivity level of data and the identities of users who want to access the data. Administrators can trace the access to data based on detailed audit logs.
Digital Watermarks
Invisible watermarks of Alibaba Cloud are robust and hardly visible. You can add invisible watermarks to your screen or web pages. This prevents data leaks due to photo taking or capture.

Internet Access

Module
Type
Price
Internet Access Internet Access DLP Edition USD 4.5 per account quota-month
(The minimum account quota that you can purchase is 100.)
Buy Now
Value-added Service File Storage USD 75 per TB-month
(The minimum file storage capacity that you can purchase is 1 TB.)
Buy Now
Value-added Service Log Storage USD 40 per 500 GB-month
(You can purchase log storage in increments of 500 GB.)
Buy Now
phone Contact Us