| Primary job | App-level SSO, MFA, access policy, and audit for existing HTTP/HTTPS web applications. | Secure reachability to private apps and networks, often as part of a broader Zero Trust or SASE platform. |
|---|
| Data plane | Self-hosted in your environment; application traffic does not route through Datawiza's cloud service. | Often cloud-brokered through vendor points of presence, connectors, tunnels, or service edges. |
|---|
| Vendor cloud outage impact | Existing protected web-app traffic continues through the self-hosted data plane; management changes depend on the cloud control plane. | Depends on architecture; cloud-brokered access can make vendor service availability part of the traffic path. |
|---|
| Tunnel or connector | No outbound tunnel dependency; standard reverse proxy pattern for web apps. | Many products require connectors, publishers, tunnels, or service edges. |
|---|
| Endpoint agent | Not required for browser-based HTTP/HTTPS application access. | May require an endpoint client or agent depending on the product, protocol, and protected resource. |
|---|
| Legacy ERP login | Supported app-specific SSO patterns, including PeopleSoft PSSSOUID, Oracle EBS ICX session creation, and JDE_SSO_UID. | Often gates access but leaves the legacy application login experience intact. |
|---|
| Identity options | Works with Entra ID, Okta, Ping, Cognito, Auth0, Google, and Datawiza built-in MFA. | Varies by vendor and platform assumptions. |
|---|
| Non-web protocols | Not covered. Use full ZTNA for SSH, RDP, raw TCP, databases, thick clients, or broad private-network access. | Many ZTNA/SASE products cover non-web protocols and broader private access. |
|---|