ConnectaSec Guest
The secure access for vendors and auditors that no VPN on the market offers.
A portable, install-free binary that grants temporary, scoped access to your network — and leaves an auditable trail of everything the visitor touched, without collecting anything from their device.

Today's problem
Classic VPN
Installer, drivers and admin rights on the vendor's laptop — often a personal PC or one belonging to a different company.
Sharing internal credentials
The vendor ends up with permanent access nobody revokes, and broader privileges than needed.
Bastion or web-based RDP
It works, but only for limited cases; no arbitrary protocols, no using the vendor's own tools.
AD "guest" user
Nobody decommissions it, the audit trail is poor, and it opens up too much of the network.
What ConnectaSec Guest is
A single ~150 MB portable .exe — no installer, no service, no persistent drivers.
No permissions beyond what's needed to bring up the tunnel while it runs.
One auth key per session, with bounded lifetime and scope enforced by ACLs.
Ephemeral node: as soon as the window closes, it disappears from the control plane.
ACL-bound scope: it only reaches what the customer has explicitly authorized.
The detail no VPN on the market offers
What is NOT collected from the guest's device
- ❌Hostname
- ❌Software inventory
- ❌Antivirus / device posture
- ❌OS version
- ❌Client logs
- ❌Client auto-update
What IS collected from traffic into the customer
- ✅Network flows to internal resources
- ✅Destination address, port and protocol
- ✅Connection volume and duration
- ✅All tagged with the customer's tenant
No commercial VPN draws this line: they either audit everything, or nothing. Guest is the honest middle ground — full audit for the customer, full privacy for the vendor.
Who it's for
IT vendors and contractors
Maintenance, installations, occasional deployments.
Internal and external auditors
Reviewing systems for a bounded period.
Consultants
Projects with a defined timeline.
Third-party support
Critical-application vendors who must connect to the customer's server.
External DevOps teams
Migrations, go-lives, load tests.
For the customer (who grants access)
- Generate the key in the console and the vendor is in within a minute.
- Real-time audit of everything the vendor touches on the network, from the ConnectaSec panel.
- When the vendor closes the window, access ends on its own — no manual revocation.
For the vendor (who receives access)
- Installs nothing on their PC.
- Shares no data about their device.
- Leaves nothing behind when the session ends.