SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Secure Network · Live

One network. Global. Secure.

SD-WAN on a private global backbone, encrypted end to end and app-aware, with underlay and overlay run as one by AI and Level-3 engineers. One accountable vendor from site to cloud.

Why it is built differently

Stop stitching the network to the security.

SD-WAN decouples your network from the physical line, bundling internet, DIA, 5G or MPLS into one encrypted overlay that puts business-critical apps first. The hard part was never the overlay, it was operating the underlay and the overlay together, across providers, without a queue of tickets. We do both: last-mile sourcing, a private backbone and the SD-WAN overlay, one managed service, one SLA, one team that answers for it.

500+Points of Presence on the private backbone
121backbone locations across 32 countries
Chinareliable connectivity in difficult, regulated regions
End to endSLAs on availability and traffic quality, site to PoP to PoP
The network as an asset

A network that learns your traffic.

Because we operate the whole path, every packet is telemetry. Thirty-five years of running networks feeds the AI that predicts congestion, reroutes around trouble before users notice, and hands anything consequential to a Level-3 engineer. No L1, no L2. Sovereign by design, with data residency you can put in front of an auditor.

Straight answers

Questions about the network.

What network teams ask before handing over the underlay as well as the overlay.

What is the difference between the underlay and the overlay, and why does it matter?

The underlay is the physical transport: internet, dedicated lines, 5G or MPLS from whichever carriers serve each site. The overlay is the encrypted, app-aware SD-WAN fabric that runs across it. Most vendors sell you the overlay and leave the underlay to you, which is where the finger-pointing starts. We source and operate both, under one SLA, so there is one team to call when a line in one country misbehaves.

Do we have to give up our existing carriers?

No. Last-mile sourcing is carrier-agnostic: we can take over your existing circuits or source new ones, and a site can bundle several transports at once. Being independent of the physical line is the point of SD-WAN, and it is also what makes a staged migration possible instead of a rip-and-replace.

Is a private backbone actually better than the public internet?

For long-haul and for regions where the public internet is unpredictable, measurably yes. 500+ points of presence across 121 backbone locations in 32 countries mean traffic enters a managed path close to the site instead of taking whatever route the internet offers that morning, and availability and traffic quality are covered by end-to-end SLAs from site to PoP to PoP.

How does this work in China?

With in-country connectivity built for exactly that case, which is why China gets its own line in the numbers above. Reliable, compliant access from mainland sites to global applications is a recurring reason customers move to the backbone; the China solution page sets out what is involved.

Which applications get priority, and who decides?

You do, at the level of app, site and connection. Bandwidth control and path selection enforce those decisions per policy, and application optimization handles the links that are simply slow, with caching, compression and protocol tuning. What we bring is the operational read on what your traffic actually does, because we run the whole path.

Is site-to-site traffic encrypted by default?

Yes. Encryption and authentication for site-to-site traffic are automatic rather than a project: keys and tunnels are managed by the platform, not maintained by hand in a rulebase. That is deliberate, because the encryption people skip is the encryption that was inconvenient to set up.

Do we need your hardware at every site?

A SASE edge appliance is the usual deployment, in four sizes plus a server option with RMA included, and it is priced per appliance and month under Foundation on the pricing page. Small and cloud-only locations can be reached without one, and mobile and roaming users come in through the Mobile Entry Point instead.

How is the network itself made autonomous?

Because we operate the whole path, every packet is telemetry. Thirty-five years of running networks feeds AI that predicts congestion and reroutes around trouble before users notice, and hands anything consequential to a Level-3 engineer. The network stops being a thing you watch and becomes a thing that reports to you.
Replace MPLS

Legacy circuits to the private backbone.

A staged migration from MPLS or DIY SD-WAN, run by Level-3 engineers, with no drama and no downtime.

See migration
Already a customerEverything you use today keeps running.