Hardware appliance
A fanless desktop or rack-mount appliance for branch, retail, and factory sites. Zero-touch provisioning means it is unboxed and powered on by site staff, not an engineer.
COSGrid ReFleX-Edge is the SD-WAN gateway of COSGrid ReFleX-WAN, COSGrid's SD-WAN solution. It is deployed at branch offices, factories, retail stores, data centres, or cloud environments to connect multiple WAN links such as broadband, MPLS, DIA, 4G/5G, and Wi-Fi. ReFleX-Edge intelligently selects the best path for each application to ensure reliable and high-performance connectivity.
Branch offices, factories, retail stores, data centres, or cloud environments.
Multiple WAN links such as broadband, MPLS, DIA, 4G/5G, and Wi-Fi.
Hardware Appliance
Virtual Machine
Cloud All managed centrally through the COSGrid Guider controller, with the same management experience across all deployment models.




The appliance is shipped or the image is booted, and it calls home to the COSGrid Guider controller over any available link. It authenticates with a device certificate, pulls its site configuration, and comes online without an engineer on site.
ReFleX-Edge brings up all available underlays simultaneously — broadband, DIA, MPLS, 4G/5G, Wi-Fi — and treats them as an interchangeable pool rather than a primary and a standby. There is no idle backup circuit.
ReFleX-Edge builds encrypted tunnels across every active transport to the nearest PoP or data center, forming a resilient mesh that survives individual link degradation or failure.
Traffic is continuously steered per-application across the healthiest available path based on real-time latency, loss, and jitter measurements — not just link up/down status.
Every ReFleX-Edge device, regardless of deployment form factor, is managed, monitored, and updated from a single COSGrid Guider console with consistent policy enforcement.
ReFleX-Edge is delivered in three form factors that share a single configuration and policy model, so a policy written for a branch appliance applies unchanged to a virtual appliance in your data centre or a cloud image in AWS.

A fanless desktop or rack-mount appliance for branch, retail, and factory sites. Zero-touch provisioning means it is unboxed and powered on by site staff, not an engineer.

A VM image for KVM, Proxmox, OpenStack, and standard enterprise hypervisors—for data centres, colocation, and sites that already run a virtualisation host.

Native AWS and Azure images built for each cloud’s accelerated networking path rather than converted from a generic disk image, providing native performance.

COSGrid Guider
COSGrid ZGrid
COSGrid SAR
COSGrid MZA App Client
MicroZAccess & ZT-NACCOSGrid Guider (management plane) provisions and configures every ReFleX-Edge with zero-touch over an encrypted, mutually authenticated control channel. It securely pushes signed policies that every edge verifies before applying. Telemetry such as latency, loss, jitter, SLA status, and faults continuously streams back to Guider for centralized monitoring.
COSGrid ZGrid provides the distributed cloud backbone for ReFleX Edge. It interconnects branches, cloud workloads, and data centres with secure encrypted overlays, ensuring low-latency connectivity and resilient routing across geographically distributed locations.
COSGrid Security Analyser & Responder continuously receives telemetry from every ReFleX Edge. Using behavioural analytics and machine learning, it detects anomalies, performs threat hunting, and orchestrates automated responses through integrated policy enforcement.
The COSGrid MZA App Client securely connects remote users to enterprise applications through ReFleX Edge. It authenticates users and devices, establishes encrypted connectivity, validates device posture, and enforces Zero Trust access policies before granting application access.
MicroZAccess and ZT-NAC integrate with ReFleX Edge to provide Zero Trust Network Access and Network Access Control. They continuously verify user identity, device posture, and security compliance before allowing access to enterprise resources while maintaining a unified policy across the entire COSGrid architecture.
Application-aware path selection
All transports, all active
Next-generation firewall on the same box
Zero-touch deployment
Any form factor, one policy
The orchestrator; it provisions ReFleX-Edge with zero touch and pushes its signed policy over the control channel.

The SASE PoP fabric where ReFleX-Edge terminates its encrypted overlay to reach the Internet, SaaS, and other sites.

ReFleX-Edge is its branch gateway; ReFleX-WAN is Guider + the ReFleX-Edge gateways + the ZGrid PoPs as one solution.

The Mesh ZTNA service the client is the endpoint for; the client is how a user’s device joins the MicroZAccess overlay.

Shares the client’s posture engine; the same device-hygiene checks gate both ZTNA access and NAC admission.
Necessary Cookies
Performance Cookies
Targetting Cookies
Functional Cookies