What is COSGrid ZGrid?
When most applications lived in the corporate data centre, sending branch traffic back there to be inspected by a firewall was efficient. Now that most traffic goes to SaaS and public cloud, backhauling means sending a packet away from its destination to be inspected and then back again — a detour called hairpinning that adds latency to every session. A PoP-based architecture removes the detour: each site and user connects to the nearest cloud point of presence, and inspection happens there, close to the user and close to the internet exit, while policy stays centralised.
BUILT IN
DEPLOYED AT
ZGrid is that fabric for COSGrid. It is a separate component from the branch gateway because its job is different: ReFleX-Edge secures one site at its physical edge, while ZGrid is the shared cloud tier where traffic from many sources — branches, remote users, cloud workloads, even third-party routers — lands and is inspected together, under one policy, before egress.
CONNECTS
Inside each PoP, firewall, web filtering, application control, intrusion prevention, inline CASB, and DLP run as a single-pass engine: a flow is decrypted and examined once, against one policy decision, rather than being handed from product to product with latency and disagreement at every hop.
AVAILABLE AS
India-Resident PoPs
Self-Hosted / Air-Gapped How ZGrid Works
Anycast and GeoDNS send each site, user, and workload to the closest available PoP.
IPsec from ReFleX-Edge or a third-party router, an encrypted tunnel from the MZA App Client, or a cloud-connector attachment — all land in the same engine.
The PoP builds a single flow record carrying user identity, device posture, application, and destination category.
Firewall, web, IPS, CASB, and DLP policy are evaluated against that one examination; TLS is decrypted selectively via a per-tenant CA with bypass lists.
Allowed traffic exits directly to internet/SaaS/site; high-risk web is redirected to isolation; one log record is written and streamed to compliance reporting, SAR, and (optionally) your SIEM.
Role in the COSGrid Architecture

COSGrid Guider
COSGrid ReFleX-Edge
COSGrid MZA App Client
COSGrid SAR
MicroZAccess (ZTNA) and ZT-NACCOSGrid Guider
COSGrid Guider (management plane) configures and monitors every PoP over an encrypted, mutually-authenticated control channel, pushing signed policy each PoP verifies before applying, and collecting its telemetry and running state.
COSGrid ReFleX-Edge
COSGrid ReFleX-Edge terminates its encrypted SD-WAN overlay on the nearest ZGrid PoP — the branch is one of the traffic sources the PoP inspects. Any third-party router speaking IPsec or GRE can also land on a PoP, so ZGrid does not require COSGrid at the branch.
COSGrid MZA App Client
COSGrid MZA App Client tunnels remote users to the nearest PoP, so an off-network user gets the same inspection and policy as a branch.
COSGrid SAR
COSGrid SAR consumes the flow, session, and threat telemetry the PoPs produce to baseline behaviour and detect threats, and automated responses are applied back at the PoP.
MicroZAccess (ZTNA) and ZT-NAC
Together with ReFleX-Edge, ZGrid is where MicroZAccess (ZTNA) and ZT-NAC (NAC) access decisions are enforced in the cloud tier — one policy plane across SD-WAN, SASE, and access.
Key Features of COSGrid ZGrid
Single-pass inspection
Enforcement close to the user
India-resident, sovereignty-ready
Lands any source
Session continuity and resilience