Architecture
A glass box, not a black one.
Every customer runs its own environment: an edge, the Inlinea server, the Control Center, the Workspace, the ZERA gateway and the session engine. Follow one request through them and see which component decides what.
The request path
One connector dials out. Nothing opens inbound.
An HTTPS request from a browser to a private application, step by step, and the agent path beside it.
Inlinea server
- Browser
- Edge
- ZERA gateway
- Encrypted private network
- Connector
- Application
Step 1 of 10
The browser resolves the resource's address to your tenant and opens an HTTPS connection.
One connector dials out. Nothing opens inbound at the private site.
Components
What runs in your tenant
| Component | Responsibility |
|---|---|
| Edge | Public entry, platform TLS and hostname routing; forwards protected hostnames to the gateway without reading them |
| Inlinea server | API, identity, policy, signalling, relay and STUN; the one place policy is decided |
| Control Center | The administrator application; a client of the server with no database of its own |
| Workspace | The end-user portal; shows only what the person is approved to open |
| ZERA gateway | Resource TLS, user authentication, policy enforcement and the encrypted private path to the application |
| Session engine | Renders RDP, SSH, VNC and Telnet for Secure Sessions; reachable from the gateway only |
Trust boundaries
Which component decides what
| Component | Trusts | Cannot do |
|---|---|---|
| Edge | Hostnames and certificates | Reach a private application: it has no mapping to one |
| ZERA gateway | Identity, policy and the service mapping from the server | Open a path before the policy decision; the decision comes first |
| Encrypted network client | The authenticated peer at the destination | Reach anything the policy did not grant |
| Destination connector | The private network it was enrolled into | Decide which browser user is authorised; that was decided before it was dialled |
| Browser | The resource's certificate | Address the private application directly; it is not exposed |
Encryption and visibility
What Inlinea can and cannot see
- Agent pathEncrypted end to end between devices. Inlinea cannot read it; a relay forwards packets it cannot open.
- ZERA pathThe gateway in your tenant terminates TLS by design, to authenticate the person and enforce policy, then reaches the application over the encrypted private network.
- Control planeIdentity, policy, signalling and logs, in your tenant. What leaves a device for Inlinea is control traffic, never application payload on the agent path.
Network surfaces
Ports a tenant exposes
| Port | Protocol | Purpose |
|---|---|---|
| 80 | TCP | Redirect to HTTPS |
| 443 | TCP | Platform HTTPS, the Workspace, the Control Center, and protected hostnames passed to the gateway |
| 3478 | UDP | STUN, for direct device paths |
| 51820 | UDP | The encrypted private data plane |
Custom TCP and UDP services use a reserved, published port range you decide on. The session engine listens on the gateway's loopback only.
Questions buyers ask
Is anything shared between customers?
Images are shared; environments are not. Each customer's server, Control Center, Workspace, gateway and session engine run in that customer's own tenant with their own data.
Why does the gateway terminate TLS?
To know who is asking and to apply policy to the request. That is the design of agentless access: the gateway in your tenant is the policy enforcement point for the browser path.
Where is the full detail?
The Trust Center publishes the security overview, what we can and cannot see, every outbound connection and the data residency facts.