NovaStack EdgeShield Zero Trust Network

Zero Trust Network-as-a-Service · Hosted in Malaysia

Nothing to attack, because there is nothing to find.

EdgeShield removes your public address and inbound ports entirely. Scanners find nothing to attack — while your staff reach the same systems exactly as before.

Running in production today
external scanner
nmap -Pn -p- customer.example.my
Starting Nmap 7.95 — 65535 ports
Host seems down. No ports found open.
 
curl https://customer.example.my
Could not resolve host
 
staff laptop — EdgeShield agent
Connected · 4 services reachable · 128 ms
The same network. From outside: nothing at all. From inside: fully working.

Why it is different

Six things a VPN and a firewall cannot do for you

Conventional defence guards an exposed door. EdgeShield removes the door, so there is nothing left to scan, brute-force, or exploit.

01

No public address

No public IP, no inbound ports. Connections are outbound only. Internet-wide scanners have no target to enumerate.

02

Keys stay on your devices

End-to-end encryption between your own devices. We carry already-encrypted traffic and hold no key that can read it.

03

Evidence for auditors

Every access is recorded: who, which device, which service, when. Twelve-month retention, CSV export, report-ready output.

04

Every device is its own island

Access is granted per device and per service. One infected laptop cannot crawl the network — there is no flat network to crawl.

05

Revoke in one click

Staff leave or a phone goes missing — revoke that device from the console and its access dies immediately, with no password reset to chase.

06

Data stays in Malaysia

Hosted in Malaysia by default, or deployed entirely inside your own premises when policy demands it.

The usual objection

“Isn’t this just a VPN?”

No. A VPN encrypts the road to a door that is still standing in public. EdgeShield removes the door.

Typical VPN
EdgeShield
Visible on the internet
Yes — address and port exposed to scanners
No — no address, no inbound port
Who holds the keys
Provider terminates encryption and can read traffic
Your devices only — we cannot decrypt
After one device is infected
Flat network — ransomware moves sideways
Contained to the services that device was allowed
Records for audit
Connection logs, rarely auditor-ready
Per-device, per-service trail with CSV export
Removing access
Rotate credentials and hope everyone re-enrols
Revoke the device — effective immediately

Post-quantum

Traffic captured today can be opened later

Attackers record encrypted traffic now and keep it until a quantum computer can open it. If your secrets must hold past 2030, that is a problem today, not later.

Where we actually stand

LivePost-quantum key exchange in production
NovaStack already runs hybrid post-quantum TLS on our own public services.
LiveFree readiness check
Test any website and see whether its key exchange is still classical.
RoadmapHybrid key exchange inside EdgeShield
Scheduled, not yet shipped. We do not label this product post-quantum until it genuinely is.

Malaysian context

NACSA and the Ministry of Digital published a National PQC Readiness Roadmap in October 2025 covering 2025–2030. It is a strategic framework, not a mandate — so each organisation carries its own migration plan.

“Bukan lagi satu pilihan, sebaliknya keperluan mendesak.” — Gobind Singh Deo, Minister of Digital, on the PQC transition.

Deployment

From sign-up to closed ports, in four steps

The order matters: public ports close only after every device is proven to connect. No planned downtime.

1

Your organisation is registered

We open an isolated space for your organisation. No other customer shares it.

minutes

2

Enrolment keys are handed over

Each staff member receives a one-time key for their own device. The key expires once used.

same day

3

Devices are connected

The agent installs on Windows, macOS, Linux, Android and iOS. About five minutes per device, with no change to how staff work.

~5 min per device

4

Public exposure is closed

Only once everyone is connected do the public ports close. From that moment, outside scanners see nothing.

no downtime

Specification

What you get

CapabilityDetail
Network exposureNo public IP, no inbound ports; outbound connections only
EncryptionEnd-to-end between devices; the operator cannot decrypt
Access controlPer device and per service, with isolation between organisations
Agent platformsWindows, macOS, Linux, Android, iOS, servers and network devices
Audit trailTwelve-month retention, CSV export, compliance reports
AvailabilityMonitored every five minutes with automatic recovery
BackupsDaily, retained for 30 days
Hosting optionsHosted in Malaysia, or deployed inside your premises
AdministrationWeb console with instant device revocation

Pricing

Per user, per month

No setup fee and no three-year lock-in. On-premises deployment is quoted separately.

Lite RM29/user 1–10 users
Business RM22/user 11–50 users
Enterprise RM18/user 51 users and above

Compliance

Built to the frameworks you are audited against

EdgeShield supplies the controls and evidence these frameworks ask for. Certification remains your organisation’s own — we supply the evidence, not the certificate.

PDPA Malaysia ISO/IEC 27001 BNM RMiT IEC 62443 MAMPU circulars

Next step

Watch your network disappear from the internet

We scan your public exposure today, put EdgeShield in front of one service, and scan again while you watch. No cost, no commitment.