KeyStone now offers Timus SASE — zero trust access that replaces your VPN
September 18, 2026
A VPN asks who you are one time. Someone types a password at 8am and the tunnel trusts that session for the rest of the day — the same access whether the laptop is sitting on your office network or a hotel Wi-Fi, fully patched or three months behind, in the hands of your employee or someone who phished them.
Meanwhile your cyber-insurance renewal wants to know about MFA and network segmentation, and somebody on your team is filing another ticket because the VPN dropped again. We've added Timus to our managed security stack to deal with all of that at once.
A login is not a security check
Timus evaluates access continuously instead of once. It looks at who the user is, what condition their device is in, and whether the session is behaving normally — a login from Nashville followed forty minutes later by one from another continent gets stopped rather than waved through. When something changes, access narrows right then. It doesn't wait for the next login.
Three things our team manages, now one
- Always-on encrypted tunnels that replace the VPN, with people connected without thinking about it
- A cloud firewall that segments your network, filters traffic, and cuts off a device the moment it looks infected
- Web filtering that blocks malicious and off-limits sites before the browser finishes loading them
- Conditional access with MFA and single sign-on, tied to the identity system you already run — Entra ID, Okta, or Google Workspace
One agent on the machine, one place we manage it from, across desktop and mobile.
An answer for your insurer and your auditor
MFA, conditional access, network segmentation, and access logging are the controls that show up on nearly every cyber-insurance questionnaire and compliance review. Timus enforces them and reports on them, with reporting built around HIPAA, SOC 2, and PCI-DSS requirements. You can also get a dedicated static IP, which matters the moment a SaaS vendor wants to allow-list your traffic and your people are scattered across home offices.
What rollout actually asks of you
There's no hardware. Nothing to ship, rack, or schedule downtime for — it's cloud-delivered, and it plugs into the identity provider and endpoint tools you're already running. We handle deployment, policy, and the day-to-day of it. If something breaks, you call the same number you always call.
Why we picked this one
- It cleared our own vendor review. We hold SOC 2 Type 2 ourselves, which means every vendor we put in front of you gets vetted first. Timus is SOC 2 Type 2 and ISO 27001 certified.
- It's priced per person, not per device — the same way the rest of your KeyStone services work, so nobody is counting laptops at renewal.
- It bills through the system that already generates your invoices, so your seat count stays accurate without anyone reconciling a spreadsheet.
If your VPN is generating tickets, or your next insurance renewal is asking questions you'd rather have better answers to, tell us what your remote access looks like today. We'll tell you straight whether this fixes it.
If you are a KeyStone ITTaaS® customer, reach out to your account team for more info and assessment on whether this is the right fit for your needs.
Get Started Today
Curious What Better IT Looks Like?
A free, honest conversation about what's working, what's not, and whether we're the right partner for your business. No pressure, no sales pitch — just straight talk.