SASE is an architecture born from a problem most startups never had: traffic hauled back to a head office to be inspected. Knowing which parts of it apply to you saves a large amount of money.
The short answer
SASE, pronounced sassy, stands for secure access service edge. It converges networking and network security into one cloud-delivered service, so that inspection and access decisions happen close to the user rather than inside a corporate data centre. The five components are SD-WAN, secure web gateway, cloud access security broker, zero trust network access and firewall as a service.
It is an enterprise architecture. Whether you need all of it, some of it or one piece of it depends almost entirely on whether you own offices and private networks.
On this page
The five SASE components
| Component | What it does |
|---|---|
| SD-WAN | Software-defined routing between offices, data centres and cloud, replacing fixed private circuits |
| Secure web gateway | Inspects outbound web traffic, filters categories and blocks malicious destinations |
| Cloud access security broker | Visibility and policy over SaaS use, including sanctioned and unsanctioned applications |
| ZTNA | Access to private applications gated per user and per device, with no network-level trust |
| Firewall as a service | Firewall capability delivered from the cloud rather than from appliances you rack |
SASE and SSE
SSE, security service edge, is the same architecture with the networking removed. It is the security half: secure web gateway, cloud access security broker and ZTNA, without SD-WAN.
The reason the term exists is that many buyers wanted the security convergence but had no appetite to replace their networking at the same time. For a company with no branch offices and no private circuits, SSE is usually the relevant conversation and SASE is the term the vendor happened to lead with.
What SASE actually solves
The original problem was backhaul. A company with offices and a data centre routed all traffic back to headquarters so it could pass through the security appliances installed there. That worked when applications lived in the data centre. Once applications moved to SaaS and cloud, sending a user’s traffic across the country and back to reach a service hosted near them became slow, expensive and pointless.
If you never had a data centre, you never had the backhaul problem
A cloud-native company with a distributed team and everything in SaaS did not inherit the architecture SASE was designed to replace. That does not make the security functions irrelevant, but it does mean buying a full suite to solve a problem you never had is an expensive way to acquire one control you do need. The pieces are separable, and vendors prefer that you not notice.
What a lean team needs from it
| Component | Worth it for a 10 to 50 person company? |
|---|---|
| ZTNA | Yes. Private servers and internal tools need access gated by user and device, and this is the piece that replaces a VPN |
| Web filtering | Often, though usually adequate as an endpoint control rather than a network service |
| SaaS visibility | Sometimes. Valuable once SaaS sprawl is real, less so at twenty applications |
| Cloud firewall | Rarely as a separate purchase. Cloud provider controls and a WAF usually cover it |
| SD-WAN | Almost never. It solves routing between sites you do not have |
The through line is that identity, not network location, is what the architecture actually anchors on. Get access management, MFA and device posture right and you have the substance of the model, whatever the suite is called.
Where Osto fits
Osto is not a SASE suite and does not claim to be. There is no SD-WAN and no managed network fabric. What Osto delivers is the piece a cloud-native company actually needs from the architecture, plus the controls around it.
ZTNA provisions a private domain for your cloud servers and resources, unreachable unless the endpoint agent is installed and MFA is enforced. Alongside it sit endpoint protection, device and content controls, data loss prevention, web and API protection and inbound email security. The access decisions, endpoint state and application traffic all correlate in the same SIEM, which is the part a stitched-together edge stack struggles to deliver. If you have branch offices and private circuits, a full suite is a reasonable conversation. If you do not, this is the shorter path to the same outcome.
Platform walkthrough
The piece you actually need
Private access gated by user and device, with endpoint, data and application controls correlating in the same stack. No network fabric to replace. One owner, one dashboard.
Book a demoZTNA without the suite · Built for lean teams · One platform, everything
Frequently asked questions
What is SASE?
Secure access service edge, an architecture that converges networking and network security into one cloud-delivered service. Its components are SD-WAN, secure web gateway, cloud access security broker, ZTNA and firewall as a service, with identity as the policy anchor.
What is the difference between SASE and SSE?
SSE, security service edge, is the security half without the networking. It covers web gateway, SaaS control and ZTNA but not SD-WAN. Companies without branch offices or private circuits usually want SSE rather than the full architecture.
Does a startup need SASE?
Usually not as a suite. The architecture was designed to replace backhauling traffic to a corporate data centre, which cloud-native companies never did. ZTNA is normally the one component that earns its cost immediately.
Is SASE the same as zero trust?
No. Zero trust is a principle: verify every request rather than trusting a network location. SASE is one architecture for delivering it, and ZTNA is the component within it that applies the principle to private application access.
Does SASE replace a VPN?
The ZTNA component does. A VPN places a user on the network and trusts them broadly. ZTNA grants access to specific resources per user and per device, with no network-level trust, which is a materially different security posture.

