Hi everyone, I've been tasked with helping my team evaluate zero trust / SDP options. We're a fully distributed SaaS company, about 50 people, all over the globe. Our main needs are secure access to a few internal web apps (like our admin panel and analytics dashboard) and some Git repositories.
Right now, we're using a basic VPN and it's... not great. The onboarding for new hires is clunky, and performance can be really slow for some folks.
I've narrowed it down to Appgate SDP and Zscaler Private Access after some initial research, but I'm feeling a bit lost on the practical differences. The high-level features sound similar from the websites.
Could anyone share real-world experiences with either, especially for a setup like ours? I'm particularly curious about:
* How easy is the initial setup and ongoing management for a small tech team?
* How is the end-user experience? Do they need to be connected all day, or can they just reach the apps they need on-demand?
* Any gotchas with pricing models? We're very conscious of per-user costs as we grow.
I've set up trials for both, but any insights before I dive in would be so helpful. I just want to make sure I'm looking at the right things during the evaluation.
✌️ annie
I work on a team of about 30 devs and ops people for a SaaS company, and we've been running Zscaler Private Access for a bit over two years now.
**Setup & Management:** Zscaler is easier if you have no on-prem gear. It's cloud-hosted, so you configure users and app rules in a portal. Appgate is more flexible but needs you to deploy their gateways, which is extra work if you're fully cloud.
**User Experience:** Both can do on-demand access, but Zscaler's client feels lighter. Our users don't stay connected all day; they click an app and the client handles the connection. Appgate's client is powerful but sometimes feels heavier to end-users.
**Pricing Gotcha:** Watch the user definition. Zscaler's cost is per user, period. Appgate, in my last shop, had costs based on "simultaneous connected users" which could save money if not everyone is online at once, but it's trickier to model.
**Performance for Distributed Teams:** Since Zscaler uses their own global proxy network, our users in APAC see much better speeds to our US apps. With Appgate, performance depends heavily on where you host your own gateways, which adds complexity and cost.
I'd recommend Zscaler Private Access for your case of 50 fully distributed people needing simple web app access. It gets you going faster. If you had a hybrid cloud/on-prem setup with more complex protocols than HTTP/HTTPS, I'd lean Appgate. Tell us if you have any legacy non-web apps or if controlling the physical gateway location is important to you.
CloudNewbie