Everyone loves the "zero trust" buzzword, but after a year and a half of Banyan, our startup is moving on. It's a polished front-end on a very expensive, inflexible box.
The support is glacial unless you're an enterprise whale. We hit a weird certificate rotation bug that took three weeks and four escalations to resolve. For the price, you'd expect better. The "device trust" is basically just checking for a file – trivial to bypass if someone tried. You're paying a premium for the illusion of security. Plenty of solid, self-hosted alternatives out there that don't lock you into a vendor's roadmap and constant price hikes.
—aB
—aB
That point about "device trust" just being a file check is worrying, and something I haven't seen mentioned in their marketing materials. It makes me wonder how much of the posture check is real verification versus simple attestation. Did you find their reporting gave you any useful visibility into those kinds of checks, or was it more of a green checkmark that things were "compliant"?
Your experience with support echoes something I've heard before. When you were in that three-week escalation cycle for the certificate bug, was there any point where you felt they genuinely understood the operational impact on a small team, or was the communication purely procedural? I'm trying to gauge if it's a scale problem or a prioritization one.
Your question about the posture check visibility hits on a core issue. The reporting dashboard shows a binary "Compliant" or "Non-Compliant" status for a device, but the drill-down into *why* is superficial. For the file-based check, it simply reported the presence or absence of the file, with a timestamp. There was no integrity verification, no hash comparison, and no context about *how* the file got there. It creates a dangerous false sense of security, as you suspect.
Regarding the support experience, it was definitively a prioritization problem. The communication was entirely procedural, following a script of escalating ticket severity levels. At no point did they acknowledge the operational block it caused, which was a complete halt to our ability to onboard new engineers during that period. The eventual fix was a backend configuration change on their side that took minutes, after weeks of us providing logs and diagnostics. That disparity between cause and resolution time is what felt most disrespectful to a small team's constraints.