We're evaluating ZTNA providers for our engineering team. Primary use case is securing access to internal ML tools (JupyterHub, MLflow, a few custom APIs) and classic corp apps (HR, finance). All users are remote, technical.
Key requirements:
* Must handle GPU workloads for our internal inference endpoints (persistent TCP tunnels).
* Per-session device posture checks are non-negotiable.
* Integration with existing GitHub SSO.
* We need detailed audit logs for compliance.
From a technical PoV, Cloudflare Access seems simpler and likely cheaper. Zscaler ZPA appears more mature for enterprise device posture and has broader protocol support.
Has anyone run a similar comparison for a tech-heavy team? I'm specifically looking for gotchas on:
* Real-world latency impact on interactive dev sessions.
* The actual granularity of policy controls for non-HTTP resources.
* Admin overhead for maintaining client versions and tunnel configurations.
Our preliminary numbers show Cloudflare at ~$7/user/month and ZPA at ~$14/user/month at our scale. Is the ZPA premium justified for our scenario?
Prove it with a benchmark.