We're a fully remote SaaS company (~300 employees). Looking at NordLayer for a combined VPN and zero-trust network access solution to replace our basic VPN.
Can anyone share real experience on:
* Contract flexibility for sub-500 seats? Is it truly month-to-month or are there hidden annual commitments?
* Any gotchas in their SLA? How is support response for non-enterprise tiers?
* How clear is the per-user pricing? Are there separate fees for gateway usage or data caps we should watch for?
Also interested in how it compares to Zscaler or Twingate for a team our size, specifically on admin overhead and compliance (SOC 2).
Based on your seat count and requirement for SOC 2, I'd advise looking at contract terms very carefully. Many vendors advertise month-to-month flexibility for under 500 seats, but the pricing is often punitive compared to an annual commitment, effectively locking you in. You should request explicit quotes for both models.
For admin overhead, Zscaler has a more complex architecture that typically demands dedicated network security staff. Twingate and NordLayer are lighter, but Twingate's reliance on connectors in your own infrastructure adds a different type of management burden. For a 300-person remote SaaS team, the simplicity of a cloud gateway model often wins.
On SLA gotchas, review the definitions of "service availability" closely. Some exclude scheduled maintenance or only cover core gateway connectivity, not the client application performance. Support response times for mid-market tiers can be slow for non-critical issues; ask for their average ticket resolution time for your proposed plan.
null
You're spot on about the punitive month-to-month pricing. We saw the same from three different vendors last year. The "flexible" plan was nearly 40% more per seat, which is just an annual commitment with extra steps and risk.
Your point on SLAs covering only gateway connectivity is critical. We almost missed that in one proposal. Ask for explicit language that client-to-gateway latency and connector health are included in the service level calculation, not just their cloud pop being online. If they won't put it in writing, walk away.
Twingate's connector management overhead is real. For a lean team, even lightweight infra you own becomes a pager duty item. Unless you have dedicated platform or infra engineers, that's a hidden cost.
Garbage in, garbage out.
Ran NordLayer for about a year for a similar sized team. Their month-to-month is real, but you'll pay roughly 25-30% more per seat. No hidden annual lock, but the price difference feels like a soft commitment.
Support for the Business tier was slow on non-critical issues. Took days for config questions. Their SLA defines downtime as gateway unreachable, not high latency, which bit us once during a regional cloud provider issue.
For your size, the admin overhead was okay. It's simpler than Zscaler, but we found Twingate's audit logs were more detailed for SOC 2 evidence. NordLayer's were sufficient but required more manual aggregation.
Oh, the soft commitment through punitive pricing. Classic. Wait until you see the "true-up" clauses they sneak in for growing teams, which effectively nullify any month-to-month benefit you thought you had.
And on the SLA point: even if they *do* agree to include client-to-gateway latency in writing, good luck defining and measuring an acceptable threshold. That negotiation is where they'll wear you down.
Trust but verify.
Ran NordLayer's Business tier for 180 seats for about 18 months. On your first point, it's month-to-month on paper, but the pricing is structured to make the annual commitment the only sensible choice. The monthly per-seat cost was nearly double, so you're functionally locked in.
Their per-user pricing is clear until you need to scale gateways for performance or geo-distribution. There are no separate fees for gateway usage per se, but each "gateway server" is a separate resource in their portal with its own concurrent connection limits. If you hit those limits, you're adding another gateway, which feels like a sneaky capacity cap.
For SOC 2, their logs are exportable but the schema is basic. You'll spend more time correlating events than with Twingate, which bakes more context into each log entry. Admin overhead is lower than Zscaler, but you trade that for less granular control in audits.
Automate everything. Twice.