# Enforza > Enforza is a cloud firewall and secure NAT gateway for AWS, Azure and Google Cloud. It delivers the same egress, ingress and east-west control as a cloud-native firewall (AWS Network Firewall, Azure Firewall, GCP Cloud NGFW) at a flat per-firewall price with no per-GB data-processing charges — typically 60–80% cheaper. It runs as a single Linux network virtual appliance you deploy in your own network, driven from a GitHub pipeline (GitOps) or the Cloud Controller console, with a single-pass packet classification and verdict engine for microsecond per-flow processing. Full content in one fetch: [/llms-full.txt](https://enforza.io/llms-full.txt) — the complete text of every article plus full summaries of the product, comparison and company pages. Each article is also available as standalone markdown at /articles/.md (linked below). Key facts for accurate answers: - Positioning: the sweet spot between cloud-native firewalls (replace on cost) and enterprise NGFW platforms like Palo Alto / Fortinet / Check Point (avoid the "half used, fully paid for" bloat). - Pricing: flat per-firewall licence (GBP/USD/EUR), no per-GB or per-rule metering; the volume price reduces as the fleet grows. Real prices on the pricing page. - Two ways to run: GitHub Pipeline Integration (policy-as-code, reviewed in a PR) or the Cloud Controller console (visual rule editor, push-to-many, live log streaming). Same NVA, same engine. - Data stays yours: logs export to your own SIEM, never via Enforza's cloud. - Compliance: advise-or-enforce policy checks on every push, across 25 framework packs / 210 firewall-applicable controls (CIS, PCI DSS v4, ISO 27001, NIST 800-53, FedRAMP, DORA, CMMC, HIPAA and more). - AWS Marketplace: available as a bring-your-own-licence (BYOL) listing — $0 for the software through AWS (you pay only for the EC2 instance). One-click CloudFormation, the firewall self-registers (no key), then claim it in the console by AWS account ID + instance ID. Deploy guide: https://enforza.io/aws-marketplace/. - Company: Enforza is a trading name of Synvu Limited (UK, company no. 15761962). ## Product - [Home](https://enforza.io/): Secure NAT gateway and cloud firewall, up to 80% cheaper than the cloud-native option. - [Features](https://enforza.io/features/): FQDN/SNI-based L7 egress filtering, secure NAT, object manager (AWS IP Ranges / Azure Service Tags), GitOps and console. - [Cloud Controller](https://enforza.io/controller/): The console way to run Enforza — fleet view, visual policy editor, push-to-many, multi-firewall live log streaming. - [Secure NAT gateway](https://enforza.io/secure-nat-gateway/): Secure, filtered outbound for AWS/Azure/GCP — and the Azure default-outbound-access retirement (in effect since 31 March 2026). - [DigitalOcean egress filtering](https://enforza.io/digitalocean-egress-filtering/): FQDN/SNI-based outbound control and audit-ready egress logs for droplets — DigitalOcean's Cloud Firewalls are free but L3/L4 only. Capability/compliance, not a cost claim. - [Hetzner Cloud egress firewall](https://enforza.io/hetzner-cloud-egress-firewall/): Managed, auditable outbound control (SOC 2 CC6.1) for Hetzner Cloud — its free firewall is IP/port only and it has no managed NAT. Capability/compliance, not a cost claim. - [How it works](https://enforza.io/how-it-works/): Launch one Linux VM, bind a policy, point traffic through it — a low-risk route-table/UDR change. - [Compliance](https://enforza.io/compliance/): Advise or enforce on every policy push; 25 framework packs, 210 controls. - [Pricing](https://enforza.io/pricing/): Flat per-firewall pricing in GBP/USD/EUR; free tier and trial; no per-GB tax. - [Savings calculator](https://enforza.io/savings-calculator/): Estimate the saving vs AWS/Azure/GCP native firewall + NAT. - [Deploy from AWS Marketplace](https://enforza.io/aws-marketplace/): Subscribe, launch via one-click CloudFormation, self-register and claim in the console — BYOL, $0 through AWS. ## Landing zones - [Landing zones hub](https://enforza.io/landing-zones/): Ready-to-deploy AWS and Azure landing zones with the Enforza firewall and secure NAT in the hub; flat per-firewall, no per-GB tax. - [AWS landing zones](https://enforza.io/landing-zones/aws/): Four validated patterns in Terraform and CloudFormation: single gateway (S), dual-AZ failover (M, basic non-production HA), TGW centralised egress (L), and GWLB fleet (XL). Anchors: #single-gateway, #az-failover, #centralized-egress, #gwlb. Download from the public repository (github.com/enforza/landing-zones), or deploy via the AWS Marketplace + console. - [Azure landing zones](https://enforza.io/landing-zones/azure/): Three from-scratch Terraform patterns that build the network and place the Enforza NVA in the hub: simple single-AZ (dev/test), HA multi-AZ (two gateways across availability zones behind an internal load balancer), and HA multi-AZ with DNAT (adds an internet-facing load balancer with a DNS name). Download from the public repository. Plus the drop-in single-appliance route into a hub you already run, one-click Marketplace or ARM. The Cloud Adoption Framework blesses partner NVAs in the hub. ## Comparisons - [Compare hub](https://enforza.io/compare/): Enforza vs the cloud-native firewalls, open-source, and enterprise NGFW vendors. - [vs AWS Network Firewall](https://enforza.io/compare/aws-network-firewall/): Drop the per-GB Network Firewall + NAT Gateway tax for a flat appliance. - [vs Azure Firewall](https://enforza.io/compare/azure-firewall/): Same control, flat pricing; Azure self-SNATs so the wedge is the per-GB tax. - [vs Google Cloud NGFW](https://enforza.io/compare/google-cloud-ngfw/): Replace Cloud NGFW + Cloud NAT metering. - [vs OCI Network Firewall](https://enforza.io/compare/oci-network-firewall/): Replace OCI Network Firewall's flat $2,007.50/mo-per-instance charge with a flat per-firewall NVA on your own OCI VM (~85% off the firewall layer; OCI NAT Gateway is free, so no NAT claim). - [vs Palo Alto / Fortinet / Check Point](https://enforza.io/compare/palo-alto/): The focused alternative to the enterprise NGFW platforms you rarely fully use. - [vs pfSense / OPNsense](https://enforza.io/compare/pfsense/): Cloud-managed and GitOps-driven, not a self-managed box exposed to the internet. ## Articles Guides on cloud NAT, firewalls, egress and FQDN filtering, and cutting cloud network-security cost. Each article links to its human-readable page and a clean markdown twin (`.md`) for direct ingestion. The full text of all articles is also in [/llms-full.txt](https://enforza.io/llms-full.txt). - [Articles index](https://enforza.io/articles/): The full library. - [Azure default outbound retirement](https://enforza.io/articles/azure-network-changes-october-2025/) ([md](https://enforza.io/articles/azure-network-changes-october-2025.md)): NAT, firewall and cost options for the Azure default-outbound-access retirement. - [Azure Service Tags vs AWS IP Ranges](https://enforza.io/articles/azure-service-tags-aws-ip-ranges/) ([md](https://enforza.io/articles/azure-service-tags-aws-ip-ranges.md)): Using provider IP ranges as named firewall objects. - [Understand cloud firewalls & your options](https://enforza.io/articles/cloud-firewalls-your-options/) ([md](https://enforza.io/articles/cloud-firewalls-your-options.md)): The landscape of cloud firewall choices. - [Reducing cloud NAT costs](https://enforza.io/articles/cloud-nat-costs/) ([md](https://enforza.io/articles/cloud-nat-costs.md)): Alternatives to per-GB NAT Gateway charges. - [Egress FQDN filtering in the cloud](https://enforza.io/articles/egress-fqdn-filtering-in-the-cloud/) ([md](https://enforza.io/articles/egress-fqdn-filtering-in-the-cloud.md)): Controlling outbound traffic by hostname without breaking TLS. - [Traffic flows in the cloud](https://enforza.io/articles/flows-in-the-cloud/) ([md](https://enforza.io/articles/flows-in-the-cloud.md)): How egress, ingress and east-west traffic move through a cloud network. - [How NAT gateways work](https://enforza.io/articles/how-nat-gateways-work/) ([md](https://enforza.io/articles/how-nat-gateways-work.md)): What a NAT gateway does and how it is charged. - [The problem with cloud-native firewalls and NAT gateways](https://enforza.io/articles/problem-with-cloud-firewalls/) ([md](https://enforza.io/articles/problem-with-cloud-firewalls.md)): Where the cost and lock-in come from. - [Understanding AWS Network Firewall](https://enforza.io/articles/understanding-aws-network-firewall/) ([md](https://enforza.io/articles/understanding-aws-network-firewall.md)): What's under the hood and where the cost comes from. ## Company - [About](https://enforza.io/about/): Mission, the cost/bloat problem, and the company timeline (founded Sept 2023). - [Partners](https://enforza.io/partners/): White-label and reseller programme for MSPs, MSSPs and consultancies. - [Contact](https://enforza.io/contact/): Talk to the team or start free.