Flat per firewall
£179/month per firewall (£149 from your sixth), plus the VM each client runs it on. No per-GB data-processing charge — the cost stops scaling with traffic.
Run a fleet of per-client firewalls from one console, isolated tenant by tenant, under your own brand and domain. Flat per-firewall pricing with no per-GB tax keeps your managed-service margin intact — and each client's logs go to their own SIEM, never through us.
The economics, the isolation and the fleet console an MSSP needs to operate a managed firewall line — without the enterprise-NGFW licensing complexity or the per-GB tax.
Your managed-service price is set; if your firewall cost moves with the client's traffic, your margin moves with it too. Enforza is a flat per-firewall licence — no per-GB tax, no charge by CPU, instance size, protected IP or protected device — so the cost base is fixed and the spread is yours to keep.
Operate every client's firewall from one pane of glass: deploy, set policy, watch live logs across the fleet, and push self-upgrades with rollback. No SSH-into-boxes, no per-client tooling, no internet-exposed management plane to babysit.
Tenant isolation is the default, not an upgrade. Each client is a separate tenant with its own policy and its own boundary, so you can run many clients side by side without their environments touching.
Run the console on your own domain (a custom FQDN) with your own branding and theming. Your clients see your firewall, your portal, your name — you keep the relationship end to end.
Logs stream to each client's own SIEM, never through Enforza's cloud. The firewall runs as a single Linux VM inside the client's own network, with no inbound management port and no admin UI exposed — the assurance your clients ask you for.
25 framework packs and 210 firewall-applicable controls, advise-or-enforce on every publish. Give each client a defensible posture — PCI DSS, HIPAA, ISO 27001, NIST and more — without bolting on a separate tool.
Three steps from partner onboarding to a managed firewall running for every client, all from one console.
Request partner access, and we walk your team through the fleet console, multi-tenant model, white-label setup, GitOps and console workflows, compliance gating and live log streaming.
Create an isolated tenant for each client and deploy a firewall inside their network in minutes on a Linux VM they provision — on AWS, Azure, GCP or on-premise. Brand it as yours.
Run policy, compliance and live logs across every client from one console. Add tenants as you win clients; the flat per-firewall economics scale predictably, and volume pricing kicks in as the fleet grows.
A per-client firewall usually means a managed cloud firewall plus a NAT gateway — per-hour fees often duplicated per Availability Zone, plus two per-GB meters. Enforza is one flat-priced appliance per firewall.
£179/month per firewall (£149 from your sixth), plus the VM each client runs it on. No per-GB data-processing charge — the cost stops scaling with traffic.
Against a cloud-native firewall stacked with a NAT gateway at modest egress, the flat line is usually 60–80% cheaper — headroom for your service margin and a saving for the client.
Same flat line on every tenant, with volume pricing as the fleet grows. You forecast a known number per client, not a meter that moves with their month.
Yes. Multi-tenancy is the default: each client is an isolated tenant with its own policy and boundary, and you manage every tenant's firewall from one fleet console. That's the foundation for running a managed cloud-firewall line across many clients without their environments touching. You can also run the console under your own brand and domain — see the white-label firewall page.
Your service price is fixed, so a cost base that moves with the client's traffic eats into your margin. The cloud-native firewall and NAT gateway meter per gigabyte; Enforza is one flat per-firewall licence with no per-GB tax and no charge by CPU, instance size, protected IP or protected device. The cost base is predictable, so the spread between your service price and your firewall cost stays where you set it. At modest egress the flat line is typically 60–80% cheaper than a metered cloud-native firewall stacked with a NAT gateway.
Yes — white-label is shipped. Run the console on your own domain (a custom FQDN) with your own branding and theming so each client sees your firewall and your portal. Combined with default multi-tenant isolation, that lets you deliver a managed firewall service that's wholly yours on the surface, with Enforza as the engine underneath.
To the client, not to us. Logs stream to each client's own SIEM rather than through Enforza's cloud, and the firewall runs as a single Linux VM inside the client's own network with no inbound management port or admin UI exposed on the device. That keeps the client's traffic and data theirs — exactly the assurance an MSSP needs to give its own customers.
From one fleet console. You deploy, set policy, run compliance guardrails, push self-upgrades with rollback, and watch live logs across every client's firewall from a single pane of glass — with each client isolated as its own tenant. There's no SSH-into-boxes, no per-client tooling, and no internet-exposed management plane to maintain.
Email support is included in every plan, and premium support and hourly consultancy are available as paid add-ons — useful when you're on the hook to your own clients under an SLA. Partner access is gated; email partners@enforza.io to talk through the support tier and economics that fit your delivery model. We agree commercial terms per partner rather than publishing them.
Partner access is by request. Tell us about your business and the clients you serve and the partner team will be in touch to talk through managed delivery, white-label setup, the support tier and the economics that fit you.
One fleet console, isolated tenant by tenant, white-label to your own domain — with flat per-firewall economics that keep your managed-service margin intact. Partner access is by request.