Partner Access

Give your clients managed access to your apps — no VPN.

If you run private apps or customer environments for many clients — SaaS, ERP, hosting or integration — Partner Access lets you offer secure web access as part of your own service. Your clients get verified, scoped, logged and revocable sessions to the right app, without a device VPN and without exposing internal addresses.

Request Partner Access

Who it is for

What the platform gives you

Clients and apps in one partner account

Manage client workspaces, published apps, connectors and users from one partner account.

Access without VPN

Each client environment is reached through an outbound connector and a managed public app address — no inbound ports, no internal hostnames or private IPs exposed to end users.

Usage reporting and billing

Active-user reporting per client to support your own billing; platform fee plus per-active-user pricing.

Content protection

Optional dynamic watermark and copy/print/screenshot deterrents on protected app pages make mishandling more visible. They reduce casual leakage risk but do not replace DLP.

Partner-ready operations

Partner dashboard, delegated APIs and client-level reporting support sales-assisted MSP and integrator rollouts under BusinessProxy-branded surfaces.

Why partners win

It becomes your “secure access without VPN” feature

You already have the client base, billing, support and trust. BusinessProxy becomes a feature you include in your plan or sell as an add-on — one contract can replace dozens of separate small access setups.

Pricing

Platform fee + per active user

Platform from $300–2,000 / month plus $1–3 per active user per month, with app- and connector-based components for larger deployments. Final pricing depends on volume and delivery model.

Request Partner Access

Partner Access FAQ

Why is this better than giving each client a VPN?
A VPN connects the whole device to a network and is costly to support across many clients. Partner Access publishes a specific app per client with verified, scoped, logged and revocable sessions — no device tunnel.
What is available today and what requires a separate rollout?
The public app address + connector access model, client workspaces, users, partner dashboard and access event log are the working core. Broader partner billing and custom public identity require a separate enterprise rollout.
How does the connector see app traffic?
The public app address path works as a Layer-7 reverse proxy: it relays the full request and response (method, path, headers and bodies) in transit to your connector. Bodies are not logged or retained. This is disclosed before enablement.