BSDTrustGate provides enterprise-grade identity and access management with Zero Trust Architecture. Control who accesses your resources, from where, and under what conditions with our comprehensive security platform.
Identity-Based Access Control: Manage user identities and access permissions with granular control over who can access what resources.
Multi-Factor Authentication: Add layers of security with MFA support including biometrics, tokens, and mobile authenticators.
Geo-control Policies: Restrict access based on geographic location to comply with data sovereignty requirements.
Cloud & Virtualization
IDVE
Powerful cloud infrastructure management platform
IDVE (Infrastructure Development and Virtualization Environment) is a comprehensive cloud infrastructure management platform designed for modern enterprises. It provides seamless native migration from VMware, KVM clustering, Ceph storage, and automated point-in-time disaster recovery.
Virtual Machine Management: Manage hundreds of virtual machines through an intuitive, real-time interface powered by WebSocket technology. Monitor resource usage, power states, and network configuration instantly.
Cloud-init Support: Automate VM provisioning with fully customizable YAML templates sent directly to the hypervisor seamlessly.
Detailed Topology: Visualize your entire cluster architecture and virtual machine relationships at a glance with interactive maps.
Network & Operations
NOCS
Enterprise NOC Platform: Multi-Vendor Telemetry, Proxmox & Ceph, IPAM, Web SSH, & On-Premise AI
NOCS (Network Operations Center System) is an enterprise-grade, all-in-one platform designed for network operations, monitoring, infrastructure management, and intelligent automation. The platform delivers real-time visibility, automated telemetry collection, security auditing (CVE & OWASP Top 10), and AI-driven troubleshooting across multi-vendor network hardware, virtualization environments (Proxmox VE & Ceph), data center facilities & IPAM, and web services.
Comprehensive Network Monitoring & Protocols: SNMP (v1/v2c/v3) with counter-wrap handling and spike suppression, NetFlow / IPFIX / sFlow Flow Analyzer with Top Talkers & Whois lookup, ICMP Ping latency & rolling SLA metrics, BGP Peering monitoring & dynamic topology graph, centralized Syslog server, and Looking Glass diagnostic suite (Ping, Traceroute, MTR, DNS).
Multi-Vendor Management & Network Automation: Deep telemetry and management for MikroTik RouterOS, Cisco IOS/XE, Juniper JunOS, and Huawei VRP; automated configuration backups (binary & export) and OpenVPN tunnel provisioning; plus an in-browser multi-pane Web SSH terminal with split-screen modes.
Visual Data Center & IPAM Elevation: Interactive rack elevation layouts (U-size units), port-to-port mapping, chassis/blade slot allocation, alongside comprehensive IPv4/IPv6 subnet hierarchy, CIDR block allocation, VLAN tracking, and automated IP conflict detection.
CyBSD is your security operations backbone. Combining distributed SIEM log correlation, automated SOAR playbooks, and threat intelligence, it provides comprehensive visibility and automated incident response.
SIEM Log Analysis: Collect, correlate, and analyze logs from all your security tools and infrastructure.
SOAR Workflow Automation: Automate incident response with playbooks and orchestration.
Threat Intelligence Integration: Enrich alerts with threat intel from multiple sources.
Cybersecurity
WAFX
Enterprise-Grade Layer-7 Web Protection
WAFX protects your web applications from attacks with enterprise-grade WAF, AI bot mitigation, and real-time traffic monitoring. Keep your mission-critical applications secure and available.
Web Application Firewall: Protect against OWASP Top 10 and other web application attacks.
Virtual Patching: Instantly protect vulnerable applications without code changes.
Bot Mitigation: Detect and block malicious bots while allowing legitimate traffic.
Enterprise Solutions
IDMBX
Standalone Mailbox, Modern Webmail & Built-in Team Collaboration Platform
IDMBX (ID Mailbox Server) is a standalone email server platform that combines mailbox storage, standard email protocols, a modern webmail, and collaboration features in a single lightweight application with zero external database dependencies.
Complete Email Server & Industry Standards: Inbound delivery via LMTP from gateway (IDMG), authenticated SMTP Submission (port 587), IMAP (143/993) & POP3 (110/995) client access, Maildir storage, and ClamAV antivirus integration.
Modern Webmail & PWA Ready: Responsive webmail interface with desktop and mobile support, installable as a PWA, with Gmail-style smart categories (Primary, Social, Purchases, Updates, Forums, Promotions).
Unified Collaboration Suite & Video Meetings: Internal team chat, video meetings with built-in communication server, notes, tasks with reporting, calendar, file storage, and Google Drive integration.
IDMG (Intelligent Mail Gateway) is an enterprise-grade standalone Mail Gateway and SMTP Relay system. IDMG sits in front of internal mail servers (Exchange, Zimbra, Postfix, IDMBX) to filter inbound spam and viruses, and acts as a hardened outbound relay with automated DKIM signing and Outbound Data Loss Prevention (DLP).
Dual-Flow SMTP Engine (RFC 5321): Inbound Gateway (port 25/2525) verifies destination domains and forwards clean mail to internal servers; Outbound Submission & Relay (port 587/465) with trusted IP/CIDR/SASL, auto DKIM signing, and direct MX relay.
Multi-Layer Security & Content Filtering: SPF, DKIM, and DMARC validator, weighted multi-DNSBL spam heuristics (Spamhaus, SpamCop, Barracuda), native ClamAV antivirus (zINSTREAM), deep attachment inspection including nested ZIPs, and adaptive greylisting.
SMTP Firewall & Intrusion Prevention (IPS): Sliding-window failure detection for AUTH brute-force (535), open-relay probes (550), and port-scans with automatic IP bans, plus persistent CIDR whitelists and blocklists stored in internal storage.
IDVE Backup Server (IBS) is an enterprise deduplicating backup and disaster-recovery platform. It consolidates multi-node physical and virtual machine backups into a single secure repository, cutting storage requirements by up to 80% with SHA-256 block deduplication and instant bare-metal restore capabilities.
High-Efficiency Data Deduplication: Data is split into 4 MB chunks identified by SHA-256 digest (.chunks/xxxx/...). Identical chunks are stored only once, saving up to 80% storage space securely and efficiently.
Whole-Disk & Bare-Metal Restore: Comprehensive whole-disk and partition image backup, consistent point-in-time snapshots, and instant bare-metal restore executed straight from the web dashboard.
Polling-Based Autonomous Agent: Protected nodes run a lightweight agent (idve-backup-agent). The agent autonomously claims jobs from the server periodically and reports progress with zero inbound firewall port requirements.
Ticka is a standalone helpdesk and IT Service Management (ITSM) platform that streamlines enterprise support operations. It features structured 3-tier escalation (L1 Helpdesk, L2 Technical, L3 Expert), automated SLA breach tracking, Markdown knowledge base, built-in live chat, and lightweight local document storage with zero external database requirements.
Structured 3-Tier Support Workflow (L1/L2/L3): Seamless ticket lifecycle management spanning L1 Helpdesk, L2 Technical, and L3 Expert tiers with complete comments audit logging, priority shifts, auto-escalation, and ticket reopening.
Automated SLA Target & Breach Tracking: Configurable response and resolution time targets by priority with real-time health indicators (on track, at risk, breached) and automated escalation triggers for unattended tickets.
Integrated Knowledge Base & Live Chat: Self-service structured documentation portal for end users and real-time interactive live chat with support engineers for rapid incident triage.
Cybersecurity
IDSSO
Modern Self-Hosted IAM Platform, OpenID Connect 1.0 & OAuth 2.0 with Native AES-256-GCM Vault
IDSSO is a high-performance, self-hosted Identity and Access Management (IAM) and Secret Vault Engine built in Go. It delivers modern centralized authentication (OpenID Connect 1.0 & OAuth 2.0) alongside native military-grade AES-256-GCM encrypted secret management without cloud vendor lock-in or JVM overhead.
OpenID Connect 1.0 & OAuth 2.0 Engine: Authorization Code Grant Flow, PKCE (RFC 7636) for SPAs and Mobile, RS256 2048-bit JWT ID tokens, dynamic OIDC discovery, auto-rotated JWKS endpoints, and granular interactive consent screens.