Layer 4 · Policy & Governance

CyMatrix

One policy hierarchy. From tenant to packet. Hierarchical, most-restrictive-merge.

CyMatrix

CyMatrix is a hierarchical policy engine. NetworkPolicy, RuntimePolicy, DevicePosturePolicy, GeolocationPolicy, and DLP (380+ patterns with real validators) flow from SYSTEM → TENANT → NETWORK → VM. Translated to OVN ACLs in real-time and enforced at the logical switch layer.

Gallery

See Cymatrix in action.

Use Cases

Where CyMatrix wins.

1

Multi-tenant SaaS isolation

One tenant's policy can never expose another tenant's data. OVN address-set isolation at network layer; DLP at data layer. Both enforced from the same hierarchical policy.

2

India DPDP / Aadhaar / PAN compliance

Real validators (Verhoeff for Aadhaar, MOD-97 for IBAN, Luhn for credit cards) — not regex approximations. 380+ patterns out of the box.

3

Geolocation-based access control

Impossible-travel detection (Mumbai login + London login 10 minutes later = blocked). Country-of-origin enforcement for export controls.

4

Network microsegmentation

VM-level firewall rules synthesized from policy. Hot-reload, no agent. OVN translates declarative intent to flow rules in <1 second.

5

Forcepoint DLP replacement

Forcepoint is moving to SaaS-only. CyMatrix DLP is on-prem and integrated into VDI/RBI/audit — no separate scan agent on endpoints.

6

Segregation of Duties enforcement

When requester = approver, the request is BLOCKED at request-time — not just logged. Most products only log the violation; we prevent it.

Key Capabilities

What's inside.

🏛️

Hierarchical merge

Higher-scope policy wins on conflict. SYSTEM > TENANT > NETWORK > VM. Predictable, auditable, debuggable.

🔍

380+ DLP patterns

Real validators (IBAN MOD-97, Aadhaar Verhoeff, Luhn) — not regex approximations.

Real-time OVN sync

Policy change to network ACL in <1s. Hot reload, no restart, no agent.

📋

365-day immutable audit

Every policy change attributed, immutable, exportable to SIEM. One audit log across all enforcement points.

🚫

SoD block, not log

Block requester = approver violations at request-time. Most competitors only log.

🤝

Coexists with edge SSE/SWG

Zscaler at network edge + CyMatrix at workload = full coverage. Different layers, fully complementary.

vs competition: Replaces Forcepoint DLP, Symantec DLP. Complementary to Zscaler/Netskope (edge SSE) and SailPoint (IGA).
Full battle card →

Ready to see CyMatrix in action?

30-day proof of concept on two idle servers. We bring the SE. You bring the use case.