UPAS · NAC + Zero Trust Device Governance

Know every device. Control every connection.

UPAS combines Network Access Control and IT Asset Management to discover connected assets, assess device health and enforce access policy from one platform. It helps teams reduce Shadow IT and control devices across IT, OT, IoT and IoMT environments.

One connected platform

See the device. Understand the risk. Control access.

UPAS connects network access and asset health, giving security and IT teams a shared view of the devices they need to govern.

  1. Connected devices

    Discover and identify devices across your environment.

    • IT
    • OT
    • IoT
    • IoMT
  2. UPAS · NAC + ITAM

    Combine access decisions with device and asset context.

    NACWho and what may connect
    ITAMDevice inventory and health
  3. Policy-based response

    Allow appropriate access, restrict risk and guide corrective action.

    • Allow
    • Restrict
    • Remediate
A shared device record, from discovery to response. Simplified from UPAS’s NAC + ITAM architecture overview; deployment and enforcement depend on your environment.

Business outcomes

Why UPAS is more than conventional NAC

NAC and ITAM in one platform

Connect device discovery, network access, asset inventory and endpoint remediation so security and IT teams work from the same record.

Agentless visibility without a network redesign

Discover and classify connected devices across existing infrastructure, including equipment that cannot run an endpoint agent.

Zero Trust decisions based on device health

Use identity, ownership, patch status, security controls and policy conditions to decide what each device may access.

Stop unknown and unhealthy devices at the network

Restrict, isolate or block devices that are unauthorised, non-compliant or showing higher-risk conditions.

Trace devices across users, addresses and switch ports

Link IP, MAC, device name, user, location and connection history to investigate changes and resolve issues faster.

Move from findings to remediation

Identify vulnerable software, missing patches and configuration gaps, then guide corrective action before restoring normal access.

NAC + device governance

What the UPAS platform can cover

  • Agentless discovery and classification of IT, OT, IoT and IoMT devices
  • Device identity, ownership, location and connection history
  • Allowlisting and policy-based network access control
  • Restriction, isolation, blocking and remediation access
  • Hardware, software, patch and vulnerability inventory
  • Endpoint health checks for antivirus, EDR, required software and configuration
  • IP and MAC address governance, topology and switch-port visibility
  • Active Directory, GPO, USB, mobile-device and remote-operations options
  • Dashboards, alerts, event records and configurable reporting

Continuous device governance

From connection request to policy enforcement

Device trust can change. UPAS connects discovery, access control and ongoing health checks in a continuous workflow.

  1. 01

    Identify

    Recognise the device and check whether it is trusted.

  2. 02

    Build inventory

    Collect the device context needed for access decisions.

  3. 03

    Control access

    Apply access policy for the device and its intended use.

  4. 04

    Monitor health

    Check compliance and watch for changes in risk.

  5. 05

    Remediate

    Address gaps and restrict access where policy requires.

  6. 06

    Reassess

    Verify the current state before allowing appropriate access.

Continuous checks keep access aligned with device health.

Simplified from UPAS’s Zero Trust Device Security Validation Workflow. Policy, device support and remediation scope are agreed during solution design. Discuss your device environment

Platform capabilities

One device record across network security and IT operations

Network Access Control

Discover devices without changing the existing network design, build allowlists and stop unauthorised or non-compliant connections.

IT Asset Management

Maintain hardware and software inventory, identify missing patches and risky applications, and coordinate endpoint remediation.

IP Address Management

Track IP and MAC use, device history, switch location and address conflicts from one operating view.

Identity and device trust

Connect directory accounts with approved devices and use identity, posture and context to inform access decisions.

Endpoint and data controls

Apply software, USB, removable-media, remote-management and configuration policies to supported endpoints.

Mobile device governance

Bring smartphones and tablets into the same governance model with application controls, remote lock and wipe options.

IT, OT, IoT and IoMT visibility

Identify diverse connected equipment across offices, plants, healthcare environments and distributed sites.

Audit and compliance evidence

Use event history, device status, policy results and configurable reports to support reviews and investigations.

Established platform

Built for complex device environments

3,800+corporate and government customers reported by UPAS
30+ yearsof network and endpoint management development
Agentless discoveryfor IT, OT, IoT and IoMT assets that may not support an agent
Mixed infrastructuresupport for major operating systems, switch vendors and security tools
Apexagen-managed implementation

Turn UPAS capabilities into enforceable operating policy

We assess your network and device environment, define access and health policies, plan deployment and integrations, coordinate implementation and establish the processes for exceptions, remediation and ongoing review.

Try UPAS for 60 days

Evaluate device discovery, asset visibility and a defined network access use case in your own environment with guidance from Apexagen.

Request your free trial

UPAS questions

NAC and Zero Trust device governance FAQ

What is Network Access Control?

Network Access Control identifies devices connecting to a network and applies policies that determine whether each device can connect, needs restricted access or should be isolated or blocked.

How does UPAS support Zero Trust?

UPAS uses device identity, health, ownership and policy status to inform access decisions. Trust can be reassessed as the device changes, allowing access to be reduced or restored according to current conditions.

Does UPAS require an agent on every device?

No. UPAS can discover and identify connected devices without installing an agent. Agents can be used where deeper endpoint health, software, patching or remediation functions are required.

Can UPAS identify OT, IoT and medical devices?

UPAS is designed to discover IT, OT, IoT and IoMT devices, including equipment that may not support endpoint agents. The device types and enforcement approach are confirmed during assessment and design.

How do NAC and ITAM work together?

NAC controls whether a device can connect. ITAM adds hardware, software, patch, vulnerability and configuration context. UPAS brings both into one workflow so device risk can influence network access and remediation.

Will deployment require a network redesign?

UPAS supports agentless discovery and flexible deployment with existing network infrastructure. Apexagen reviews switch compatibility, network topology, enforcement points and availability requirements before confirming the design.

Deployed to Deliver

Try UPAS in your environment for 60 days

Choose a device discovery, asset visibility or network access-control use case. Apexagen will help define a practical trial scope so your team can evaluate UPAS with its own devices and network.

Request your 60-day free trial