European Alternatives to Zscaler
Looking for a European alternative to Zscaler? Zscaler, Inc. is a San Jose, California company; its End User Subscription Agreement is governed by California law with the courts of Santa Clara County, and its data processing agreement names Zscaler, Inc. as processor and relies on standard contractual clauses and the EU-US Data Privacy Framework for transfers out of the EEA.
Eleven European tools cover parts of the job: zero trust access and private networks, firewall-based remote access, DNS-layer web filtering and one managed SASE service, from companies in Germany, Poland, France, Switzerland, Finland, Denmark and the United Kingdom.
How we rank these tools — 4-step process
-
1
European ownership, verified
The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.
-
2
Category fit and hands-on review
What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.
-
3
Compliance and pricing check
GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.
-
4
Position on this page
Placement on this page can be paid, and that can affect which tools appear here and the order they appear in. It never buys a good review: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.
Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect which tools appear here and the order they appear in. Editorial policy
11 European Alternatives to Zscaler
NetBird
Berlin open-source zero trust network on WireGuard, with a free cloud plan for 5 users and published prices
Defguard
Self-hosted WireGuard access platform from Szczecin with connection-level MFA and an AGPL core
Systancia
French zero trust remote and privileged access platform (cyberelements Gate), as software or SaaS
Open Systems
Zurich managed SASE service with SD-WAN, firewall, secure web gateway, CASB and ZTNA
Stormshield
French firewalls with ZTNA host checks, MFA and per-group application policy included at no extra cost
genua genusphere
Browser-based, VPN-free access to internal applications from a German security vendor
SSH.com PrivX
Helsinki-listed vendor with passwordless, just-in-time access to servers and applications
LANCOM Trusted Access
Cloud-managed trusted access client and VPN from LANCOM, now part of Rohde & Schwarz
Sophos ZTNA
Zero trust access that shares device health with Sophos firewall and endpoint, contracted under English law
Heimdal DNS Security
Copenhagen DNS-layer web filtering for networks and endpoints, with a free trial
Securepoint Cloud Shield
Lueneburg DNS-based web protection for networks and devices, served from servers in Germany
Key takeaways
- Zscaler, Inc. is a San Jose company whose subscription agreement is governed by California law with the Santa Clara County courts, and whose data transfers from the EEA rest on standard contractual clauses and the EU-US Data Privacy Framework.
- NetBird (Berlin) is the most open: a Free plan for 5 users and 100 machines, Team at €6 and Business at €12 per user a month, mostly open-source code, and German law.
- Defguard (Szczecin) is self-hosted with an AGPL core and connection-level MFA, with a free Business tier up to 10 users and one location.
- Systancia (France) and genua (Germany) sell zero trust access to applications without a classic VPN, as software or as a service, with no published prices.
- Open Systems (Zurich) is the only one here that sells a managed SASE service with a secure web gateway, but its own site could not be opened for this page.
- Heimdal and Securepoint filter web traffic at the DNS layer, which is a lighter job than a full web gateway.
Why people leave Zscaler
Zscaler sells security as a cloud service. Companies send their staff's internet traffic and their access to internal applications through it, so that they can replace a VPN and an on-premises web proxy.
Its Private Access product brokers connections between a user and a single approved application instead of giving the user a place on the network, and its own product page lists inline traffic inspection, data loss prevention and browser isolation. It shows no prices: you ask for a demo.
The company is Zscaler, Inc. of San Jose, California. Its End User Subscription Agreement is governed by the laws of California, with the federal and state courts in Santa Clara County as the exclusive venue, and it contains no arbitration clause.
The agreement text does not say which Zscaler entity you contract with. The data processing agreement names Zscaler, Inc. as processor and uses EU standard contractual clauses (with a UK addendum) and the EU-US Data Privacy Framework for transfers out of the EEA.
None of the eleven European tools below copies all of Zscaler. Open Systems comes nearest as a managed service. Most of the others cover the access side (replacing a VPN with per-application access), and two cover only the DNS layer of web filtering. Which one fits depends on which half of the Zscaler job you actually use.
- Your contract and your court are in California The subscription agreement picks California law and the Santa Clara County courts. For a European buyer, a dispute then means litigating on the other side of the Atlantic. The European tools here contract under German, Polish, French, Swiss, Finnish, Danish or English law, and for NetBird, Defguard and Heimdal the venue is the vendor's home court.
- Transfers rely on a framework, not on location Zscaler's data processing agreement handles transfers out of the EEA with standard contractual clauses and certification under the EU-US Data Privacy Framework, and it keeps a list of sub-processors with 30 days' notice and a right to object. That is a lawful route, but it depends on a framework that can change. Self-hosted tools like NetBird, Defguard and genua remove the question because the control plane runs where you put it.
- You may be paying for more than you use Zscaler's platform spans web security, private access, data protection and more, and its pricing is by quote only. A company that mostly wants to retire a VPN may need only the access half, and NetBird, Defguard and Stormshield publish or include that part openly. A company that needs a managed web gateway has fewer European options.
- The European answers are different kinds of product Three are open-source or self-hostable access platforms, three are French or German security vendors that also sell firewalls or on-premises gateways, one is a managed SASE operator, one is a UK security vendor, and two filter at the DNS layer. Treat the list as a menu of parts, not as eleven like-for-like replacements.
What you have to replace, not just match
Start by splitting what Zscaler does for you into two jobs: private access (staff reaching internal apps and servers) and web security (staff browsing the internet, with filtering and inspection). Check which of the two you actually use and which policies sit on top. Access is the easier job to move; the web gateway with inspection and data loss prevention is where Europe has fewer like-for-like options.
Move access first, in parallel. Install one of the access tools next to Zscaler for a small group, move one application at a time, and keep the old path until the logs show nobody uses it. Do not forget identity: every tool here relies on your identity provider for sign-in and MFA, so the work is mostly mapping groups and policies.
The alternatives compared
| Position | Tool | Headquarters | Pricing | Jurisdiction |
|---|---|---|---|---|
| #5 | Stormshield | Issy-les-Moulineaux, France | Enterprise pricing on request | EU (France) |
| #10 | Heimdal DNS Security | Copenhagen, Denmark | Per endpoint, quoted | EU (Denmark) |
How each alternative compares to Zscaler
NetBird
an open, self-hostable zero trust network with published prices
Best for: Teams that want to replace a VPN with identity-based access and can try it free first
NetBird is run by NetBird GmbH, Rosenthaler Str. 36, Berlin, registered at Amtsgericht Berlin (Charlottenburg) under HRB 237529 B. Its terms are under German law, and for business customers the venue is the registered seat of NetBird GmbH.
It builds a private network of peer-to-peer WireGuard connections with a central access policy. Its repository lists SSO and MFA, group-based access rules, device posture checks, traffic event logging, private DNS and re-authentication. Most code is BSD-3-Clause, and the management, signal and relay parts are AGPLv3, so you can self-host with Docker Compose.
Its pricing page lists Free at €0 for up to 5 users and 100 machines, Team at €6 and Business at €12 per user a month, and Enterprise on request, with extra machines at €0.50 a month on Team and Business. Device approvals, MDM and EDR controls, posture checks and traffic logging are on Business.
What NetBird does better than Zscaler
- German company under German law, where Zscaler is governed by California law
- A free plan, published prices and self-hosting, where Zscaler sells by quote
- Open-source code you can read
- Simple per-user pricing
Where NetBird is a step down from Zscaler
- Covers private access only: no web gateway, no inline inspection or data loss prevention
- A much smaller company and platform than Zscaler
- Posture checks and logging are on the €12 Business plan
- Self-hosting makes you responsible for operating it
Standout against Zscaler. It is the only tool here where you can read the code, see the prices and start free before talking to anyone.
Defguard
a self-hosted WireGuard platform with MFA on every connection
Best for: Technical teams that want to run their own access platform and keep all data in their own infrastructure
Defguard Sp. z o.o. is registered at ul. Cyfrowa 6/317, 71-441 Szczecin (KRS 0001168794, EU VAT PL851-332-92-06). Its terms are under Polish law, with the courts competent for its Szczecin seat.
It combines a WireGuard VPN with an identity provider, connection-level MFA (TOTP, WebAuthn, email), firewall rules by user and group, and LDAP or Active Directory sync, and it describes itself as fully self-hosted with no external dependencies. The repository is AGPL for most code, with an enterprise directory under a separate license.
The pricing page lists Open Source as always free, Business as free up to 10 users and one location with paid options, and Enterprise on request. It shows no prices for the paid options.
What Defguard does better than Zscaler
- Polish company under Polish law with a local court
- MFA on the WireGuard connection itself
- A free tier for small teams and an open-source core
- Nothing leaves your infrastructure when self-hosted
Where Defguard is a step down from Zscaler
- No web gateway, inspection or data loss prevention
- Paid Business and Enterprise prices are not shown
- A young, small vendor compared with Zscaler
- You run and patch the servers yourself
Standout against Zscaler. It enforces multi-factor authentication on every WireGuard connection and runs entirely on your own servers.
Systancia
a French zero trust access and privileged access platform
Best for: French and European organizations that want ZTNA for IT and industrial systems, as software or as a service
Systancia is SA SYSTANCIA, Actipolis III, Sausheim, France (RCS Mulhouse 419 687 231, capital €2.5 million). Its homepage describes an independent cybersecurity vendor.
Its platform is branded cyberelements: Gate for zero trust remote access to IT and operational technology systems, Cleanroom for zero trust privileged access, Identity for entitlements, and Access for authentication. It calls itself a Product Leader in KuppingerCole's 2024 Leadership Compass for ZTNA and a representative vendor in Gartner's 2023 Market Guide, which are its own statements. Gate is available as software or as a cloud service, and its site says its data centers are in France.
No prices are shown on its site; you contact it.
What Systancia does better than Zscaler
- French company under French law, with a French register entry
- Covers industrial and operational systems, not only office applications
- Privileged access is in the same suite
- Sold as software or as a service
Where Systancia is a step down from Zscaler
- No published prices
- Does not offer a web gateway with inspection
- Its certifications and rankings are its own claims and were not checked
- A smaller ecosystem than Zscaler
Standout against Zscaler. It treats operational technology and privileged access as part of the same zero trust platform.
Open Systems
the nearest to Zscaler in scope, as a managed Swiss SASE service
Best for: Larger companies that want SD-WAN, firewall, web gateway and ZTNA run for them
Open Systems AG is at Räffelstrasse 29, 8045 Zürich (commercial register number CH-270.3.001.794-5), and the listing of its imprint says it is part of the Swiss Post Group. Switzerland is outside the EU and EEA, but it is within the contracting-entity rule used on this site. Its website terms are under Swiss law with Zürich as venue.
Its platform description lists SD-WAN, firewall, secure web gateway, CASB and ZTNA, run as a managed service with a 24 by 7 operations center and a named customer success manager. This is the only tool in the list that matches Zscaler's breadth in a managed form.
Its own website returned an access error when opened for this page, so these details come from search listings of its pages. The customer contract and prices could not be checked.
What Open Systems does better than Zscaler
- Covers a secure web gateway and ZTNA together, which most others here do not
- Managed by the vendor, with a service team
- Swiss company and Swiss-law website terms
- Operated for large, multi-country customers
Where Open Systems is a step down from Zscaler
- No published prices and no self-service trial
- Its site could not be opened, so claims are unverified
- Customer contract and hosting locations not checked
- Switzerland is outside the EU and the EEA
Standout against Zscaler. It sells the SASE package as a managed service, which no other tool here does.
- Which law reaches it. EU (France). Zscaler is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
- Where the data sits. Mostly the EEA, with international transfers under EU standard contractual clauses.
- Source code. Closed source, as Zscaler is.
- Independently checked. ANSSI CSPN, CCN-LINCE (Spain), Cybersecurity Made in Europe label.
Best for: Organizations that already run or plan to run next-generation firewalls and want ZTNA on top
Stormshield is a French société par actions simplifiée at 2-10 rue Marceau, Issy-les-Moulineaux (RCS Nanterre 428 173 975, capital €2.79 million). Its website is hosted by OVHcloud.
Its ZTNA page describes host checks on the workstation (operating system, domain, firewall, VPN client, antivirus), a zero-trust policy per user or group, multi-factor authentication, micro-segmentation and, in firmware 5, single sign-on. A ZTNA agent opens a VPN connection from the workstation to the allowed resources. Stormshield says all of this is included in its products at no extra cost.
It is a firewall-based approach, so you run the appliances, not a cloud service.
What Stormshield does better than Zscaler
- ZTNA features are included in the firewall, with no separate license
- French company with a French register entry
- Host-compliance checks before access is granted
- Suited to industrial and public-sector sites
Where Stormshield is a step down from Zscaler
- You run the firewalls; there is no global cloud broker
- No cloud web gateway with inspection like Zscaler Internet Access
- Prices are not shown on the pages opened
- Less suited to a company with no hardware or with many small sites
Standout against Zscaler. It treats ZTNA as a feature of the firewall you already buy.
genua genusphere
browser-based access to internal applications without a VPN client
Best for: Public-sector and regulated organizations that want zero trust access they can run themselves
genua GmbH is at Domagkstrasse 7, 85551 Kirchheim near Munich (HRB 98238, Amtsgericht München), and its homepage says it is a subsidiary of the Bundesdruckerei Group.
genusphere gives users browser-based access to the applications they are allowed to use, with no VPN client, role-based authorization, encryption of all traffic, audit-proof logging and sign-in through Microsoft Entra ID or Keycloak. It can run on-premises, on Kubernetes or in the cloud, and genua says the operator keeps full data sovereignty.
genua also sells VPN clients and firewall appliances (genuconnect, genuscreen). No prices are shown; you contact sales.
What genua genusphere does better than Zscaler
- Runs where you decide, with the operator keeping the data
- No client software needed for browser-based access
- German vendor, part of the Bundesdruckerei Group
- Part of a wider range of firewalls and VPN products
Where genua genusphere is a step down from Zscaler
- Applications reached by browser only, not all network protocols
- No web gateway or data loss prevention
- No published prices and no free tier
- You operate the platform yourself
Standout against Zscaler. It gives users access to applications in a browser, with no client and no VPN.
SSH.com PrivX
passwordless, just-in-time access for servers and applications
Best for: IT and DevOps teams that mainly need controlled access to servers and infrastructure
SSH Communications Security Oyj has its global headquarters at Karvaamokuja 2D, Helsinki. I could not open its terms, so its contracting law is not confirmed here.
PrivX is described on its product page as a privileged access management product built on zero standing privileges, ephemeral and passwordless access, with certificate-based authentication for both people and machines. It is aimed at cloud-native environments, and the page offers a free trial but no price.
It is closer to privileged access than to a user-wide web and application gateway, so it replaces part of Zscaler's private access use, not its web security.
What SSH.com PrivX does better than Zscaler
- Finnish company (an Oyj, a public limited company)
- Passwordless, short-lived access reduces standing credentials
- Built for servers, containers and cloud infrastructure
- A free trial
Where SSH.com PrivX is a step down from Zscaler
- Not a general web or application gateway for all staff
- No published prices
- Terms and governing law could not be checked
- Sold as a privileged-access product, not a SASE platform
Standout against Zscaler. It removes standing credentials: access is granted just in time, on certificates, and expires.
LANCOM Trusted Access
cloud-managed trusted access from a German network vendor, now part of Rohde & Schwarz
Best for: Organizations that already use LANCOM networking and its Management Cloud
Since 1 July 2026, LANCOM Systems appears under the name Rohde & Schwarz Networks and Cybersecurity GmbH, Adenauerstrasse 20/B2, Würselen (HRB 16976, County Court Aachen). Its Management Cloud is listed as ISO/IEC 27001 certified.
LANCOM Trusted Access is described in a 2022 press release and datasheet as a cloud-managed access client for office, home and mobile staff, with Active Directory integration through the Management Cloud and access limited to assigned applications, and optionally also usable as a managed VPN client.
The current product page returned a not-found error and the homepage does not mention ZTNA, so this entry rests on older documents. Check that the product is still sold under this name before you plan around it.
What LANCOM Trusted Access does better than Zscaler
- German company, with cloud management said to be GDPR-compliant
- Fits into LANCOM networks and SD-WAN
- Active Directory integration
- ISO/IEC 27001 listing for its management cloud
Where LANCOM Trusted Access is a step down from Zscaler
- Current product details could not be verified
- No web gateway or data loss prevention
- No published prices
- Best value only if you already run its networking
Standout against Zscaler. It manages the trusted access client from the same cloud as your LANCOM networks.
Sophos ZTNA
zero trust access that shares device health with Sophos firewall and endpoint
Best for: Organizations that already run Sophos endpoint and firewall products
Sophos' end-user terms name Sophos Limited as the contracting company for customers outside the United States, Canada and Latin America, under the law of England and Wales with English courts. Who owns the group was not checked for this page.
Its ZTNA page describes multi-factor authentication, device health checks in access policies, micro-segmentation, and automatic isolation of a compromised device through Synchronized Security and Active Threat Response. It is built into Sophos Protected Browser with RDP and SSH clients, and sold as part of the Sophos Workspace Protection bundle.
No prices are shown on its page.
What Sophos ZTNA does better than Zscaler
- English-law contract with an English court, for customers outside the Americas
- Device health decides access automatically
- Integrated with a firewall and endpoint you may already own
- Isolates a compromised device without manual steps
Where Sophos ZTNA is a step down from Zscaler
- The UK is outside the EU and EEA
- Strongest if you already use Sophos products
- No published prices
- Group ownership was not verified
Standout against Zscaler. Access decisions follow the device health reported by the rest of the Sophos stack.
- Which law reaches it. EU (Denmark). Zscaler is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
- Where the data sits. Customer-selectable data centre: EU (Netherlands or Germany), UK, US or UAE.
- Source code. Closed source, as Zscaler is.
Best for: Small and mid-sized organizations that mainly want to block malicious and unwanted domains
Heimdal Security A/S is at Vester Farimagsgade 1, Copenhagen (CVR 35 80 24 95). Its license agreement is under Danish law, with the Copenhagen city court as the venue in the first instance, apart from some cases such as non-payment or IP infringement.
Its DNS Security product has a network and an endpoint variant. The vendor describes a local DNS filter (DarkLayer Guard) with allow and block lists, DNS over HTTPS filtering, category blocking and logging. Its homepage offers a free trial and sends visitors to a bundles page for pricing, which I did not open.
It filters at the DNS layer, so it does not decrypt and inspect web traffic.
What Heimdal DNS Security does better than Zscaler
- Danish company under Danish law, with a Copenhagen venue
- Light to deploy compared with a full gateway
- Free trial
- Part of a wider endpoint and patching platform already on this site
Where Heimdal DNS Security is a step down from Zscaler
- No private application access or ZTNA
- DNS filtering only, no inline inspection or data loss prevention
- Prices not checked
- Not designed for the largest enterprises
Standout against Zscaler. It adds DNS filtering to an endpoint security platform and can run on the device or the network.
Securepoint Cloud Shield
German DNS-based web protection served from servers in Germany
Best for: German small and mid-sized businesses and their IT service partners
Securepoint GmbH is at Bleckeder Landstraße 28, Lüneburg, registered at the Lüneburg commercial register. It also has a Swiss subsidiary in Baar.
Cloud Shield routes DNS requests from devices through Securepoint's own servers with regularly updated filter lists, using encrypted DNS (DNS over TLS or HTTPS). Its documentation lists category and content filtering, including time-based rules, and says the servers are in Germany. It sits beside Securepoint's firewalls, mail security and managed detection.
No prices are shown on its pages, and documentation is largely in German.
What Securepoint Cloud Shield does better than Zscaler
- German company with servers in Germany
- Part of a package with firewalls and mail security
- Simple to switch on by pointing DNS at it
- Sold alongside firewalls and mail security from the same vendor
Where Securepoint Cloud Shield is a step down from Zscaler
- DNS filtering only, no inline inspection
- No private application access
- Documentation mostly in German
- No published prices
Standout against Zscaler. It is the German DNS filter you can pair with Securepoint firewalls and mail security from one partner.
What actually breaks when you switch
The hard part of leaving Zscaler is policy, not software. Years of web categories, application segments, exceptions and SSL inspection rules do not export to another tool. Export what you can, then rebuild the rules in the new tool one group of users at a time, and keep Zscaler on for the rest until the new rules have run clean.
If you use Zscaler for inline inspection and data loss prevention, the tools here are mostly thinner. Only Open Systems describes a web gateway with CASB, and its site could not be opened, so ask for a trial and read the contract. Heimdal and Securepoint filter DNS only.
Several prices are not shown, including Systancia, genua, Open Systems, Sophos, Stormshield, SSH.com, LANCOM and Securepoint. Only NetBird publishes a full price list, and Defguard publishes its free tiers. Ask for a written quote that covers the number of users, sites and log retention you actually need.
Is there a European tool that does everything Zscaler does?
Not in a single product that I could verify. The closest in scope is Open Systems of Zurich, which describes a managed SASE platform with SD-WAN, firewall, secure web gateway, CASB and ZTNA. Its site could not be opened for this page, so check the current service description and the customer contract directly.
For the rest, you combine parts: an access tool (NetBird, Defguard, Systancia, genua, SSH.com, Stormshield, LANCOM or Sophos) for private applications, and DNS filtering (Heimdal, Securepoint) or a firewall with web filtering for browsing.
Which of these can I try without talking to sales?
NetBird has a Free plan with up to 5 users and 100 machines and publishes its prices. Defguard's Open Source edition is free and its Business edition is free for up to 10 users and one location. SSH.com offers a free trial of PrivX, and Heimdal's homepage offers a free trial.
Systancia, genua, Open Systems, Sophos, Securepoint and LANCOM show no prices on the pages I could open, so expect a quote.
Can I host it myself?
NetBird can be self-hosted with a Docker Compose quickstart, and Defguard describes itself as fully self-hosted. genusphere runs on-premises or on Kubernetes, and Systancia sells Gate as software or as a service. Stormshield's ZTNA is a feature of its firewalls, which you run yourself.
Self-hosting moves operational work onto you. If you want somebody else to run it, the managed options are NetBird's cloud plans, Systancia's SaaS, Open Systems and Heimdal.
How is this different from a VPN?
A classic VPN puts a user on a network. Zero trust access, as Zscaler Private Access and the tools here describe it, checks the user and often the device and then allows a connection to specific applications or groups of resources. Some tools here, such as NetBird and Defguard, build on WireGuard but add identity, group policy and MFA on top. genusphere goes further and gives browser access to approved applications without a client.
Which one to pick
If you want to retire a VPN and try the replacement yourself, start with NetBird: it is the one with a free plan, published prices and open code. Defguard is the choice for a technical team that wants to run the platform on its own servers.
If you want a French or German vendor with a public-sector profile, look at Systancia, genua or Stormshield. If you want a managed service that covers the web gateway too, Open Systems is the only one in the list that describes it, and it needs a careful look at the contract because its site could not be opened.
Heimdal and Securepoint are light DNS filters, not gateways. Choose them if blocking bad domains is the job, not if you need inspection.
Be realistic about the gap. Zscaler is a large cloud platform that inspects traffic inline and prices by quote, and none of the eleven matches all of it. Switch if California law and a Santa Clara County venue are the problem, and keep Zscaler for the web security you cannot yet replace.
Frequently Asked Questions
It depends on the job. NetBird scores highest on this page because you can try it free, read the prices, and self-host it, but it is an access network and not a web gateway. If you need a managed SASE service with a secure web gateway, Open Systems is the one to look at first. If you want zero trust access from a French or German vendor with a public-sector profile, look at Systancia or genua.
No. Zscaler, Inc. is in San Jose, California. Its subscription agreement is governed by California law, and the exclusive venue is the federal and state courts in Santa Clara County. The agreement does not name a specific Zscaler entity, and its data processing agreement names Zscaler, Inc. as processor.
Its data processing agreement relies on EU standard contractual clauses and a UK addendum, and says the company is certified under the EU-US Data Privacy Framework, the UK extension and the Swiss-US framework. It keeps a list of sub-processors, gives 30 days' notice of new ones, and lets customers object on data protection grounds.
Its product pages show no prices. You request a demo or contact sales. For comparison, NetBird lists €6 per user a month on Team and €12 on Business, with a Free plan, and extra machines at €0.50 a month on those two plans.
NetBird GmbH in Berlin (Amtsgericht Charlottenburg, HRB 237529 B) lists Free at €0 for up to 5 users and 100 machines, Team at €6 and Business at €12 per user a month, and Enterprise on request. Its terms are under German law, and for business customers the venue is the seat of NetBird GmbH. Most of the code is BSD-3-Clause, with AGPLv3 for the management, signal and relay parts.
Mostly. Its repository uses the AGPL for most code, and a separate enterprise directory under its own license. Defguard lists an Open Source edition as always free, and a Business edition that is free for up to 10 users and one location, with paid options for more. The contracting company is Defguard Sp. z o.o. in Szczecin (KRS 0001168794) under Polish law.
genua is a subsidiary of the Bundesdruckerei Group, by its own homepage. Open Systems describes itself in its imprint listing as part of the Swiss Post Group. LANCOM Systems is now Rohde & Schwarz Networks and Cybersecurity GmbH since 1 July 2026. For Sophos, its terms name Sophos Limited and English law, and I did not verify who owns the group.
Its end-user terms name Sophos Limited as the contracting company for customers outside the United States, Canada and Latin America, under the law of England and Wales with English courts. The United Kingdom is outside the EU but is covered by the contracting-entity rule used on this site. Its ZTNA is sold inside the Sophos Workspace Protection bundle with no public price.
Only in part. Heimdal DNS Security and Securepoint Cloud Shield both filter at the DNS layer, which blocks known bad and unwanted domains before a connection is made. They do not decrypt and inspect traffic the way a full web gateway does. They suit small and mid-sized organizations that mainly want category blocking and malware protection.
Several describe themselves that way. Stormshield and genua are aimed at public-sector and critical-infrastructure buyers, and LANCOM's Management Cloud is listed as ISO/IEC 27001 certified. Systancia describes recognition by KuppingerCole and Gartner. These are the vendors' own statements, and I did not verify any certificate, so ask for the document.
Related comparisons
European tools head to head
Explore More European Alternatives
Discover privacy-focused European alternatives to other popular US tech services.