The Platform · Control. Peace of Mind.

Generation 3 Zero TrustA new trust model for modern infrastructure

Most cybersecurity platforms focus on protecting users and applications. Faction extends Zero Trust principles to infrastructure, OT and IoT devices, data, and AI-enabled operations.

What Makes Generation 3 Different

Finally, Zero Trust Has a Secure Foundation

01

Zero Knowledge Architecture

Faction routes encrypted communications without holding your encryption keys or any decryptable content. Customers have full visibility and control inside of their network, Faction has none.

02

Owner-Controlled Keys

Organizations create, control and store the keys to their Faction Network. Trust and trust relationships originate with the owner, not the vendor.

03

Zero Trust for the Cloud

Faction leverages all the benefits of the Cloud, but never trusts centralized infrastructure — even our own — that becomes a high-value target.

04

Hardware-Embedded Zero Trust

Faction Pods and Portals secure OT, IoT, embedded systems, and infrastructure, making them invisible and unreachable on the Internet.

05

AI Security

Secure private AI infrastructure and ensure human identity-bound accountability and policy enforcement for Agentic AI.

06

Cyber Assurance

Independent Cyber Lab inspection and verification of hardware + supply chain and continuous monitoring of network integrity back up Zero Trust.

Architecture Overview

Trust you can understand and verify

Generation 3 Zero Trust is more than a security philosophy — it is a different architecture. See where Faction sits, what it controls, and how it reduces dependency on centralized infrastructure.

High-Level Architecture

Where Faction sits

Endpoints connect through a Waypoint into a single encrypted overlay that governs networks, devices, data, OT/IoT, and AI. The Waypoint forwards traffic but sees only routing metadata, and the control plane stays off the public internet — reachable only from inside your Faction.

Users & Devices
Waypointinternet-reachable · routing metadata only
Your Factionencrypted overlay · owner holds the keys
Networks
Devices
Data
OT / IoT
AI Systems
How Faction Differs

Trust controlled by you, not by us

Traditional cloud ZTNA routes you through a vendor control plane. Faction establishes a direct, encrypted relationship governed by trust the owner creates and holds.

Traditional Cloud ZTNA
User
Cloud Control Planevendor holds trust · public target
Application
Faction
User
Owner-Controlled Trust
End-to-End Encryptedkeys held by owner
Resource
AI Security Model

AI security with human control and accountability

Secure your private AI infrastructure in a Faction Network, and deploy a Faction Trust & Control Layer to enforce policy and governance, control access, contain the blast radius, and keep a verified human in the loop.

AI Agentsrequest access · execute actions
AI Cyber Guardian
AI Governancemonitors & executes policy
Controls AI access & contains the blast radiusFaction Trust & Control LayerEnsures human-in-the-loop control
Resources & Devicesaccess · control · execution
Cryptographic Kill Switch
Human Approvalun-bypassable enforcement
Partner Deployment Model

Built for MSPs and integrators

Deliver Generation 3 cybersecurity to your clients with peace of mind. Client ownership and control of keys and trust ensure that you can never become the point of compromise.

MSP / MSSP DashboardSingle Pane of Glass
End-to-End Encryptedkeys held by owner
Customer Aowns & controls trust
Customer Bowns & controls trust
Customer Cowns & controls trust
OT & IoT Security Model

Protection for devices that can't protect themselves

Faction Pods and Portals extend Zero Trust protection to OT and IoT machines and devices that can't protect themselves — regardless of operating system, age, or capability.

Devices that can't run agents
IP Camera
Sensor
PLC / Controller
Legacy Machine
Faction Pod / Portalembedded zero trust hardware gateway — nothing installed on the device
E2EEprivate tunnel to your Faction Network · content encrypted end to end
Your Faction Networkowner-controlled overlay · off the public internet
Four Areas of Control

Four Zero Trust pillars for your Cyber Security

PILLAR / 01

Networking

Secure networking built around owner-controlled trust and reduced dependence on centralized control infrastructure.

PILLAR / 02

OT & IoT

Protection for the devices traditional, software-only security models struggle to secure.

PILLAR / 03

Data

Encryption and trust governed by the organization rather than third-party vendors.

PILLAR / 04

AI

Identity-bound governance, accountability, and policy enforcement for AI-enabled operations.

How Faction Works

Security built around ownership of trust

STEP / 01

Deploy alongside existing infrastructure

No rip-and-replace required. Faction is an overlay on what you already operate.

STEP / 02

Create owner-controlled trust

Encryption keys that secure your trust relationships are created, controlled and stored by the Faction Network Owner, not Faction.

STEP / 03

Authenticate with cryptographic identity

Users and devices are verified out-of-band, impervious to phishing and credential theft.

STEP / 04

Escalate to Human Identity when needed

Flexible levels of verification are available when you need to ensure human control and accountability.

STEP / 05

Extend protection to OT & IoT

Secure the devices software-only models can't, using Pods, Portals, and embedded capabilities.

STEP / 06

Gain Peace of Mind

Your security does not depend on a vendor's infrastructure, untrustworthy hardware, and unknowable Cloud vulnerabilities.

Cyber Assurance

Trust that is verified, not assumed

Generation 3 is more than architecture — it is a commitment to verification. Faction's assurance program applies independent inspection, hardware analysis, and continuous monitoring so trust can be verified, not just claimed.

Independent security testing

Source code and protocol inspection by independent cyber labs.

Hardware assurance

Chip-off and motherboard analysis. ORION Assured.

Continuous monitoring

Assurance is ongoing — not a one-time certification or a checkbox.

Three Generations at a Glance

The three generations, side by side

Architecture, network visibility, authentication, device coverage, data — and, ultimately, who holds the keys. Here is how the three generations compare across the dimensions that decide an organization's security posture.

CapabilityGen 1 — VPNs & FirewallsGen 2 — Cloud ZTNA / SDNGen 3 — Faction
ArchitecturePerimeter gatewayCloud control planeZero Knowledge · no public control plane
Network visibilityExposed, scannableCloud broker visibleInvisible by default
AuthenticationCredentials (phishable)Cloud IAM + 2FAOut-of-band cryptographic key
Certificate authorityPublic internet CAPublic internet CAThe network owner is the CA
Encryption keysGateway-managedVendor / cloud-heldCreated & held by the owner
OT / IoT devicesUnprotectedSoftware onlyPods, Portals, Modules
AI agent controlNoneCloud IAM (vulnerable)Identity-bound governance
Data encryptionIn transit onlyIn transit onlyIn transit and at rest
Cloud VulnerabilityHighBetter, but still centralizedZero — owner holds the keys

See the architecture in your environment

Request a technical briefing and we'll walk through how Faction establishes trust across your networks, devices, data, and AI.