VPN for Healthcare & Legal Professionals: GDPR-Compliant Remote Access for Confidential Data
VPN for Healthcare & Legal Professionals: GDPR-Compliant Remote Access for Confidential Data
VPN for healthcare providers, law firms, and tax advisors: how professionals handling confidential data meet GDPR, HIPAA, and professional secrecy requirements with NetBird. End-to-end encryption, audit logging, and certified infrastructure.
Content notice: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, pricing, versions, licensing models and external content are subject to change. Please verify the information independently, especially before making business-critical or security-relevant decisions. This article does not constitute individual professional, legal or tax advice.
Healthcare providers, lawyers, and tax advisors share a common obligation: they handle some of the most sensitive data that exists. Patient records, legal case files, tax returns — unauthorized disclosure of this data does not just trigger regulatory fines. In many jurisdictions, it constitutes a criminal offense.
Under German law (section 203 StGB), healthcare providers and lawyers face imprisonment of up to one year for unauthorized disclosure of professional secrets — including through insecure IT systems. Under HIPAA in the United States, violations carry fines up to USD 1.5 million per category per year. Under GDPR, which applies across the entire European Union, fines reach EUR 20 million or 4% of global turnover. In the UK, Australia, and Canada, equivalent professional privilege and data protection laws impose similar obligations.
At the same time, the reality of modern practice demands remote access. Home office, satellite offices, house calls, external consultants — staff need to reach patient management systems, document management systems, and case files from outside the office network. The question is not whether to allow remote access, but how to secure it.
This article explains the regulatory requirements that professionals handling confidential data must meet, why legacy VPN solutions typically fall short, and how a modern Zero Trust VPN with NetBird and birdhost closes the compliance gap.
Also worth reading: NIS2 and Network Security · Setting Up a Business Network for Remote Employees · Sophos VPN Alternative 2026
The Regulatory Landscape: Why IT Security Is a Professional Obligation
Professionals handling confidential data operate under multiple, overlapping legal frameworks. The specifics vary by country, but the core requirements are remarkably consistent: encrypt data in transit, control who can access what, log access for audit purposes, and authenticate users with more than just a password.
GDPR Article 32 — Security of Processing (EU-Wide)
The General Data Protection Regulation applies across all 27 EU member states, the EEA, and — through adequacy decisions and contractual mechanisms — affects organizations worldwide that process EU residents' data.
Article 32 requires "appropriate technical and organizational measures" to protect personal data. The level of protection must be proportionate to the risk. For health data, Article 9 applies — "special categories of personal data." Patient records, diagnoses, treatment histories, and even the fact that someone is a patient at a particular practice all fall under Article 9's heightened protections.
Article 32(1) names specific measures:
- Encryption of personal data
- The ability to ensure confidentiality, integrity, availability, and resilience of processing systems
- Procedures for regularly testing and evaluating the effectiveness of those measures
For remote access to practice systems, this translates directly into: encryption is mandatory, access control is mandatory, audit logging is mandatory — and all measures must be regularly reviewed.
German Professional Secrecy — Section 203 StGB
Germany imposes some of the strictest professional secrecy obligations in the world. Section 203 of the German Criminal Code (Strafgesetzbuch) makes it a criminal offense for healthcare providers, lawyers, notaries, tax advisors, and auditors to disclose client or patient secrets without authorization.
Critically, the law covers not just active disclosure but also "making accessible." If patient data is transmitted over an unencrypted connection, or if an unsecured remote access path allows unauthorized access to case files, the offense may already be committed.
Consequences of violations:
- Imprisonment up to one year or a fine (section 203(1) StGB)
- Up to two years if committed for profit (section 203(5) StGB)
- Professional disciplinary sanctions (medical chamber, bar association)
- Civil liability for damages
- GDPR fines on top
The 2017 reform (section 203(3) StGB) clarified that engaging IT service providers ("other participants") is permissible — provided they are contractually bound to confidentiality and technical measures prevent unauthorized access to protected data.
HIPAA — US Healthcare (For Comparison)
In the United States, the Health Insurance Portability and Accountability Act (HIPAA) establishes comparable requirements for "covered entities" — healthcare providers, health plans, and their business associates.
The HIPAA Security Rule mandates Technical Safeguards including:
- Access controls (unique user identification, emergency access procedures)
- Audit controls (hardware, software, and procedural mechanisms to record and examine access)
- Transmission security (encryption of ePHI in transit)
- Authentication (procedures to verify that a person seeking access is who they claim to be)
HIPAA violations carry fines up to USD 1.5 million per violation category per year. Willful neglect with no correction can result in criminal prosecution.
Professional Privilege — UK, Australia, Canada
In the United Kingdom, the Data Protection Act 2018 (implementing the UK GDPR) and the Solicitors Regulation Authority (SRA) Standards impose data security obligations on both healthcare providers and lawyers. Legal professional privilege is a fundamental right, and the SRA expects firms to take "effective steps" to protect client information.
In Australia, the Australian Privacy Principles (APPs) under the Privacy Act 1988 and the Health Records Act require healthcare providers to take "reasonable steps" to protect health information. The Legal Profession Uniform Law imposes confidentiality duties on lawyers.
In Canada, PIPEDA and provincial health information laws (such as Ontario's PHIPA) govern the handling of health data, while law societies enforce confidentiality through codes of professional conduct.
The common thread across all jurisdictions: encryption, access control, audit logging, and strong authentication are not optional — they are the minimum standard of care.
KBV IT Security Directive — German Healthcare Specifics
For readers operating medical practices in Germany: the Kassenärztliche Bundesvereinigung (KBV) published a binding IT Security Directive under section 75b SGB V. It differentiates requirements by practice size (1-5 staff, 6-20, 20+, and practices with large medical devices). Requirements include encrypted connections for all remote access, user authentication before accessing patient data, network segmentation, documented access rights, and — for larger practices — incident response procedures and security audits.
BRAO/BORA — German Legal Profession Specifics
German lawyers are bound by section 43a(2) BRAO (Federal Lawyers' Act) requiring confidentiality and section 2 BORA (Professional Code of Conduct) requiring organizational measures to protect it — explicitly including IT infrastructure. The Federal Bar Association (BRAK) has stated that IT security measures must meet the current state of the art.
Real-World Scenarios: Where Remote Access Becomes Necessary
Scenario 1: Medical Practice with Remote Staff
A general practice with three doctors and eight medical assistants. Two assistants work partly from home — handling appointment scheduling, prescription requests, and documentation. They need access to the Practice Management System (PMS) and electronic patient records.
The problem: The practice uses a consumer router with built-in VPN. The two remote workers connect through it. There is no separate access control — anyone who connects has access to the entire practice network, including billing systems, the radiology PACS server, and the file server. No audit log exists. MFA is not configured.
Why this is problematic:
- No access control: the remote assistant needs access to the PMS, not to the PACS or billing systems
- No audit log: in the event of a data breach, there is no record of who accessed what and when
- No MFA: a compromised password grants immediate full access to all patient data
- GDPR Article 32 requires measures proportionate to the risk — health data demands the highest level of protection
Scenario 2: Law Firm with Multiple Offices
A mid-sized law firm with headquarters in one city and a branch office in another. Twelve lawyers and eight support staff work across both locations. The Document Management System (DMS) runs on a server at headquarters; the branch office needs permanent access.
The problem: The site-to-site connection runs through an IPsec tunnel between two hardware firewalls. Both require static IP addresses and regular firmware updates. A lawyer working from home uses the firewall's SSL VPN client — without MFA and with access to the entire headquarters network.
Why this is problematic:
- After authentication, the VPN grants access to the entire network — no resource-based control
- Lawyers in one practice group can access case files from other practice groups, even when there is no need
- Professional conduct rules require "ethical walls" (information barriers) — including within the firm's IT
- Firmware updates carry the risk of VPN outages; each update is a potential disruption
Scenario 3: Multi-Provider Healthcare Center with External Physicians
A multi-provider healthcare center (such as a German MVZ or a group practice) with four employed physicians and three external consulting physicians who work part-time from their own practices. The external physicians need access to the clinical information system — but only for their own patients.
The problem: External physicians receive the same VPN access as employed staff. Restricting access to specific patients must happen at the application level — but the externals have network access to all systems including billing, HR, and backup servers.
Why this is problematic:
- External physicians have network access far beyond what their role requires
- The principle of least privilege is violated
- External physicians' devices are not managed by the center's IT — a potential security risk
- Under most regulatory frameworks, even unauthorized access (not just active disclosure) can constitute a violation
Scenario 4: Accounting Firm with Client Document Exchange
An accounting or tax advisory firm wants to provide selected clients with secure access to document exchange — as an alternative to sending tax returns, financial statements, and payroll documents via email.
The problem: The firm currently uses a third-party cloud portal for document exchange. The provider stores data on US-based servers. A Data Processing Agreement exists, but GDPR compliance after the Schrems II ruling is questionable. Alternatively, documents are sent via encrypted email — which regularly fails in practice because clients cannot use S/MIME or PGP correctly.
Why this is problematic:
- Client data on US servers creates tension between the US CLOUD Act and GDPR
- Professional secrecy obligations apply even vis-a-vis the cloud provider
- Email encryption is rarely used correctly by non-technical recipients
Why Legacy VPN Solutions Fall Short for Regulated Professions
The regulatory requirements across all frameworks distill into four technical demands:
- Encryption of all connections using current standards
- Granular access control following the least-privilege principle
- Auditability through access logging
- Authentication security through multi-factor authentication
Legacy VPN solutions typically fulfill point 1 — and fail on points 2, 3, and 4.
Consumer Router VPN (FritzBox, ISP Devices)
Consumer routers are the de facto standard in small practices and firms. The built-in VPN (WireGuard or IPsec) provides basic encryption — and nothing else.
No access control: Every VPN user has full access to the entire LAN after connecting. Restricting access to specific servers or ports is not possible. A remote assistant can reach not just the practice management system, but also the billing server, PACS, and network printers.
No audit logging: Consumer routers log VPN connections only at the most basic level — connection start and end times. Who accessed which system within the VPN is not recorded. In the event of a data breach, there is no trail.
No MFA integration: Consumer routers have no SSO, no LDAP, no identity provider integration. Authentication uses pre-shared keys or the router's own credentials. MFA is not supported.
Scale limitation: Maximum approximately 10 simultaneous VPN connections depending on model. Unusable for a multi-provider center or a firm with multiple offices.
Enterprise Firewalls (Sophos XGS, Fortinet, Cisco)
Enterprise firewalls offer significantly more functionality — but with considerable complexity and cost.
Central gateway as bottleneck: All VPN traffic flows through the firewall appliance. With 20 simultaneous VPN users, the hardware becomes a bottleneck — especially when using SSL VPN (which relies on OpenVPN and is significantly slower than WireGuard).
Vendor lock-in and complexity: Configuring an enterprise firewall for granular VPN access requires specialist knowledge. Firmware updates can break VPN connections. Vendor EOL cycles (such as Sophos UTM reaching end-of-life) force costly migrations.
Access control in theory only: Granular access control is technically possible through firewall rules, zones, and user groups. In practice, most configurations place all VPN users in a "VPN zone" with access to the entire "LAN zone." The granularity remains theoretical.
Cost: Enterprise firewalls with VPN licensing typically cost EUR 200 to 500 per month (lease plus license), plus implementation costs and ongoing administration — or an IT service provider to manage the appliance.
OpenVPN (Self-Hosted)
OpenVPN offers maximum flexibility but also maximum operational overhead.
Certificate management: OpenVPN relies on a PKI infrastructure. Every user needs a certificate, every certificate has an expiration date, and every expired certificate creates a support ticket. For a practice without a dedicated IT department, this is unsustainable.
Cipher misconfiguration risk: OpenVPN allows configuration of cipher suites. This sounds like an advantage but is a risk in practice: misconfigurations (weak ciphers, disabled PFS, outdated TLS versions) are common and difficult to detect.
No native Zero Trust: Access control is only possible through additional firewall rules on the VPN server. OpenVPN itself has no identity-based access control.
How NetBird and birdhost Meet the Requirements
NetBird is an open-source mesh VPN built on WireGuard and designed from the ground up as a Zero Trust solution. birdhost provides managed NetBird hosting: dedicated instances hosted in ISO 27001 and SOC 2 certified data centers, fully managed.
Requirement: State-of-the-Art Encryption (GDPR Art. 32, HIPAA, Professional Secrecy Laws)
NetBird uses WireGuard as its encryption protocol. WireGuard employs modern cryptography: ChaCha20 for symmetric encryption, Curve25519 for key exchange, Poly1305 for authentication, and BLAKE2s as hash function.
The critical difference from OpenVPN and firewall-based SSL VPN: there are no configurable cipher suites. The cryptography is fixed and always current. Misconfiguration is impossible.
All connections are end-to-end encrypted — directly between peers. There is no central gateway where traffic is decrypted and re-encrypted. Even birdhost as the managed hosting provider cannot read the data traffic. For professionals bound by secrecy obligations, this is essential: even the IT service provider has no technical access to the transmitted data.
Requirement: Granular Access Control (Least Privilege, GDPR, HIPAA, Professional Conduct Rules)
NetBird provides identity-based Access Policies. Administrators define granularly which user group may access which resource — including protocol restrictions (TCP, UDP) and port ranges.
Example — medical practice:
- Group "Remote Assistants" -> Access to PMS server (port 443) and printer
- Group "Physicians" -> Access to PMS, PACS, lab interface
- Group "Billing" -> Access to PMS and billing system
- Group "External IT" -> Access to practice server only (SSH, port 22), time-limited
Example — law firm:
- Group "Employment Law" -> Access to DMS employment law section
- Group "Criminal Law" -> Access to DMS criminal law section
- Group "Secretariat" -> Access to DMS, printers, phone system
- Group "Client Access" -> Document exchange folder only, time-limited
This access control is configured graphically in the web UI — no JSON policies, no iptables, no firewall rule sets.
Additionally, NetBird offers Posture Checks: only devices that meet defined security requirements (current operating system, active firewall, correct NetBird version) are granted access at all. An external physician's personal device without up-to-date security software is automatically blocked.
Requirement: Audit Logging and Traceability (GDPR Art. 32, HIPAA Audit Controls)
NetBird logs:
- Every connection (who connects, when, from where)
- Every policy change (who modifies which access rule, when)
- Every login and authentication event
- Device registrations and deactivations
These logs are precisely the evidence required during an audit by a data protection authority, a medical board, or a bar association. "Who accessed the practice network on March 15 at 14:23?" — this question can be answered.
Requirement: Multi-Factor Authentication (State of the Art, HIPAA, GDPR)
NetBird handles MFA through native SSO integration. Authentication runs through the organization's identity provider — Azure AD, Google Workspace, Okta, Keycloak, or Authentik. When the IdP enforces MFA, this automatically applies to VPN access as well.
For practices and firms already using Microsoft 365 or Google Workspace, this means: MFA is activatable without additional infrastructure. No separate token management, no RSA tokens, no additional apps.
Requirement: Data Sovereignty and Compliant Hosting (GDPR, Schrems II, HIPAA)
birdhost operates infrastructure across multiple regions, hosted in ISO 27001 and SOC 2 certified data centers (certifications held by the data center operators). For EU-based organizations handling health or legal data, EU hosting (Germany, Netherlands) is recommended — no metadata leaves the EU, no US cloud provider in the stack, no CLOUD Act exposure, no Schrems II concerns.
For organizations in other regions, birdhost also offers hosting in North America (US, Canada) and Asia-Pacific (Singapore, Japan, India).
A Data Processing Agreement (DPA) is available directly through the merkaio portal — no negotiations with a US legal department required.
NetBird is 100 percent open source. The entire codebase — client, management server, signal server, relay — is available on GitHub and fully auditable. For regulated professionals who engage IT service providers, this transparency is a decisive advantage.
Step-by-Step: Setting Up Secure Remote Access for a Medical Practice
Starting Point
A group practice with three physicians, ten medical assistants, and two home office workstations (appointment management and documentation). On the practice network:
- PMS server (Practice Management System) — 192.168.1.10
- PACS server (radiology images) — 192.168.1.11
- Lab interface — 192.168.1.12
- Network printer — 192.168.1.20
- NAS for documents — 192.168.1.30
The internet connection runs through a consumer router with a dynamic IP address.
Step 1: Create a birdhost Instance
- Go to portal.merkaio.com
- Create an account (email or SSO)
- "New Instance" -> select birdhost
- Choose a plan (Startup from EUR 99.90 per month, Germany region — or EUR 119.90 per month, other regions)
- Select your preferred region -> Deploy
Your dedicated NetBird instance is ready within minutes. You receive access to your own NetBird dashboard with a dedicated URL.
7-day free trial available through the merkaio self-service portal.
Step 2: Connect Your Identity Provider
If your practice uses Microsoft 365 or Google Workspace, connect the identity provider to NetBird. This means existing MFA policies automatically apply to VPN access as well. User groups can be synchronized automatically via SCIM.
If no IdP is available: NetBird also offers local user management with invitation links.
Step 3: Set Up a Routing Peer in the Practice Network
You need a continuously running device in the practice network to act as a gateway. This can be the practice server, a mini PC, or a Raspberry Pi.
Install the NetBird client:
curl -fsSL https://pkgs.netbird.io/install.sh | sh
netbird up
The device appears in the NetBird dashboard. Under Networks, create a new network:
- Name: "Practice Network"
- Subnet:
192.168.1.0/24 - Gateway: the routing peer
Step 4: Define User Groups and Access Rights
In the dashboard under Access Control, create the groups:
Group "Remote Assistants":
- Access to PMS server (192.168.1.10, TCP port 443)
- Access to network printer (192.168.1.20, TCP port 9100)
- No access to PACS, lab interface, or NAS
Group "Remote Physicians":
- Access to PMS server (192.168.1.10)
- Access to PACS server (192.168.1.11)
- Access to lab interface (192.168.1.12)
- Access to NAS (192.168.1.30, SMB port 445)
Group "External IT":
- Access to practice server only (192.168.1.10, SSH port 22)
- Time-limited setup key with expiration date
Step 5: Configure Posture Checks
Under Posture Checks, define minimum requirements for endpoint devices:
- Operating system: Windows 10 or later, macOS 13 or later
- NetBird version: at least the current stable version
- Optional: firewall must be active
Devices that do not meet these requirements are automatically blocked — regardless of whether the user has authenticated correctly.
Step 6: Onboard Remote Staff
The remote assistant installs the NetBird client on their computer:
- Windows: download the installer from the NetBird website
- macOS:
brew install netbirdio/tap/netbird
After installation, they click "Login" and are redirected to the identity provider. After signing in (with MFA), they are automatically assigned to the "Remote Assistants" group and have access to the PMS and printer — and nothing else.
Step 7: Documentation for Compliance
From the NetBird dashboard, you can export:
- List of all registered devices and users
- Active access policies with groups and resources
- Posture check configuration
- Audit events
This documentation satisfies the requirements of GDPR Article 32 for demonstrating appropriate technical measures, HIPAA audit requirements, and profession-specific directives such as the German KBV IT Security Directive.
Cost Comparison: VPN Solutions for Practices and Firms
A realistic cost calculation for a practice or firm with 15 people who need remote access:
| Solution | Monthly Cost | Setup Cost | Hidden Costs |
|---|---|---|---|
| Consumer Router VPN | EUR 0 | EUR 0 | No access control, no logging, no MFA — compliance risk |
| OpenVPN (Self-Hosted) | ~EUR 50 (server) | EUR 500–1,500 (IT provider) | Certificate management, updates, ~4–8h admin/month |
| Sophos XGS 87 | EUR 200–400 (lease + license) | EUR 2,000–5,000 (implementation) | Firmware updates, specialist expertise, vendor lock-in |
| birdhost Startup | EUR 99.90 (Germany region) | EUR 0 | None — everything included |
| birdhost Business | EUR 199.90 (Germany region) | EUR 0 | None — SSO, Reverse Proxy, setup call included |
With birdhost, server infrastructure, monitoring, updates, patches, and support are included in the monthly price. There are no per-user fees — whether 5 or 50 users, the price stays the same.
Over three years, a Sophos solution easily costs EUR 15,000 to 25,000 (hardware, licenses, implementation, ongoing management). birdhost costs approximately EUR 1,260 over the same period (Business plan, annual) — with better access control, better logging, and no vendor lock-in.
Compliance Checklist for Regulated Professionals
Review your current infrastructure against these points:
Encryption and Data Protection:
- Are all remote connections to patient/client data encrypted in transit?
- Is the encryption up to current standards (no SHA-1, no outdated TLS)?
- Is end-to-end encryption in place so that even the IT service provider cannot access transmitted data?
Access Control (Least Privilege):
- Are access rights defined by role and need-to-know?
- Can you demonstrate who is authorized to access which systems?
- Are access rights updated promptly when staff change roles or leave?
- Is there automated offboarding when employees depart?
Authentication:
- Is multi-factor authentication enabled for all remote access?
- Does every user have an individual account (no shared credentials)?
Logging and Documentation:
- Are VPN connections logged (who, when, from where)?
- Are access policy changes documented?
- Can audit events be produced for a regulatory inspection?
Data Sovereignty:
- Is connection metadata processed within the EU (or your regulatory jurisdiction)?
- Do you have a DPA with the VPN provider?
- Is the VPN solution's source code auditable?
Endpoint Security:
- Are remote access devices checked against security standards?
- Are non-compliant devices automatically blocked?
If more than three of these points are unresolved, action is required.
Common Objections — and Why They Do Not Hold
"Our practice is too small for this to matter."
GDPR has no minimum threshold for data protection obligations. Neither does HIPAA. A solo practitioner with one remote assistant must still secure remote access to patient data. The obligations apply to every organization that processes personal data — regardless of size.
"We already use a router VPN."
A consumer router encrypts the connection — that is a good start. But encryption alone is not enough. GDPR requires demonstrable access control, regulatory authorities expect audit trails, and the current state of the art requires MFA. Consumer routers provide none of these.
"Our IT provider handles that."
This does not relieve you of responsibility. GDPR addresses the data controller — that is the practice owner or the firm's managing partners. The IT provider is a data processor who must be contractually bound (GDPR Article 28). The technical measures must still be demonstrable by the controller.
"We have a password on the VPN."
A password without a second factor does not meet the current state of the art. Data protection authorities across the EU have stated in multiple annual reports that MFA for remote access to sensitive data represents the state of the art and is therefore effectively mandatory.
Conclusion: IT Security as a Professional Duty
For healthcare providers, lawyers, and tax advisors, IT security is not a technical afterthought — it is a professional obligation. GDPR Article 32, HIPAA, German section 203 StGB, the KBV IT Security Directive, BRAO/BORA, ABA Model Rules, and their equivalents across jurisdictions all converge on the same requirements: encryption, access control, authentication, and auditability.
Legacy VPN solutions — whether consumer routers, enterprise firewalls, or self-hosted OpenVPN — were not designed for these requirements. They encrypt the transport layer, but they do not control access granularly, they do not log access events comprehensively, and they do not verify endpoint security.
NetBird with birdhost as a managed service meets the requirements natively: WireGuard end-to-end encryption, identity-based access control with posture checks, MFA via SSO integration, comprehensive audit logging, and hosting in ISO 27001 and SOC 2 certified data centers (certifications held by the data center operators). From EUR 99.90 per month (Germany region) or EUR 119.90 per month (other regions), no per-user fees, no vendor lock-in.
Try it now: Launch your own NetBird instance through the merkaio self-service portal — 7-day free trial, dedicated instance, hosted on certified infrastructure, ready in minutes.
Further reading:
Sources:
- GDPR Article 32 — Security of Processing
- GDPR Article 9 — Processing of Special Categories of Personal Data
- Section 203 StGB — Violation of Private Secrets (German Criminal Code)
- KBV IT Security Directive under Section 75b SGB V
- HIPAA Security Rule — Technical Safeguards
- ABA Model Rules of Professional Conduct — Rule 1.6 (Confidentiality)
- UK SRA Standards and Regulations
- NetBird Documentation — Access Control
- NetBird Documentation — Posture Checks
- NetBird GitHub Repository
- WireGuard Protocol Specification
- birdhost.de — Managed NetBird Hosting
Frequently Asked Questions
Do healthcare practices need a VPN?▼
What are the penalties for breaching patient confidentiality through insecure IT?▼
Does a consumer-grade router VPN meet compliance requirements?▼
What does GDPR Article 32 require for remote access to health data?▼
Is birdhost suitable for processing health data under GDPR Article 9?▼
How do the obligations differ for lawyers versus healthcare providers?▼
What does a GDPR-compliant VPN cost for a medical practice or law firm?▼
Can I run NetBird alongside my existing practice or firm IT?▼
Do my staff need technical skills to use the VPN?▼
Which regions does birdhost support?▼
Written by
Timo Wevelsiep
Founder, merkaio
Founder of merkaio. Managed NetBird VPN hosting. Focused on network security, zero-trust architecture and scalable VPN infrastructure.
LinkedIn