EN
DE
View the demo
Single pane of glass for supported Zscaler workflows

Complex Zscaler environments.One shared operational context.

Built on the official Zscaler OneAPI, CentaurNexus connects supported workflows for help desk, end users, administration, security, MSPs and management in one role-based context.

The single view

User Support Center / Unified Support Center

All user information from ZIA, ZPA, and ZDX in a single view - as a cohesive overview, without requiring Zscaler admin privileges.

View →
Is it Zscaler - or not?

Connectivity Triage Map

Merges available ZDXsignals and policy statuses for triage, and displays possible causes such as ISP, Wi-Fi, device, or Zscaler traceable.

View →
Test first + roll back

Change Effect Preview & Configuration Rollback

Check the scope and expected effect of a selected individual change before approval and prepare the targeted return path in a comprehensible way.

View →
Get more out of your Zscaler license

Policy Health

Configuration health as a score plus a prioritized action plan - get more out of your existing Zscaler license.

View →
Patent-pending self-protection

Privileged Access Guard

The cockpit that protects itself: the administration layer secures itself using your tenant’s zero-trust signals.

View →
Proxy rules without hand-editing

PAC Configuration Studio

Assemble PAC files from building blocks instead of typing them: every rule is a click, the generated code sits next to it, and a linter checks along.

View →
Client logs made readable

Log Verdict

Upload the client log bundle and get a clear finding back - instead of working through lines until the pattern shows.

View →
From finding to change request

Change Package Builder

Bundle changes from different areas into one change, explain it in the board and fill the fields in your ITSM system.

View →

User Support Center / Unified Support Center

User context at a glance.

Support enters an email address. CentaurNexus runs the OneAPI queries in parallel and combines web status, application access and connection quality into one coherent finding with around 70 data points per user. No portal switch and no broad Zscaler admin rights.

ZIA: blocked categories & DLP hits with plain-text explanations.
ZPA: Matrix of all approved internal app segments.
ZDX: Endpoint latency and packet loss. The Unified Support Center adds ZIdentity, PRA and EASM to the context.
Open demo →
Unified Support Center - rollenbezogener Nutzer-, Geräte- und Zugriffskontext
Product view not loaded The corresponding product view could not be displayed in this browser.

Connectivity Triage Map

Is it Zscaler - or not?

When a call stutters, merges CentaurNexus available ZDXsignals, device and policy status into a triage view. In this way, possible causes such as ISP, WLAN, device or Zscaler with their source context can be checked.

Deep trace of the entire chain. From the end device through Wi-Fi and the ISP to the Zscaler policy - hop by hop.
Plain-language verdict. A clear statement instead of raw data - understandable even to first-level support.
Findings exportable. Sources, status and test result can be entered for further processing.
Connectivity Triage Map · ZDX Deep TracingLive
Zscaler-PolicyZIA / ZPA · Policy set active
OK
EndpointClient 4.2 · Posture met
OK
ISP linkLatency 24 ms · stable
OK
Home Wi-FiPacket loss 8.4% · 2.4 GHz overloaded
Cause
Not Zscaler. The local Wi-Fi is losing packets - Recommendation: Use the 5-GHz band.

Change safety in both directions

Test first. Roll back granularly when in doubt.

No more fear of policy changes - you can see the impact before a rule goes live and can undo every single step in granular detail.

Change Effect Preview

Test first

Test the impact of a policy change against real usage patterns before a single rule goes live - across URL/cloud app, DNS, firewall, and file type masks.

  • Preview the impact against real traffic patterns.
  • Retrospective over 7, 14, or 30 days.
  • Release and execution according to tenant policy.
Configuration Rollback

Roll back granularly when in doubt

Changes in supported workflows are tracked individually. Where a take-back path is available, the affected change can be undone in a targeted manner.

  • Granular rollback of individual changes.
  • Diff preview before reverting - you can see in advance what will change.
  • Audit records selection, approval status, target effect and read-back.

Policy Health

Get more out of your existing Zscaler license.

Policy Health classifies configuration findings as comprehensible indications. Source, status, data age and coverage remain visible; the selection and implementation of a change remains with humans.

Supported inspection areas with visible data source and coverage.
Verifiable guidance with clear impact and priority.
Exportable report for internal review and documentation.
Watch Demo →
Security Score
74
out of 100 points
+12 this month
ZIA Policies
82
ZPA Visits
91
DLP Configuration
58
IAM & MFA
70
Policy Management
65
23Measures Identified
7Critical - Take immediate action

Admin on the go

Your dashboard fits in your pocket.

The native CentaurNexus admin app keeps you informed about your Zscaler environment and brings simple approvals to your smartphone. Complex rule changes deliberately remain in the full web cockpit.

Real-time connector status. All ZPA connector groups with status indicators and push notifications for outages.
Security traffic lights on the go. Cockpit traffic lights and current security events, even when you’re away from your desk.
Simple approvals on the go. Review website and application approvals with a clear decision context.
iOS · Apple App StoreAndroid · Google Play

For administrators, as a companion to the full web cockpit.

9:41●●●● 5G
CentaurNexus
Connectors Security
Berlin Headquarters4/4 online
edge-01
edge-02
Munich Branch3/4 online
edge-07
edge-08
Connector “edge-07” degraded - Push sent

Beyond the portal

Right where the work happens.

Not every case starts in the portal. Two paths bring CentaurNexus to where the issue arises: into the browser and onto the user’s device.

Browser extension

The user works in the browser. The extension brings the most common actions there: request access to a blocked website, request an urgently needed app, and check the status of Teams, Zoom, and similar services before a call—all without opening the portal.

Endpoint Agent

The agent delivers only what the OneAPI does not expose: zero-trust signals from the administrator's device, which Privileged Access Guard uses to secure access to the administration layer, plus supplementary device data. The latter exclusively for customers with a licensed ZDX.


Seamlessly integrated into daily work

Directly in your workflows.

CentaurNexus connects supported Zscaler workflows with ticketing systems, team channels and the languages used by international organisations.


Supported Zscaler contexts

An interface for supported workflows.

Concrete availability depends on the Zscaler domain, licence and tenant configuration. Each view shows source, status, data age and coverage.

ZIA

Internet Access

URL/DLP status, firewall & URL policies, shadow IT, bandwidth, geoblocking.

ZPA

Private Access

App segments, vendor/partner access, PRA, microtenants, M&A clean room.

ZDX

Digital Experience

Device health, ZDX Deep Tracing, Connectivity Triage Map, VIP check and Endpoint Action Center.

ZCCClient Connector
ZTWCloud / Branch Connector
ZIdentityIAM self-service
ZWAWorkflow automation / DLP
EASMExternal attack surface
ZTBBranch Connector
Z-InsightsInsights
ZMSManagement Service
ZAIGuardAI Guard

OneAPI + NSS/LSS

Current context. Better with growing history.

The official Zscaler OneAPI provides supported current context. Full use of history-based analysis and assessment additionally requires the relevant NSS and LSS feeds.

Once connectedUse current OneAPI context in supported workflows.
From onboardingBuild NSS and LSS history; no retrospective history is created.
As history growsInterpret patterns, deviations and developments earlier and with more context.

Features

Features that make a real difference.

Self-service reduces the burden on the help desk, admin tools speed up operations, and security features close gaps - all without granting a single employee full Zscaler admin privileges.

Self-service brings supported requests directly to the user and relieves the helpdesk of avoidable portal changes and handovers.

IAM Self-Service (ZIdentity)

Reset a password or temporarily suspend MFA without an IdP console and within the intended audit context.

Common help desk request

Request App & SaaS Access

Request access to supported private applications or SaaS services; review and approval follow tenant policy.

Self-Service

BYOD-Onboarding & Posture

Register a personal device yourself and check the compliance posture status.

Without the help desk

Service Tunnel Check - One-click diagnostics

Classifies available ZDX, link, and device signals, and makes the report exportable.

Source-based findings

Certificate Onboarding - developer tool setup

Zscaler Root CA Self-Service + ready-to-use config snippets for npm, pip, Docker, and git.

Developer
View all self-service features
Access & approvals
  • Time-limited website access request reviewed against tenant policy
  • Application and SaaS access request under tenant policy
  • DLP quarantine request
  • Request an SSL/TLS inspection exception
  • Travel mode activation
Diagnostics & transparency
  • Service Tunnel Check - current ZDX context
  • Conference Readiness - connectivity check before a video call
  • Zero Trust Self-Protection - what can my IT team see?
  • Service Health Overview - current Zscaler service status
  • My Access - overview of assigned ZPA segments
Identity & device
  • IAM self-service for supported identity workflows
  • BYOD onboarding & posture check
  • Certificate Onboarding - developer tool configuration
  • Device self-service
Communication
  • Report a categorisation issue
  • Access request linked to an ITSM case
Read about all features in the Help Center →

Enterprise

Built for enterprise and corporate structures.

Multi-tenant operation with granular separation and traceable audit information for complex organisational structures.

Regional production operation

CentaurNexus is provided in the agreed region. For EU customers, production operation runs entirely on STACKIT in the EU; regional rollout for the USA and APAC is approaching.

SH

Qualified self-hosting

Deployment in customer infrastructure is qualified for the specific project. Architecture, responsibility boundaries, operations and support are defined in advance.

VIP & Executive

Priority Lane, Principal Horizon and Delegation Ledger support clearly assigned representation and protection processes with traceable audit.

Domain-Scoping

RLS-enforced tenant/domain separation - an admin sees only their own domain, not the sister domain.

Rule Set Backup

Rule set backup as JSON - anti-vendor lock-in. You retain control of your own configuration at all times.

Governance & Evidence

Tenant policy, traceable audit trail and exportable proof of operations support internal review and approval processes.

Protected access

Role-based access, MFA for privileged accounts, and secure sessions limit access to the features they need.

Fine-grained RBAC

Position-based role hierarchy plus custom roles - for complex organizational structures.

Integration

ITSM (ServiceNow / JSM / Freshservice / Zendesk) and SIEM feeds - your existing toolchain remains intact.

Support and Operational Channels

Clear responsibilities, status information and documented handovers support stable platform operation.

Custom-Domain

Access via your own (sub)domain - consistent corporate identity for your users.

Data residency & recovery

Region, backup and recovery paths are documented in the agreed operating model.

Onboarding & Professional Services

Guided onboarding plus configuration best practices - fast time-to-value.

Whitelabeling

Deploy CentaurNexus to subsidiaries under your own brand - group-wide rollout.

Privileged Access Guard

Patent-pending zero-trust self-protection at the administrative level - your trust anchor.

Qualified self-hosting

Deployment in customer infrastructure is qualified for the specific project. Architecture, responsibility boundaries, operations and support are defined in advance.


MSP & System Integrator

Manage tenants securely in context.

CentaurNexus combines repeatable processes with clear customer responsibility. Access remains limited to the tenants that are actually managed.

Tenant context

Classify the status, source, data age and coverage of the actual managed customer tenants without unnecessary changes of environment.

Configuration Drift Review

Target-vs.-actual comparison across all tenants - configuration deviations are immediately reported as findings.

Compliance Coverage Matrix / Customer Risk Board

Audit status, existing evidence and risk warnings per managed client in an overview.

Domain-Scoping

Strict tenant separation at the database level - no customer can see even a single data point belonging to another.

Clear customer responsibility

The role, tenant, selected action, and target system status remain visible in each workflow.

More for partners →

Patent pending (DPMA)A zero-trust self-protection procedure developed by CentaurNexus. DPMA application no. 10 2026 003 651.8.
Privileged Access Guard

The cockpit that protects itself.

Anyone who manages a Zscaler environment is a valuable target in their own right. That’s why CentaurNexus secures its own administrative level with your tenant’s Zero-Trust signals - the administrative functions are protected by your own Zero-Trust verification, not just by a password. Access and login identity are deliberately decoupled.

Your Zero-Trust signals protect the Cockpit. Administrative access is protected by your own verification.
Adapts to the risk situation - without slowing down operations.
Closed when in doubt. If the status cannot be determined with certainty, access is restricted rather than granted.
View security architecture →
Access to the administration levelLive verification
Login identity confirmedDecoupled from the email address
Tenant’s zero-trust signalAccess from your protected environment
Device status checkedPosture meets the policy
Access to the management layer granted
External access without zero-trust verification - administrative level locked

Security

Enterprise security, built-in.

View the complete security architecture →

Hard client isolation

PostgreSQL row-level security enforces separation at the database level - not just in the UI, and cannot be bypassed via the API.

PostgreSQL RLS

Secrets in the Vault

API keys and secrets are encrypted with AES-256-GCM; the keys are stored in the vault - never in the code, never in plain text.

AES-256-GCM

Traceable audit trail

Security-relevant actions capture actor, timing, tenant, selection, target status, and read-back for internal review and verification.

Audit · Read-back

MFA & Secure Sessions

MFA/TOTP for privileged access, JWT with refresh token rotation, httpOnly cookies, and CSRF protection via double-submit.

MFA · JWT · CSRF

Hardened input and session controls

Server-side validation, rate limits, secure session cookies, and CSRF protection limit abusive and erroneous requests.

Validation · Rate-Limit · CSRF

Production operation in the EU

For EU customers, CentaurNexus runs entirely on STACKIT in the EU. Additional data paths and subprocessors are disclosed in contractual and privacy documentation.

STACKIT · EU

Results, not just promises

Less friction in daily work.

CentaurNexus connects supported Zscaler workflows with the appropriate role and tenant context. Limits and missing coverage remain visible instead of being presented as full support.

Costs ↓Work & Complexity ↓Adoption & Speed ↑

What annoys users - here’s how we fix it

“I can’t get anything approved on my own.”
Self-service request with tenant policy, documented release where intended and clear validity.
“Is the internet slow - or is it Zscaler’s fault?”
One-click self-test with source status and comparable findings.
“A legitimate site is being blocked by mistake.”
Report misclassification + immediate approval request.
Show more
“Developer tools aren’t working (pip/npm/Docker, SSL).”
Zscaler Root CA Self-Service + ready-made config snippets.
“The block page does not provide a reason or contact information.”
Informative lockout page with reason & direct unlock button.
“What does my IT department actually see about me?”
Transparency Center: what’s being monitored - and what isn’t.

What’s holding admins back - and how we solve it

Several places in , Experience Centermissing connection
User Support Center / Unified Support Center combines supported ZIA, ZPA and ZDX context in a role-based view.
Diagnosis takes a long time
URL Trace, Root Cause, and Deep Trace.
Help desk requires Zscaler admin rights (risk)
Role-based reads and controlled requests without broad Zscaler admin rights.
Show more
Unused/conflicting rules, fear of change
Policy Hygiene Desk, Policy Conflict Review, Rule Set Backup, Policy Impact Preview, Configuration Rollback.
API rate limit / OneAPI performance
Custom call counting + conservation (cache, quotas, live counters).
Compilation of operational and change records
Compliance Evidence Collector structures existing configuration, release, and audit information for internal audits.

Honestly: Not everything can be solved through the platform. We clearly explain client and OS behavior and include this information in a Help Center article.


Checking the impact with your own data

Measure operational benefits in a comprehensible way.

Compare processing time

Measure selected pre- and post-rollout tasks with the same start and end points.

Measurement basis: Your operating data

Making handovers visible

Compare how often cases are resolved at the first level or handed over with the context relevant to the decision.

Measurement basis: Your support processes

Classify coverage

Evaluate source, data age, coverage, and confirmed target system effect per workflow.

Measurement basis: CentaurNexus status data

Calculate your own scenario

Scenario Value / Year
€45,900

The calculation uses your inputs to show the resulting scenario.


Demo

Experience the platform. One click, no login.

Select a role and open a prepared example scenario for the respective day-to-day work.

Open Demo Launcher →
No login, no installation. The demo uses prepared sample data.


Pricing

Aligned with operational scope and roles.

The offer transparently describes the tenants, roles, supported workflows, integrations and operational services involved.

Tenant Scope

Organization and managed customer contexts
  • Number and type of tenants included
  • Enterprise or MSP Responsibility
  • Clear tenant and data demarcation

Roles & Processes

End users to platform operations
  • Required roles and authorization models
  • Supported Read and Write Flows
  • Tenant Policy, Audit and Read-back

Integration & Operations

Zscaler, ITSM and operational requirements
  • Available Zscaler domains per tenant
  • Required ITSM and operating adapters
  • Introduction and documented responsibilities

You will receive an offer with an explicitly described scope of services. Request a price talk →