
GoodAccess typical implementation process:
Account creation and initial setup: Sign up, choose a gateway region, and receive instant access to the cloud dashboard; typically takes under 10 minutes to complete.
Add users and provision access: Invite team members by email, automate user provisioning via integrations, or add manually; users receive setup links and can join with one-click apps, usually within minutes.
Gateway and network configuration: Choose or customize gateway locations, set up IP whitelisting, DNS filtering, split tunneling, and security policies using the intuitive dashboard; generally done in under 30 minutes for standard deployments.
Integrate identity providers and connect resources: Configure SSO with IdPs (Google, Okta, Azure AD), connect to branch networks, clouds, or critical apps, often via built-in wizards; takes between a few minutes and an hour depending on integration complexity.
Device onboarding and client setup: Users install the GoodAccess app (iOS, Android, Mac, Windows, ChromeOS) or use browser-based VPN; zero-config for most environments—users can connect securely almost instantly.
Policy and security fine-tuning: Adjust access roles, enable Threat Blocker, review logs, set up alerts and reporting as needed; ongoing, but initial setup is usually less than one hour.
GoodAccess offers a high degree of customization to fit specific business needs:
Custom domain blacklists can be imported (CSV or manual entry) to extend threat filtering and block unwanted sites beyond built-in intelligence.
Custom DNS records allow mapping of internal IT assets, enabling the definition of private domains for easier network management and internal system resolution.
DNS server management options: choose between GoodAccess default, public, or organization-owned DNS servers to match business or policy requirements.
Security Shield settings offer granular toggles for threat blocker activation, domain filtering, reporting, and real-time situational awareness via the web dashboard.
Role-based access control and customizable policies enable administrators to assign app and network privileges per user, apply least-privilege principles, and limit exposure as regulations require.
SSO support for any identity provider (SAML 2.0) allows seamless integration with enterprise IAM/IDM systems, plus SCIM for automated user provisioning and deprovisioning across HR and IT departments.
Network segmentation via virtual access cards and static IPs lets IT teams isolate environments and align access controls with company structure or workload.
API and webhook support for automating integrations, user setup, and policy changes, harnessing GoodAccess as part of broader security and network automation.
Self-service onboarding, payment, and dashboard configuration streamline fast rollout and plan management—admins customize billing, add-ons, and user rights as needed.
Compliance and reporting: custom reports can be generated for internal/external audits, and policy automation helps ensure consistent enforcement of business and regulatory rules.
Branding elements (portal name, company details) can be configured during checkout and setup, enhancing the tailored experience for users and IT.

GoodAccess
بواسطة GoodAccess s.r.o
GoodAccess is designed to keep additional costs to a minimum. There are no setup fees—account creation, initial deployment, and onboarding are included in every plan. All maintenance, including software updates, bug fixes, infrastructure improvements, and ongoing security enhancements, is fully managed and included within the regular subscription at no extra cost. Basic customer support, onboarding resources, and help center access are standard in all plans; 24/7 customer support is also available at no additional charge for most business tiers, though priority or dedicated account management may be offered at the highest enterprise levels or as a custom add-on.
GoodAccess provides a variety of training and support resources to help new users onboard quickly and use the platform effectively:
Self-service onboarding: Step-by-step product walkthroughs, video guides, and comprehensive documentation are available in the GoodAccess resource library and web dashboard for both admins and end users.
Live online webinars and on-demand sessions: Regular expert-led sessions walk new users through topics such as secure deployment, remote access best practices, threat protection setup, and compliance configuration.
In-person and live remote training: For larger deployments or custom requirements, GoodAccess offers live online or in-person training options for teams and IT staff.
Knowledge base and FAQs: Searchable online articles and troubleshooting guides cover everything from app installation to network policy automation and integration with third-party services.
Success manager and onboarding call: After sign-up, new business customers are offered an onboarding demonstration or a one-to-one call with a dedicated customer success manager to answer questions and guide deployment steps.
Multi-channel support: Users can access help via 24/7 live chat, phone, ticketing system, community forum, and a help desk for ongoing technical or policy support needs.
Product blog and best-practice guides: Continuous education resources explore zero trust concepts, security compliance, and practical tips for IT teams scaling with GoodAccess.
GoodAccess uses a multilayered security approach based on zero trust principles, strong encryption, active threat protection, and compliance-focused controls to protect organizational data.
Zero Trust Network Access (ZTNA) and Software-Defined Perimeter (SDP): No user or device is trusted by default; every access request is authenticated, authorized, and continuously validated, reducing the risk of unauthorized breach from inside or outside the network.
AES-256 and ChaCha20 encryption: All traffic between endpoints and gateways is encrypted, using strong modern ciphers with protocols like IKEv2/IPSec and OpenVPN, including TLS authentication, perfect forward secrecy, and MitM attack protection.
Fixed/static IP, network segmentation, and access control: Enables IP whitelisting, granular app/network/role-based restrictions, and segmentation via virtual access cards, sharply limiting the network’s attack surface.
Multi-factor authentication (MFA): Requires two or more verification steps to access protected resources, plus SSO support and integration with external identity providers.
Gateway and device security: GoodAccess gateways are defended against brute-force, credential stuffing, and other credential-based attacks with certificate-based access and device state checks.
Threat Blocker and DNS filtering: Blocks access to malware, phishing, ransomware, botnet, and C2 domains in real time by leveraging multiple, continuously updated threat intelligence feeds. Admins can add custom blacklists/deny lists for policy control.
Automatic kill switch: Protects against accidental data leakage if the VPN tunnel drops, ensuring device traffic cannot flow outside the encrypted pathway.
Activity auditing and compliance reporting: Centralized dashboard records, logs, and monitors all access; enables reporting for SOC 2/ISO 27001/GDPR/HIPAA compliance and incident investigation.
Always-on private connectivity and Split tunneling: All company resources require encrypted access; split-tunneling permits safe access to only approved assets and applications.
Device and application-level security: Controls who can access specific apps or services, enforces least-privilege principles, and automatically applies security posture requirements.
No-logs policy: User activities are not tracked or monitored for content, maintaining privacy and preventing the storage of sensitive usage patterns.
Continuous updates and penetration testing: Security is regularly updated and independently tested to defend against both emerging and known cyberthreats.
GoodAccess typically releases updates every 1–3 months, delivering a blend of new features, security enhancements, and usability improvements across its clients, gateways, dashboard, and integrations. Release notes and changelogs are published on the official blog and support portal, detailing each update’s improvements—ranging from feature additions like multi-factor authentication and device approval, to bug fixes, UI updates, and major security upgrades.
Updates are managed using a cloud-first, SaaS model: backend enhancements and new features are rolled out seamlessly to all users with no service disruption, while client app updates (Windows, macOS, mobile) are pushed directly and can often be auto-installed or enabled with user prompts. Major security features and compliance upgrades are prioritized and may be deployed faster as hotfixes if needed. All maintenance is managed centrally by GoodAccess, so organizations do not need to schedule or manage update windows themselves. Users are notified of major changes within the web dashboard and by email to keep teams informed and maintain transparency about security and functionality improvements.
GoodAccess’s policy on data ownership and portability is built around the principles of customer control, legal compliance, and data portability rights. Customers (the “data controllers”) own all personal and service data transmitted or processed through the platform, while GoodAccess acts solely as a data processor, handling and safeguarding this data according to strict privacy and security standards.
Customers retain full ownership of all personal and service data they or their end users transmit through the service, including connection logs, configurations, and user directory data.
GoodAccess, as the data processor, will not claim rights over customer data and is contractually obliged to process it only on customer instructions and strictly for service delivery, legal compliance, and security functions.
Customers are responsible for the accuracy and legality of the data they collect and manage through the platform and control all privacy-related choices (e.g., deleting, exporting, restricting, or correcting data).
Upon contract termination, customers have a 30-day window to export their data (e.g., service data, logs, user lists) via the platform’s export capabilities, before GoodAccess deletes it in line with its data retention and deletion policy.
Data can be exported in standard, machine-readable formats, such as CSV or Excel, to facilitate migration or local archiving.
GoodAccess assists with lawful data transfers internationally, adhering to regulations like GDPR, UK GDPR, and Standard Contractual Clauses for data moving outside the EU/EEA.
Users (data subjects) have legal rights to access, restrict processing, object to use, request correction, deletion, or portability (structured export) of their personal data, in compliance with GDPR, HIPAA, SOC2, and ISO 27001 requirements.
Data is, by default, processed and stored within the EU, and if transferred elsewhere, it’s always in accordance with recognized cross-border transfer mechanisms and contractual clauses.
GoodAccess provides flexible terms for scaling up or down as organizational needs change, supporting seamless user and resource adjustments through its web management interface and supporting automated provisioning where enabled. The process is optimized for business agility and minimizes administrative overhead.
Adding new users, gateways, or protected resources to your network is straightforward and can be done with a few clicks in the GoodAccess Control Panel; there is no need for deep technical expertise or manual hardware installation.
Simply purchase additional licenses or subscriptions via the web UI to scale up your team size or infrastructure quickly.
New customers with up to 3 users on a discounted Essential plan can easily transition to the standard plan as the team grows, paying only the price difference when upgrading.
If using an identity provider with SCIM support, user provisioning (add/edit/delete) can be automated, so any changes in the provider sync with GoodAccess Members, improving management for scaling up quickly.
Removing or de-provisioning users and resources is managed through the Control Panel or your integrated identity provider—there are no penalties or technical barriers for reducing headcount or resources.
Subscription fees automatically adjust based on the number of seats/licenses in use, so costs scale down when you remove users or resources.
Gateway locations can be changed up to five times per month (if needed for scaling down or redeploying resources).
All changes to user counts or resource needs are self-service via the GoodAccess dashboard, allowing immediate scaling up or down and resilient response to business needs.
GoodAccess contracts have specific terms and conditions for renewal and cancellation, including automatic renewal, refund eligibility, and account management protocols. The process is designed to ensure flexibility for business customers, but also imposes some restrictions on refunds and how cancellations are handled.
Most GoodAccess subscriptions renew automatically for the same period at the end of each subscription cycle, unless the customer cancels the subscription or terminates the service contract before the current period ends.
Changes in pricing may be implemented with at least one week’s notice, delivered through the Control Panel, website, or email. However, new fees do not apply until the next renewal; any customer who disagrees with a price increase can cancel before renewal.
Passive (automatic) renewal means the service continues unless proactive cancellation is submitted before the renewal deadline.
If you purchase from an authorized reseller, renewal and termination conditions set by the reseller may override standard GoodAccess terms, but necessary compliance obligations remain.
Subscriptions can be canceled via the GoodAccess dashboard (Control Panel). There is usually a “Manage Subscription” section to initiate cancellation.
Upon cancellation, service continues until the end of the current paid period. Users will regain access to subscription management and can resume service or order a new subscription at any time.
Account closure is only possible after the subscription has expired or has been canceled; active accounts cannot be closed directly without manual intervention by support.
Customers can request a refund of subscription fees within 14 days of their first paid subscription period, provided the payment method permits and terms are respected. Abuse of trial/refund policies, such as creating multiple accounts, is prohibited.
No refunds are provided for early termination or suspension outside the initial refund window—even if the cancellation happens before the paid term ends.
GoodAccess reserves the right to immediately suspend or terminate access if illegal or criminal activity is suspected, or for a significant breach of contract.
Notice of cancellation or termination is official when delivered either by closing the account in the Control Panel or via written notice/email.
Once service terminates, users have up to 30 days to export any personal or business data from the platform, after which GoodAccess will delete or anonymize all data in line with GDPR and internal policies.
GoodAccess meets a wide range of compliance standards designed to address regulatory, industry, and security requirements for organizations worldwide. The platform is specifically built to help customers satisfy:
ISO 27001: Certification for its information security management system, covering technical, organizational, and procedural controls required by this international standard.
SOC 2: Audited for security, availability, confidentiality, and processing integrity, meeting the criteria of the American Institute of Certified Public Accountants’ SOC 2 framework.
GDPR: Full compliance with the European Union’s General Data Protection Regulation, ensuring user data rights, cross-border transfer protections, and strong privacy controls; customers can choose EU data residency by default.
HIPAA: Built with features to support compliance with the U.S. Health Insurance Portability and Accountability Act, protecting personal health information and supporting security standards in healthcare.
NIS2: Designed for organizations subject to the EU’s Network and Information Security Directive by offering technical and organizational measures aligned to the updated NIS2 framework.