Zedmos

OEM & white-label

Sell a next-generation firewall without building one

You have the hardware, the channel and the customers. What a next-generation firewall costs is not the box — it is the inspection engine behind it, and the fact that it is never finished: new protocols, new evasions, new rules, a disclosure process, a bill of materials for every release. That part is ours, permanently. The product is yours: your name on the boot screen, your interface, your console, your support address. A complete second-brand build has already shipped; this is not a roadmap item.

How many sites, which platform they run today, and what you want to see. The more concrete, the shorter the reply chain.

What you send is used to answer you and is not passed to anyone else. There is no tracking pixel and no third-party script on this page.

Shipped
A second brand already in the field
Yours
Boot image, interface, console, domain
Signed
Your own package repository and key
5 years
Security updates per product line

Where the line between us sits

The engine is the part that never stops

Application classification, intrusion rules, TLS behaviour, QUIC, encrypted DNS, data-loss detectors, the AI providers people actually use — each of these moves every quarter, and a firewall that stopped tracking them stops being a next-generation firewall. Carrying that is a permanent engineering team, not a project with an end date. It is the reason appliance makers either partner or leave the segment.

The product is yours, down to the boot screen

An image that boots into your product name on hardware from the validated list. The firewall pages carry your brand and your colours. The management console is self-hosted at your own domain, so your technicians and your customers log in to you. Your support address is the one on the screen when something goes wrong.

Your own repository, with your own key

A branded line gets its own signed package repository and its own signing key, so updates reach your fleet from your address under a signature that is yours. The console recognises a branded appliance by its own API namespace and manages it alongside every other, which is what makes one console able to serve a mixed estate.

What stays named, and why that helps you

The engine, its update repositories, its bill of materials and its vulnerability-disclosure path stay ours and stay named. That is the Cyber Resilience Act, not a preference. It also works in your favour: when a customer’s procurement asks who maintains the inspection code and for how long, you hand over a published support period and an SBOM instead of an assurance.

Your team can be certified, not just briefed

Four exams with published objectives and a pass mark, and not-for-resale licences for the lab and the demo estate at no charge for as long as the partnership stands. A practice you can staff and prove is worth more than one engineer who happens to know the product.

Both sides keep what they are good at

You keep the customer relationship, the margin on your hardware and the brand the market already knows you by. We keep one engine to maintain instead of a channel to build, and every deployment you make sharpens the same code every other deployment runs. Neither side is reselling the other; each is supplying the half it can actually carry.

What a first build actually involves

A brand name and assets, the hardware you intend to ship, the domain the console will run under, and the support address that goes on the screen. From there it is a build, a validation pass on your hardware, and a signed repository. We have done this end to end before, which is the only reason we describe it in the past tense.