How TZ Turned Weeks-Long Security Reviews Into a Same-Day Sales Advantage

Remotely managing smart lockers on enterprise networks without VPNs, firewall exceptions, or open ports

TZ

Contents

TZ
  • Industry: Technology
  • HQ: Australia
  • Customers: Bank of America, Apple, Microsoft, Adidas, Schneider Electric
  • Products Used:
    • NetFoundry Cloud
    • Zero Trust overlay networking

Ready to get started?

Security-conscious customers wouldn’t permit inbound IPs or stand up site-to-site VPNs to let TZ manage on-prem lockers.

NetFoundry’s Zero Trust B2B connectivity closed every inbound port while keeping remote management fully functional.

InfoSec reviews went from a deal blocker to a competitive advantage, and TZ scaled to hundreds of thousands of deployed lockers worldwide.

About TZ 

TZ builds integrated smart locker systems that let companies manage secure access, streamline logistics workflows, and turn every deposit or pickup into usable transactional data. The platform’s value comes from what happens after the hardware ships: TZ offers remote management, monitoring, and control of connected lockers from anywhere, which is what lets its enterprise customers run agile workplaces without adding headcount to babysit hardware. Bank of America, Apple, Microsoft, Adidas, and Schneider Electric all rely on TZ for employee storage, package delivery, and asset tracking.

That remote management capability is also where TZ ran into a wall. To reach lockers sitting inside a customer’s own network, TZ needed a way in, and for years, the only route ran through the same tools every enterprise security team has learned to distrust.

“NetFoundry’s Zero Trust B2B met our customer’s most stringent security requirements — no permitted IP addresses in their firewalls and no site-to-site VPNs.”

John Wilson, CEO, TZ

The Challenge: Winning enterprise deals meant asking IT teams to open their network

TZ’s smart lockers are only as valuable as their ability to manage them after they’re installed — real-time monitoring, remote troubleshooting, and software updates. The problem was how that access got provisioned. Reaching a locker system sitting inside a customer’s firewall traditionally meant permitting TZ’s IP addresses through the firewall, or standing up a site-to-site VPN. Neither option sat well with the security teams TZ was trying to win over.

Security reviews became the bottleneck, not the sale

For a company selling into banks, tech giants, and retailers with mature security programs, this was more than an inconvenience. InfoSec reviews that should have taken days routinely stretched into weeks, because reviewers had to evaluate exactly what TZ’s remote access would expose.

Every VPN was another thing to manage

Even where customers agreed to a VPN, TZ inherited the operational cost of it. Different customers often ran overlapping internal IP ranges, multiple VPN providers meant multiple configurations to maintain, and static IPs and port forwarding added complexity on both sides of the connection. None of this scaled cleanly as TZ tried to grow past a handful of large accounts into a broader enterprise customer base.

The business model TZ wanted to build required a better answer

TZ’s ambitions went beyond selling locker hardware: the company wanted to reposition around remote management and data capture as its core value, effectively becoming a logistics software provider rather than a hardware manufacturer. That shift only works if remote access is simple, secure, and repeatable across thousands of customer sites, and VPNs and firewall exceptions were the opposite.

The Solution: Closing every inbound port instead of trying to secure them

TZ integrated NetFoundry Cloud into its architecture, replacing VPN-based remote access with a private, Zero Trust overlay network. Instead of asking customers to open firewall ports or maintain a tunnel, TZ’s locker systems and server-side assets connect outbound-only. They’re invisible to the internet and reachable only through NetFoundry’s Zero Trust fabric.

No inbound ports, no exceptions to review

Because every connection is outbound-only, there’s nothing for a customer’s firewall team to open and nothing new to add to their attack surface. The locker system authenticates and reaches out to the network; nothing reaches in. That single architectural change is what took InfoSec reviews from a multi-week negotiation to something a security team could sign off on in one meeting.

Identity replaced IP addresses as the access model

TZ’s engineers can now connect directly to individual kiosks for maintenance and provisioning, authenticated by identity rather than network location. Access is governed by mutual TLS and X.509 certificate-based identity, which lets TZ apply least-privileged, micro-segmented permissions per session. Admins and data flows can reach exactly the resource they’re provisioned for, and nothing else. 

A global fabric that scales past what VPNs could support

NetFoundry’s full-mesh, self-healing network gave TZ a more resilient foundation for remote sessions than VPN tunnels, particularly for latency-sensitive remote administration across long distances. As TZ’s footprint grew into the hundreds of thousands of lockers and kiosks, that resilience became even more critical.

“NetFoundry Cloud has been a main enabler in our shift from a smart locker hardware manufacturer to a supplier of logistics software solutions.”

John Wilson, CEO, TZ

The Results: Security reviews stopped being a reason to say no

The clearest outcome for TZ wasn’t a cost or performance number; it was a change in how sales conversations went. InfoSec reviews that used to be a recurring point of friction became, in Wilson’s words, “single-meeting events”. For an enterprise sales motion, removing weeks of security back-and-forth from the buying process is close to a direct revenue outcome, even without attaching a percentage to it.

Operations got simpler at every layer

Identity-based policies and usage data replaced the patchwork of IP addresses, firewall access control lists, and identity-less VPN tunnels TZ used to manage per customer. That gave TZ’s team one consistent operational model across every account, instead of a slightly different networking configuration for every customer’s IT environment.

The business model shift became real, not aspirational

With remote access no longer tied to negotiating network exceptions account by account, TZ could move from hardware manufacturer to logistics software provider. New revenue models and service offerings could ship without TZ having to build new security or networking infrastructure to support them, because the Zero Trust foundation was already there.

Growth stopped being limited by network complexity

TZ scaled its deployment well beyond hundreds of thousands of kiosks and lockers globally, across customers on different networks, hardware, and clouds, without the deployment consistency problems that usually come with that kind of growth. Customers got a security upgrade — from site-to-site VPNs to Zero Trust B2B connections — without changing their own network or firewall configuration at all.

Products and Solutions Used 

  • NetFoundry Cloud: Zero Trust overlay network providing outbound-only, identity-based connectivity for remote locker management
  • OpenZiti: The open-source Zero Trust networking platform underlying NetFoundry Cloud
  • Zero Trust B2B connectivity: mTLS and X.509 certificate-based authentication replacing IP allowlisting and VPN tunnels

Get IoT access that doesn’t require a security exception.

NetFoundry helps product companies eliminate open attack surfaces, replace VPN complexity, and turn security reviews from a bottleneck into a differentiator — without rebuilding their architecture from scratch.

About Netfoundry

NetFoundry is a leader in Secure Workload Connectivity, founded by the inventors and maintainers of OpenZiti, the world’s most widely used open source Zero Trust platform. NetFoundry enables enterprises to secure and connect AI agents, MCP servers, LLMs, APIs, OT/IoT infrastructure, and traditional enterprise workloads, all with no open inbound ports, no VPNs, and no firewall changes. NetFoundry secures billions of sessions for critical infrastructure on three continents and supports Fortune 10 companies across regulated industries including healthcare, financial services, and energy.

They Made the Switch. Here’s What Happened.