How Digibee Replaced VPN Complexity with Zero Trust Networking for iPaaS

Digibee serves 250+ enterprise customers. Every one of them needed a secure connection. None of them needed another VPN.

Digibee

Contents

Digibee
  • Industry: Software / iPaaS
  • HQ: São Paulo, Brazil
  • Customers: 250+ enterprise businesses globally
  • Products Used:
    • NetFoundry Cloud
    • AppNets
    • Zero Trust SDKs

Digibee’s VPN-dependent architecture created open inbound ports, IP address conflicts across customers, and spiraling management costs — a hard ceiling on growth.

NetFoundry Zero Trust overlay embedded directly into Digibee’s iPaaS as code, with no VPN clients, no open ports, and no static IPs. Just secure, software-defined connectivity that scales with the business.

Digibee onboards new customers in days instead of weeks, slashed maintenance hours by 32%, and now offers APIs that are invisible to the internet, a security posture no competitor can match.

About Digibee 

If your business runs on software, you run on integrations. Every time a new application joins your stack, every time a customer pipeline needs connecting, every time a legacy system has to talk to a cloud-based one, someone has to build and maintain that bridge. For most enterprises, that someone is a highly specialized integration engineer, and there are never enough of them. Digibee was built to change that.

It’s a cloud-native, low-code iPaaS (Integration Platform as a Service) that lets development teams build, test, deploy, and monitor integrations up to ten times faster than traditional methods — without needing a niche specialist for every project. Its visual, drag-and-drop interface replaces manual coding, but it’s built specifically for developers, not around them. The result is an enterprise integration platform that actually moves at the speed of the business.

Today, Digibee serves more than 250 enterprise customers globally, including GoPro, Bauducco, B3, ConnectWise, and Payless, and spans financial services, manufacturing, retail, and beyond. CIOs and IT leaders rely on it to modernize their integration layer, reduce technical debt, and build the kind of scalable, cloud-connected infrastructure that makes digital transformation possible instead of theoretical.

But the bigger Digibee’s customer base grew, the more exposed a hidden problem became. Enterprise customers don’t just bring their integration needs; they bring their security requirements. And Digibee’s legacy architecture wasn’t built to carry both.

The Challenge: When Growth Becomes a Security Liability

For years, Digibee’s architecture relied on a familiar but fragile stack: site-to-site VPNs, bespoke point-to-point tunnels, and a cloud provider security layer to absorb DDoS attacks. At first it worked…until it didn’t.

Open Ports, Open Exposure

Every customer connection required open inbound firewall ports. That’s not an edge case — it’s hundreds of open attack surfaces multiplied across Digibee’s entire customer base. Security teams at enterprise prospects took one look at those open ports and started asking questions Digibee couldn’t comfortably answer.

IP Overlap Hell

As Digibee’s customer base grew, so did the nightmare of overlapping IP address spaces. Multiple customers running the same internal IP ranges meant VPN management became a full-time firefight. Scaling wasn’t just technically difficult; it was operationally exhausting.

The Cost of Complexity

Multiple VPN providers. Multiple endpoint types. Configuration-heavy deployments that required specialized knowledge to stand up and maintain. Each new customer added operational drag, not just to IT, but to sales cycles. Digibee needed a way to promise enterprise customers a secure, seamless onboarding, and actually deliver it.

“Integrating NetFoundry Cloud into our platform helped us obtain a competitive advantage — faster time-to-market, a future-proofed IT infrastructure, the strongest security, and a reduced investment in operational costs.”

Rodrigo Bernardinelli, CEO & Co-Founder, Digibee

The Solution: Zero Trust, Embedded as Code

Digibee didn’t want to bolt security onto their platform; they wanted to build it in. 

NetFoundry’s Zero Trust overlay, deployed via cloud-native SDKs and managed as code, allowed Digibee to make Zero Trust a core architectural feature of their iPaaS. Not a separate appliance or a configuration checkbox, but an intrinsic property of every customer connection.

What “Zero Trust Designed-In” Actually Means

The NetFoundry architecture operates on a simple but powerful premise: nothing is reachable by default. Edges don’t listen. APIs don’t have public faces. Customer-side infrastructure doesn’t expose ports. Everything is authenticated, authorized, and micro-segmented before a single byte moves.

Six architectural pillars make this work:

  • Secure by Default — All APIs and customer-side assets are invisible to the internet. Zero open inbound ports.
  • Embedded Zero Trust — SDKs build Zero Trust directly into applications and edge environments; they’re not bolted on after the fact.
  • Closed Inbound Ports — Outbound-only communication. No overlapping IPs, no port-forwarding, no firewall holes.
  • Least-Privileged Access — Every session, API, and admin connection is micro-segmented. Access only what’s been explicitly provisioned.
  • mTLS + X.509 Identity — Exceeds federal Zero Trust mandates with mutual TLS, encryption, and bi-directional certificate-based authentication.
  • Authentication Always Required — Unprovisioned endpoints cannot see or reach any resource. Period.

AppNets: The Unit of Zero Trust

The practical implementation runs through AppNets, NetFoundry’s approach to Zero Trust microsegmentation. Each AppNet is an isolated, policy-governed network environment containing the identities, services, and access rules for a specific customer instance. When Digibee onboards a new customer, a new AppNet spins up. That customer gets exactly the access they need. Nothing more, nothing adjacent, nothing shared.

Communication is outbound-only. Endpoints authenticate before they can see any resource. Administrators provision access remotely, on any network, with no VPN client required. The result: a customer environment that’s air-gapped by default and operationally managed from the cloud.

The Migration: Complexity Out, Code In

Switching from VPN-heavy architecture to a Zero Trust overlay eliminated several interdependencies at once for Digibee. 

  • Gone: the need for static IPs or port forwarding. 
  • Gone: the operational burden of managing VPNs across multiple providers. 
  • Gone: the exposure created by open inbound ports.

NetFoundry Cloud’s smart routing layer also gave Digibee latency optimization they didn’t have before. Endpoints and routers dynamically choose the best available path on the private Zero Trust fabric automatically with no manual tuning and no degraded experience for customers.

“We have significantly reduced our VPN complexity and mitigated issues related to NAT and FTP with overlapping IPs, which enabled us to onboard new clients and workloads with as little friction as possible. NetFoundry allowed us to scale faster, safer, and more cost-effectively.”

Rodrigo Bernardinelli, CEO & Co-Founder, Digibee

The Results: A Platform Built to Scale

Digibee reduced maintenance hours by 32% and cut infrastructure costs by 18%. Those numbers matter, but they’re almost beside the point. In fact, the harder-to-quantify wins may matter more in the long run.

Security That Sells

Enterprise procurement teams now get what they want: APIs that aren’t visible on the internet, customer environments that can’t be accessed by unauthorized endpoints, and a security posture that exceeds US federal Zero Trust mandates. Digibee’s security architecture went from a liability in sales conversations to a differentiator.

Onboarding in Days, Not Weeks

The days of nailing up VPNs and manually resolving IP conflicts are over. New customer environments are software-defined and code-driven. What used to take weeks of IT back-and-forth now happens in days with less friction, fewer handoffs, and lower support costs.

A Foundation for What’s Next

With private, app-specific networking embedded at the platform level, Digibee can extend Zero Trust security to new use cases as they emerge — without re-architecting anything. The foundation is built. The security scales with the business.

Products and Solutions Used 

  • NetFoundry Cloud: The Zero Trust overlay mesh network. Cloud-orchestrated, software-defined, globally available.
  • AppNets: NetFoundry’s Zero Trust microsegmentation implementation. Identity-bound, policy-driven, outbound-only.
  • Zero Trust SDKs: Embed Zero Trust networking directly into applications at the code level. No gateway required.

Your customers deserve connections they can trust.

NetFoundry helps enterprises eliminate open attack surfaces, ditch VPN complexity, and onboard customers faster — without rebuilding their architecture from scratch.

About Netfoundry

NetFoundry is a leader in Secure Workload Connectivity, founded by the inventors and maintainers of OpenZiti, the world’s most widely used open source Zero Trust platform. NetFoundry enables enterprises to secure and connect AI agents, MCP servers, LLMs, APIs, OT/IoT infrastructure, and traditional enterprise workloads, all with no open inbound ports, no VPNs, and no firewall changes. NetFoundry secures billions of sessions for critical infrastructure on three continents and supports Fortune 10 companies across regulated industries including healthcare, financial services, and energy.

They Made the Switch. Here’s What Happened.