Remotely managing smart lockers on enterprise networks without VPNs, firewall exceptions, or open ports
0 Inbound ports required after NetFoundry deployment
1 Meeting needed for InfoSec review timeline vs. weeks before
100% Outbound-only connectivity, no VPNs or bastions
5 Fortune-caliber enterprise clients, including Bank of America, Apple, and Microsoft
Ready to get started?
Security-conscious customers wouldn’t permit inbound IPs or stand up site-to-site VPNs to let TZ manage on-prem lockers.
NetFoundry’s Zero Trust B2B connectivity closed every inbound port while keeping remote management fully functional.
InfoSec reviews went from a deal blocker to a competitive advantage, and TZ scaled to hundreds of thousands of deployed lockers worldwide.
TZ builds integrated smart locker systems that let companies manage secure access, streamline logistics workflows, and turn every deposit or pickup into usable transactional data. The platform’s value comes from what happens after the hardware ships: TZ offers remote management, monitoring, and control of connected lockers from anywhere, which is what lets its enterprise customers run agile workplaces without adding headcount to babysit hardware. Bank of America, Apple, Microsoft, Adidas, and Schneider Electric all rely on TZ for employee storage, package delivery, and asset tracking.
That remote management capability is also where TZ ran into a wall. To reach lockers sitting inside a customer’s own network, TZ needed a way in, and for years, the only route ran through the same tools every enterprise security team has learned to distrust.
“NetFoundry’s Zero Trust B2B met our customer’s most stringent security requirements — no permitted IP addresses in their firewalls and no site-to-site VPNs.”
John Wilson, CEO, TZ
TZ’s smart lockers are only as valuable as their ability to manage them after they’re installed — real-time monitoring, remote troubleshooting, and software updates. The problem was how that access got provisioned. Reaching a locker system sitting inside a customer’s firewall traditionally meant permitting TZ’s IP addresses through the firewall, or standing up a site-to-site VPN. Neither option sat well with the security teams TZ was trying to win over.
For a company selling into banks, tech giants, and retailers with mature security programs, this was more than an inconvenience. InfoSec reviews that should have taken days routinely stretched into weeks, because reviewers had to evaluate exactly what TZ’s remote access would expose.
Even where customers agreed to a VPN, TZ inherited the operational cost of it. Different customers often ran overlapping internal IP ranges, multiple VPN providers meant multiple configurations to maintain, and static IPs and port forwarding added complexity on both sides of the connection. None of this scaled cleanly as TZ tried to grow past a handful of large accounts into a broader enterprise customer base.
TZ’s ambitions went beyond selling locker hardware: the company wanted to reposition around remote management and data capture as its core value, effectively becoming a logistics software provider rather than a hardware manufacturer. That shift only works if remote access is simple, secure, and repeatable across thousands of customer sites, and VPNs and firewall exceptions were the opposite.
TZ integrated NetFoundry Cloud into its architecture, replacing VPN-based remote access with a private, Zero Trust overlay network. Instead of asking customers to open firewall ports or maintain a tunnel, TZ’s locker systems and server-side assets connect outbound-only. They’re invisible to the internet and reachable only through NetFoundry’s Zero Trust fabric.
Because every connection is outbound-only, there’s nothing for a customer’s firewall team to open and nothing new to add to their attack surface. The locker system authenticates and reaches out to the network; nothing reaches in. That single architectural change is what took InfoSec reviews from a multi-week negotiation to something a security team could sign off on in one meeting.
TZ’s engineers can now connect directly to individual kiosks for maintenance and provisioning, authenticated by identity rather than network location. Access is governed by mutual TLS and X.509 certificate-based identity, which lets TZ apply least-privileged, micro-segmented permissions per session. Admins and data flows can reach exactly the resource they’re provisioned for, and nothing else.
NetFoundry’s full-mesh, self-healing network gave TZ a more resilient foundation for remote sessions than VPN tunnels, particularly for latency-sensitive remote administration across long distances. As TZ’s footprint grew into the hundreds of thousands of lockers and kiosks, that resilience became even more critical.
“NetFoundry Cloud has been a main enabler in our shift from a smart locker hardware manufacturer to a supplier of logistics software solutions.”
John Wilson, CEO, TZ
The clearest outcome for TZ wasn’t a cost or performance number; it was a change in how sales conversations went. InfoSec reviews that used to be a recurring point of friction became, in Wilson’s words, “single-meeting events”. For an enterprise sales motion, removing weeks of security back-and-forth from the buying process is close to a direct revenue outcome, even without attaching a percentage to it.
Identity-based policies and usage data replaced the patchwork of IP addresses, firewall access control lists, and identity-less VPN tunnels TZ used to manage per customer. That gave TZ’s team one consistent operational model across every account, instead of a slightly different networking configuration for every customer’s IT environment.
With remote access no longer tied to negotiating network exceptions account by account, TZ could move from hardware manufacturer to logistics software provider. New revenue models and service offerings could ship without TZ having to build new security or networking infrastructure to support them, because the Zero Trust foundation was already there.
TZ scaled its deployment well beyond hundreds of thousands of kiosks and lockers globally, across customers on different networks, hardware, and clouds, without the deployment consistency problems that usually come with that kind of growth. Customers got a security upgrade — from site-to-site VPNs to Zero Trust B2B connections — without changing their own network or firewall configuration at all.
NetFoundry helps product companies eliminate open attack surfaces, replace VPN complexity, and turn security reviews from a bottleneck into a differentiator — without rebuilding their architecture from scratch.
NetFoundry is a leader in Secure Workload Connectivity, founded by the inventors and maintainers of OpenZiti, the world’s most widely used open source Zero Trust platform. NetFoundry enables enterprises to secure and connect AI agents, MCP servers, LLMs, APIs, OT/IoT infrastructure, and traditional enterprise workloads, all with no open inbound ports, no VPNs, and no firewall changes. NetFoundry secures billions of sessions for critical infrastructure on three continents and supports Fortune 10 companies across regulated industries including healthcare, financial services, and energy.