Introduction

Qpoint is a universal security and operations platform for egress HTTP/S traffic. It offers endpoint discovery, real-time insights, identity-based security, and dynamic middleware injection.

How It Works

QPoint is designed to optimize egress traffic management through a modular architecture that includes three main components: an outbound proxy with selective SSL termination, an eBPF probe, and a control plane. Each component can operate independently or be integrated to provide a comprehensive solution.

Qpoint Proxy

The proxy component of QPoint acts as an intermediary for clients seeking resources from external servers. It has the capability to perform selective SSL termination per endpoint. This means that SSL/TLS traffic can be terminated at the proxy to allow for inspection and monitoring of encrypted traffic, then re-encrypted as it continues to its destination. This selective termination is vital for maintaining security while enabling deep packet inspection and data loss prevention functionalities.

Qpoint Tap

The eBPF (Extended Berkeley Packet Filter) probe in QPoint provides advanced traffic monitoring and network performance analysis. It operates at the kernel level, allowing it to gather data about network flows and system calls without significant overhead. The eBPF technology is highly efficient and flexible, ideal for real-time data collection and analysis in high-throughput environments.

Control Plane

The control plane serves as the central nervous system of QPoint, managing and orchestrating the interactions between the proxy and eBPF probe. It ensures that policies are enforced, traffic is routed correctly, and network resources are allocated efficiently. The control plane also provides a user interface for administrators to set policies, view analytics, and receive alerts on network events.

These components can be deployed independently depending on the specific needs of the network environment, or linked together to enhance QPoint's capability to manage, monitor, and secure network traffic more effectively.

Why Qpoint?

Enhanced Observability

QPoint provides tools to clearly identify which applications are communicating outside your network, continuously monitors traffic flows, and delivers real-time insights into third-party API usage. It offers detailed visibility into API token usage and accurately maps the sources and destinations of all requests involving personally identifiable information (PII), which is essential for data flow management and compliance with privacy regulations.

Zero Trust Security

QPoint supports a zero trust security model by limiting access to external endpoints based on the identities of applications or services. This approach ensures that only verified and authorized entities can interact with sensitive external systems. QPoint also includes features to remove PII and other sensitive data from outgoing requests, enhancing data security and reducing exposure to data breaches.

Operational Resilience

QPoint improves operational resilience by providing insights into endpoint performance and the real-time detection of anomalies or operational issues. This proactive monitoring allows teams to address and mitigate potential rate limits before they result in throttling or affect production applications. QPoint's ability to adapt dynamically to network changes ensures reliable operation and optimal performance.

Last updated