WZ-IT operates an upstream gateway layer that makes selected web applications available through a defined domain. Application servers, administration interfaces and internal networks do not have to be exposed directly to the public internet.
Companies worldwide trust WZ-IT
The gateway separates the public entry point from the actual target system. Domain, TLS, routing and the agreed access path are brought together in one managed layer.
Users access a documented hostname that is assigned to one clearly scoped web application.
The target system remains behind the gateway and is reached only through the agreed network path.
WZ-IT monitors the gateway service, maintains the system and proxy and manages the agreed TLS configuration.
The starting point is intended for one clearly scoped HTTP(S) web application. Target system, reachability, user group and protection requirements are confirmed before provisioning.
WZ-IT provides the upstream gateway layer and assumes responsibility for its technical operation.
A defined domain or subdomain is mapped to the agreed HTTP(S) target.
Certificate provisioning, renewal and the agreed TLS configuration are managed on the gateway layer.
A direct, restricted or private connection path is designed around the existing environment.
Availability is monitored proactively 24/7. Security advisories, the operating system and proxy component are assessed and updated within the agreed scope.
The gateway configuration required for recovery is backed up within the agreed scope. Application data remains separate.
Configuration, changes and technical findings are coordinated with a dedicated contact.
Service boundary
The application is only exposed after the target, network path, TLS, access rule and technical validation fit together.
Capture the target system, protocol, user group, domain and required reachability.
Choose the appropriate path between gateway and application and identify required firewall rules.
Set up and test the hostname, TLS, proxy rules and agreed access restrictions.
Activate the endpoint in a controlled process, monitor and update it and document changes.
Starting price
The starting point applies to a manageable standard configuration. Before proposing the service, we review the target system, connection, access, traffic and operating requirements.
Managed Cloud Gateway
from €129.90 / month
excluding VAT, monthly
For one clearly scoped external access path to an internal, local or otherwise non-public web application.
The price is a starting point, not a flat rate for arbitrary applications or access models. Additional hostnames and targets, private tunnels, SSO, dedicated protection controls, traffic, log retention, setup and higher service levels are assessed transparently in the proposal.
All prices are net and exclude statutory VAT. The offers are addressed to businesses.
Depending on the user path, the gateway can be combined with local infrastructure, private secure access or a dedicated operating framework.
Run open-source and business applications on a managed local application server at your organisation.
View App NodeConnect private networks, administration access, sites and users through identity-based controls.
View Secure Accessfrom €499.90 excl. VAT / monthAssess the separate WZ-IT infrastructure and contractual framework for professional secrets.
View the Section 203 serviceRequest a gateway
Describe the target system, user group, domain and current reachability. The enquiry is non-binding.
Reverse proxy, TLS, private connectivity, access and service boundaries
A managed cloud gateway is an upstream access layer operated by WZ-IT for selected web applications. It receives requests under a defined domain, terminates TLS and forwards them to the target through the agreed path. WZ-IT manages the gateway layer; the application and origin server are included only when they are covered by an additional agreement.
Yes. Its technical core is a reverse proxy operated by WZ-IT. The term cloud gateway describes the complete managed service covering provisioning, domain and TLS configuration, routing, monitoring, updates and documented integration with the existing environment.
The standard starting point is designed for browser-based applications and HTTP(S) targets. WebSockets and application-specific requirements can be considered after technical review. RDP, SSH, database access and full network access require a more appropriate secure-access, VPN or remote-desktop solution.
Not necessarily. Depending on the environment, the gateway can reach the target through a private tunnel, site-to-site connection or a tightly restricted public origin. The suitable approach depends on the location, firewall, existing connectivity and availability requirements.
The cloud gateway exposes one selected web service through a defined endpoint. A VPN or NetBird connects users, devices, sites and private networks. Secure access is generally more suitable for administration or several internal services, and both approaches can be combined.
Integration of an agreed hostname and provisioning and renewal of its TLS certificate on the gateway are part of the planned service scope. Registration, provider charges and administration of a new domain are itemised separately where required.
No. A reverse proxy is not automatically a web application firewall and does not replace penetration testing or dedicated DDoS protection. Access restrictions and technical protection components are assessed separately according to the actual risk.
The starting point is intended for a manageable standard configuration with a managed gateway layer, one defined hostname and HTTP(S) target, TLS, proactive 24/7 monitoring, updates, configuration backup and documentation. The final scope and price depend on factors including the connection, access model, traffic, logs, availability and additional infrastructure.
Yes. Managed Open Source, Managed Servers, App Node or software maintenance can be added as appropriate. The cloud gateway remains a separate component so that responsibilities for access, infrastructure and application remain transparent.
Yes, after assessment under the separate Section 203 Managed Cloud. Booking the standard gateway alone does not establish that operating and contractual framework. The application, data paths, participating infrastructure and required addenda are assessed together.
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Customer feedback on monitoring, updates, maintenance, support and stable production systems.
“WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.”

Steve Kirchner
Managing Director, nextGYM GmbH

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.