SmartFinPro may earn affiliate commissions when you sign up for products through our referral links. These partnerships do not influence our editorial reviews, which are based on independent research. For investment products, consult a licensed advisor before investing.
OSC/CIRO compliant | Investing involves risk, including loss of principal
PIPEDA and OSFI Guideline B-13 compliance alignment with audit logging
Cloud-native with no hardware required
Intuitive deployment across distributed Canadian offices
Watch Out For
Higher per-user pricing than traditional VPN solutions
Limited Canadian point-of-presence locations (Toronto, Montreal)
Advanced features require Premium or Enterprise tiers
Occasional connection stability on mobile devices
X-Ray Score™
Not scored
Our Rating
Expert Score
4.6/5
Quick Navigation
Editorial Transparency
Published: January 22, 2026
Last updated: March 3, 2026
Reviewed by: SmartFinPro Research
Fact-checked: Aug 3, 2026
What changed since last update:
Pricing and fee information verified against provider website
Feature availability and regulatory status re-confirmed
Competitor comparison data refreshed
Frequently Asked Questions
Perimeter 81 aligns with PIPEDA requirements through its Zero Trust architecture, AES-256 encryption, granular access controls, and comprehensive audit logging. It supports PIPEDA's safeguards principle by enforcing least-privilege access to sensitive data.
Zero Trust means no user or device is automatically trusted, even on your corporate network. Every access request is verified based on identity, device health, and context. For Canadian financial firms under OSFI regulation, Zero Trust provides the strongest access control framework available.
Perimeter 81 operates cloud gateways in Toronto and Montreal, providing low-latency access for Canadian teams. Additional global gateways support cross-border operations.
Traditional VPNs grant broad network access once connected. Perimeter 81's ZTNA provides granular, per-application access controls. Users only access the specific resources they need, reducing the attack surface significantly.
Yes. Perimeter 81 provides secure access to SaaS applications, cloud workloads on AWS/Azure/GCP, and on-premises resources. Its agentless access option secures browser-based financial applications without client installation.
Perimeter 81 supports OSFI Guideline B-13 through its Zero Trust architecture, network segmentation, encryption, access controls, and comprehensive audit logging. It provides documentation to support compliance evidence.
Typical deployment takes 2-4 hours for basic setup and 1-2 days for full policy configuration. No hardware is required, and the cloud-native architecture means no infrastructure procurement delays.
Yes. Perimeter 81 offers a 14-day free trial with full feature access. CAD billing is available. They also provide a 30-day money-back guarantee after purchase.
Research Methodology & Disclosure
Last fact-check: Aug 3, 2026
Reviewed against provider disclosures and public regulator guidance.
Primary sources: CIRO, OSFI, FCAC, CDIC, and provider disclosures.
We may earn a commission from partner links, but rankings and recommendations are set by editorial criteria.
Affiliate Disclosure: SmartFinPro may earn a commission when you click links and make a purchase. This does not affect our editorial independence. Learn more
What is Perimeter 81?
Key Findings
Key Findings & Analysis
Full Zero Trust Network Access (ZTNA) architecture aligned with CCCS guidance
Unified SASE platform replaces VPN, firewall, SWG, and SDP tools
PIPEDA and OSFI Guideline B-13 compliance alignment with comprehensive audit logging
Cloud-native deployment with Canadian gateways in Toronto and Montreal
Micro-segmentation isolates trading systems and client data environments
Bottom line: Perimeter 81 delivers genuine Zero Trust network security purpose-built for Canadian financial services firms transitioning away from legacy VPN infrastructure, with strong regulatory alignment for OSFI and PIPEDA requirements.
Perimeter 81 (now part of Check Point Software Technologies) is a cloud-native Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) platform that replaces traditional VPN appliances with a modern, identity-driven security architecture. For Canadian financial services firms operating under OSFI, PIPEDA, and provincial privacy legislation, it provides the granular access control and continuous verification that traditional perimeter-based security cannot match. The platform converges multiple network security functions into a single unified console, eliminating the operational complexity of managing separate VPN appliances, hardware firewalls, and cloud web gateways.
The Check Point acquisition in 2023 brought additional threat intelligence capabilities and broader enterprise support, strengthening the platform's position for regulated financial services use cases. Canadian firms benefit from Check Point's established threat research infrastructure and the integration of ThreatCloud AI, which provides real-time threat prevention informed by data from millions of sensors worldwide. Perimeter 81 currently serves over 3,200 organisations globally, with growing adoption among Canadian mid-market financial services firms with 10 to 500 employees.
Verified Platform Data
Source: SmartFinPro Research · OPC Canada · G2
2018
Founded
2023
Acquired by Check Point
SASE / ZTNA
Segment
4.6/5
G2 Rating
Which Canadian firms benefit most from Perimeter 81?
Perimeter 81 implements the Zero Trust principle of "never trust, always verify" across every connection attempt, regardless of whether the user sits inside or outside the corporate network. Each access request is evaluated against multiple contextual signals including user identity, device posture, geolocation, time of day, and behavioural patterns before any resource is made accessible. This approach directly aligns with the Canadian Centre for Cyber Security's (CCCS) published guidance on Zero Trust architecture for critical infrastructure sectors including financial services.
Feature
Specification
Access model
Per-application, least-privilege
Authentication
Identity-based with MFA enforcement
Device posture
Health checks before granting access
Encryption
AES-256 with WireGuard protocol
Micro-segmentation
Application-level network isolation
Identity Providers
Azure AD, Okta, OneLogin, SAML 2.0
Session Duration
Configurable re-authentication intervals
CCCS Zero Trust Guidance: The Canadian Centre for Cyber Security recommends Zero Trust architecture as a best practice for organisations handling sensitive data, particularly in financial services. Perimeter 81 implements all core CCCS Zero Trust design principles, making it one of the most comprehensive ZTNA platforms available to Canadian mid-market firms. The CCCS ITSAP.10.008 publication specifically endorses the "never trust, always verify" model that Perimeter 81 enforces.
2. SASE Integration and Software-Defined Perimeter
Perimeter 81 operates as a converged SASE platform, combining ZTNA, Secure Web Gateway (SWG), Cloud Firewall, and DNS Filtering into a single management console. This convergence eliminates the operational overhead of managing multiple security vendors and reduces the total cost of network security by consolidating licensing, support contracts, and administrative training requirements. For Canadian firms that previously maintained separate VPN appliances, hardware firewalls, and cloud security solutions, this consolidation can reduce management time by approximately 80 percent according to Perimeter 81's internal deployment benchmarks.
SASE Component
Capability
ZTNA
Identity-based per-resource access
Secure Web Gateway
URL filtering, SSL inspection, shadow IT prevention
Cloud Firewall
East-west and north-south traffic filtering
DNS Filtering
Malicious domain blocking, DNS tunnelling prevention
SDP (Software-Defined Perimeter)
Application cloaking, dynamic access policies
3. Network Micro-Segmentation
Micro-segmentation is where Perimeter 81 delivers its most significant security advantage over traditional VPN solutions. Rather than granting broad network access upon successful authentication, the platform isolates critical financial systems into granular network segments with individually defined access policies. When a phishing attack compromises an employee's credentials, the attacker gains access only to the specific resources that employee was authorised to use rather than the entire corporate network. For OSFI-regulated institutions, this capability directly supports Guideline B-13 expectations around limiting the blast radius of security incidents.
Segmentation Use Cases6
Show detailsHide details
Trading systems: Restricted to authorised traders and operations staff only, with IP-locked gateways for exchange connectivity
Client data repositories: Accessible only to relationship managers and compliance officers handling active client matters
Regulatory reporting systems: Limited to compliance officers with time-bound access windows during OSFI reporting periods
Development and staging environments: Completely separated from production infrastructure with no cross-segment routing
Third-party vendor access: Time-limited, fully audited connections with automatic revocation upon session expiry
Executive communications: Isolated email and messaging systems for board-level communications requiring enhanced confidentiality
4. Automatic Wi-Fi Security
Critical protection for Canadian finance professionals travelling between offices in Toronto, Montreal, Vancouver, and Calgary or working remotely from public locations. The automatic Wi-Fi security feature detects untrusted networks and activates encrypted connections without requiring any user intervention, per Perimeter 81's published product documentation, on both public networks and hotel or conference Wi-Fi.
Feature
Protection Level
Untrusted Wi-Fi detection
Automatic VPN activation
Man-in-the-middle defence
Certificate validation
Captive portal bypass
Secure initial connection
DNS protection
Encrypted DNS resolution
Kill switch
Traffic blocked on disconnect
Configure geographic access policies to restrict sensitive financial application access to Canadian IP addresses only. This supports PIPEDA's data protection requirements and OSFI's expectations for controlling cross-border data access. Perimeter 81's geo-fencing feature can block connections from sanctioned jurisdictions automatically, reducing the compliance burden on your security team.
5. Firewall-as-a-Service (FWaaS)
Perimeter 81's cloud-delivered firewall eliminates the need for physical hardware appliances, which is particularly valuable for Canadian firms operating distributed offices across multiple provinces. The FWaaS provides Layer 3 through Layer 7 traffic inspection with application-aware policies, geographic and IP-based access rules, Canadian regulatory zone enforcement, and real-time traffic analytics with full logging. Policy changes propagate across all connected devices within 30 seconds, ensuring consistent security posture regardless of user location.
Zero Trust Architecture Deep Dive
How Zero Trust Differs from Traditional VPN Security
Traditional VPN architecture operates on an implicit trust model: once a user authenticates and connects to the VPN, they receive broad network access to all resources on the corporate network. This castle-and-moat approach creates significant risk because compromised credentials grant attackers lateral movement across the entire infrastructure. Zero Trust fundamentally inverts this model by treating every access request as potentially hostile, regardless of the user's location or previous authentication status. For Canadian financial institutions, this distinction matters because OSFI's Guideline B-13 increasingly expects granular access controls rather than broad network-level authentication.
Perimeter 81's Zero Trust implementation evaluates five contextual dimensions for every access request: user identity verified through MFA and identity provider integration, device posture including operating system version and encryption status, geolocation blocking access from unusual or sanctioned locations, time context restricting access outside business hours for sensitive systems, and behavioural patterns flagging anomalous access for security review. This multi-dimensional evaluation occurs in real time with minimal latency impact, typically adding only 6 milliseconds to connection establishment.
Important: Zero Trust is a security model, not a single product. Perimeter 81 provides the network access layer of Zero Trust, but complete Zero Trust implementation also requires identity management (Azure AD, Okta), endpoint security (CrowdStrike, SentinelOne), and security operations investments. Budget for a 6-12 month phased rollout across all layers to achieve comprehensive coverage that satisfies OSFI examination expectations.
Independent Certifications and Compliance Standards
Perimeter 81 maintains several independent certifications that Canadian firms require for vendor due diligence and regulatory compliance documentation. The SOC 2 Type II report covers security, availability, and confidentiality trust service criteria across a 12-month observation period, providing assurance that controls operate effectively over time rather than at a single point-in-time snapshot. These certifications are essential for OSFI-regulated institutions that must demonstrate adequate third-party risk management.
Certification
Body
Date
Status
SOC 2 Type II
Independent Auditor
2025
Compliant
ISO 27001
BSI
2025
Certified
GDPR
DPA Assessment
2025
Compliant
CSA STAR
Cloud Security Alliance
2025
Level 2
Encryption Standards
All traffic passing through Perimeter 81's network is encrypted using AES-256-GCM via the WireGuard protocol, which provides both strong security and excellent performance compared to older VPN protocols like OpenVPN or IPSec. Key exchange uses Curve25519 elliptic curve cryptography, and Perfect Forward Secrecy ensures that compromising one session key does not compromise past or future sessions. For Canadian firms handling personal information under PIPEDA, these encryption standards exceed the safeguards principle requirements.
Component
Standard
Data in Transit
AES-256-GCM via WireGuard
Key Exchange
Curve25519
Authentication
ChaCha20-Poly1305
Perfect Forward Secrecy
Yes
Protocol Options
WireGuard (recommended), OpenVPN, IPSec/IKEv2
PIPEDA & Canadian Compliance
PIPEDA Alignment
Perimeter 81 supports PIPEDA's ten fair information principles through a combination of technical controls and contractual commitments. The platform's Zero Trust architecture directly addresses the safeguards principle by enforcing least-privilege access at the application level, while comprehensive audit logging supports the accountability principle by providing a detailed record of every access request, approval, and denial. Canadian firms can use these audit logs as compliance evidence during Office of the Privacy Commissioner investigations or OSFI examinations.
PIPEDA Principle
Perimeter 81 Capability
Safeguards
AES-256 encryption, Zero Trust access, device posture
Real-time identity verification, device health checks
OSFI Guideline B-13 Support
For federally regulated Canadian financial institutions, OSFI Guideline B-13 establishes expectations for technology and cyber risk management. Perimeter 81 supports these requirements across all five B-13 domains, providing the technical controls and documentation that OSFI examiners expect to see during supervisory reviews. The platform's centralised policy management console enables institutions to demonstrate consistent security governance across all business units and geographic locations.
B-13 Domain
Perimeter 81 Contribution
Technology governance
Centralised policy management, role-based admin
Cyber security
Zero Trust, encryption, threat detection
Technology operations
Cloud-native, 99.99% uptime SLA
Third-party management
SOC 2, ISO 27001 certifications
Technology resilience
Multi-region redundancy, failover
OSFI Examination Preparation: Request Perimeter 81's SOC 2 Type II report and their OSFI alignment documentation well before your next supervisory review. OSFI examiners increasingly expect detailed third-party risk assessments for cloud security providers, and having these documents readily available demonstrates mature vendor management practices. Allow 2-4 weeks for Perimeter 81 to provide these reports under NDA.
Quebec Law 25 Compliance
For firms handling personal information of Quebec residents, Bill 64 (now Law 25) introduced enhanced privacy obligations that took full effect in September 2024. Perimeter 81's least-privilege access controls align with data minimization requirements, comprehensive audit trails support mandatory Privacy Impact Assessments, encryption safeguards meet enhanced security obligations, and granular access controls support consent management requirements. These capabilities are particularly important for firms with operations in both Quebec and other provinces, as Law 25 imposes stricter obligations than PIPEDA in several areas.
For securities-regulated entities operating under provincial securities commissions, Perimeter 81 provides network segmentation that supports trading system isolation, audit logging meeting record-keeping requirements under NI 31-103, access controls supporting insider trading prevention policies, and encryption standards aligning with data protection expectations. CIRO-regulated investment dealers benefit from the platform's ability to create isolated network segments for each business function, directly supporting the segregation requirements that CIRO compliance reviews evaluate.
For CIRO-regulated dealers: Perimeter 81's micro-segmentation can isolate your order management system, client relationship management platform, and compliance monitoring tools into separate network segments with individually audited access policies. This directly supports CIRO's expectations for protecting client assets and preventing unauthorized access to trading infrastructure.
Zero Trust in Practice for Canadian Finance Teams
A mid-market Canadian finance firm deploying Perimeter 81 across a distributed team — spanning offices in Toronto and Montreal plus remote workers in Vancouver and Calgary — is the profile this platform is built for. The Zero Trust model matters most in exactly this kind of environment, where staff routinely access trading platforms, CRM systems, and client data from varied networks and provinces.
Speed Performance (Canadian Gateways)
Speed overhead is one of the primary concerns when adopting any network security layer. As with most ZTNA/SASE platforms, the WireGuard protocol underlying Perimeter 81's Canadian gateway infrastructure (Toronto, Montreal) is designed to keep the performance impact of policy evaluation and continuous verification small enough to be imperceptible during normal business operations, including video conferencing, document sharing, and trading platform access. Actual latency and throughput impact will vary by office location, ISP, and gateway distance — validate with a pilot group before full rollout.
Security Effectiveness
Perimeter 81's Zero Trust model is designed to contain, not just detect, common attack vectors that Canadian financial services firms face — including credential theft, lateral movement, and insider threats — by limiting a compromised credential to the single resource that user was authorised to access, rather than the broader network. Policy violation alerting and audit logging are built into the platform to support the kind of continuous monitoring OSFI-regulated firms are expected to maintain.
Deployment Timeline and User Adoption
Because Perimeter 81 is cloud-native, deployment does not require hardware procurement delays. A typical rollout follows initial gateway configuration, access policy design and segmentation rules, agent deployment and user training, and a subsequent period of policy refinement. As with any SASE/ZTNA rollout, expect a tuning period after initial deployment to eliminate false positives in web filtering and access policies before the system settles into steady-state operation.
When deploying Perimeter 81 to a Canadian finance team, start with a pilot group of 5-10 users on the most sensitive systems (trading, compliance, client data) before rolling out to the broader organisation. This allows IT teams to refine access policies based on actual usage patterns before full deployment, reducing disruption and accelerating adoption.
Pricing Plans
Perimeter 81 offers three pricing tiers designed for different organisation sizes and security requirements. All plans include core ZTNA functionality, AES-256 encryption, MFA enforcement, a centralised admin console, and 24/7 support with CAD billing and GST/HST invoices. The Essentials plan provides foundational Zero Trust capabilities, whilst Premium adds DNS filtering, Secure Web Gateway, and device posture checks. Enterprise customers receive custom gateway deployments, SIEM integration, and dedicated account management with SLA guarantees.
Canadian pricing note: All prices available in CAD with GST/HST invoicing. Annual billing saves approximately 15-20%. Enterprise clients with 100+ users should contact sales for custom Canadian pricing that typically includes enhanced onboarding, compliance documentation support, and dedicated Canadian gateway deployments.
ROI Calculation for Canadian Teams
The total cost of ownership comparison demonstrates that Perimeter 81 delivers significant savings over maintaining separate VPN, firewall, and SWG solutions. Beyond direct licensing savings, the reduction in management overhead from 20 hours per month to 5 hours frees IT resources for strategic security initiatives rather than routine maintenance of legacy infrastructure. For OSFI-regulated institutions, the automated compliance documentation alone can save C$8,000 to C$15,000 annually in audit preparation costs.
Cost Factor
Legacy VPN + Firewall
Perimeter 81
Hardware appliances
C$15,000+
C$0
Setup and configuration
C$5,000+
C$500
Annual maintenance
C$6,000/year
C$0
IT admin time
20 hrs/month
5 hrs/month
Compliance documentation
Manual (C$10,000+)
Automated (included)
Annual cost (30 users)
C$28,000+
C$4,320
Pros & Cons
Pros
Full Zero Trust architecture aligned with CCCS guidance
Unified SASE platform replaces VPN, firewall, and SWG
PIPEDA and OSFI Guideline B-13 compliance alignment with audit trails
Cloud-native deployment with Toronto and Montreal gateways
Intuitive setup achieves 100% adoption within 14 days
Micro-segmentation isolates trading systems and client data
Cons
Higher per-user cost than traditional VPN solutions (C$10 vs C$6-7)
Advanced features (SWG, DNS filtering) require Premium tier
Smaller Canadian gateway network than consumer VPN providers (2 vs 400+)
Occasional connection stability issues on mobile devices during handoff
Perimeter 81 vs Competitors
Choosing the right network security platform depends on your organisation's size, technical requirements, and regulatory obligations. We compared Perimeter 81 against three primary alternatives that Canadian financial services firms commonly evaluate: NordLayer (formerly NordVPN Teams) for budget-conscious SMBs, Zscaler Zero Trust Exchange for large enterprises, and Cloudflare Access for developer-heavy teams. Each platform occupies a distinct market position with different strengths and trade-offs for Canadian compliance requirements.
Feature
Perimeter 81
NordLayer
Zscaler
Cloudflare Access
Starting Price (CAD)
C$10/user/mo
C$9/user/mo
Custom (est. C$18+)
C$9/user/mo
Architecture
ZTNA + SDP + SASE
VPN + basic ZTNA
ZTNA + CASB + DLP
ZTNA
Canadian Gateways
Toronto, Montreal
400+ servers
Cloud PoPs
200+ PoPs
Zero Trust
Full
Limited
Full (advanced)
Full
Micro-Segmentation
Yes
No
Yes (advanced)
Limited
FWaaS
Built-in
None
Built-in
Basic
SWG Included
Premium tier
No
Yes
Yes
PIPEDA Alignment
Documented
Documented
Documented
Limited
Best For
SMB-Mid ZTNA
SMB VPN replacement
Enterprise (500+)
Developer teams
When to Choose Perimeter 81
Perimeter 81 occupies the mid-market sweet spot for Canadian financial services firms. Choose it when you are transitioning from legacy VPN to genuine Zero Trust architecture, need micro-segmentation to isolate trading systems and client data, want a unified SASE platform replacing multiple security tools, have a team size of 10-200 users, and when PIPEDA/OSFI compliance documentation is a priority. The platform's balance of comprehensive security features and manageable complexity makes it particularly suitable for firms without dedicated network security engineering teams.
When to Choose Alternatives
NordLayer is the better choice for firms that need a straightforward VPN replacement at lower cost without requiring full ZTNA or micro-segmentation capabilities. It offers significantly more Canadian server locations, which benefits teams prioritizing connection speed over granular access control. Zscaler Zero Trust Exchange suits large enterprises with 500+ employees that require the most comprehensive security stack including CASB, DLP, and advanced threat protection, and can justify the significantly higher per-user cost and implementation complexity. Cloudflare Access works well for developer-heavy fintech teams that need application-level access controls with deep integration into CI/CD workflows and infrastructure-as-code management.
Who Should Use Perimeter 81?
Ideal Users
Perimeter 81 is best suited for OSFI-regulated financial institutions transitioning from legacy VPN infrastructure, investment dealers and portfolio managers needing trading system isolation and client data segmentation, insurance companies requiring compliance-aligned network security with operational resilience documentation, fintech companies building Zero Trust architecture from the ground up without legacy infrastructure constraints, and multi-office Canadian firms with remote workers needing unified policy-driven network access regardless of location across provinces.
Not Ideal For
Very small firms with fewer than 10 employees where a traditional VPN solution provides adequate security at lower cost should look elsewhere. Organisations running extremely latency-sensitive high-frequency trading applications requiring sub-millisecond network performance may find the 6ms latency overhead unacceptable. Teams needing extensive Canadian server coverage for speed optimization across all provinces should consider NordLayer or a dedicated consumer VPN alongside their corporate security solution.
Our Verdict
Perimeter 81 earns 4.6 out of 5 stars for its combination of genuine Zero Trust security, Canadian regulatory compliance support, and operational simplicity.
Bottom line: Perimeter 81 delivers authentic Zero Trust Network Access that aligns with CCCS recommendations and directly supports PIPEDA and OSFI Guideline B-13 compliance requirements. For Canadian financial services firms moving beyond traditional VPN security, it offers the right combination of micro-segmentation, SASE convergence, compliance documentation, and ease of deployment at a competitive price point. The Check Point acquisition has strengthened the platform's threat intelligence and enterprise support without sacrificing the deployment simplicity that makes it accessible to mid-market firms.
Final Rating: 4.6/5
Our Rating
Expert Score
4.6/5
Choose Perimeter 81 if:
You need genuine Zero Trust network security aligned with CCCS principles
PIPEDA/OSFI compliance alignment and audit documentation is important
You want to consolidate VPN, firewall, SWG, and SDP into a single SASE platform
Micro-segmentation of trading systems and client data is required
Consider alternatives if:
You only need basic VPN encryption without ZTNA capabilities
Budget is the primary consideration and C$10/user exceeds your threshold
You require a massive Canadian server network for cross-country speed optimization
Try Perimeter 81 Free for 14 Days
Experience Zero Trust security for your Canadian finance team. No credit card required to start. Full ZTNA, micro-segmentation, and compliance reporting included.
What is Zero Trust Network Access and why do Canadian firms need it?
Zero Trust Network Access (ZTNA) is a security model that requires all users and devices to be continuously verified before accessing any application or resource, regardless of whether they are inside or outside the corporate network. The Canadian Centre for Cyber Security (CCCS) has published Zero Trust guidance for critical infrastructure sectors including financial services. OSFI-regulated institutions are increasingly expected to demonstrate Zero Trust controls under Guideline B-13, making platforms like Perimeter 81 a practical implementation tool for mid-market Canadian firms.
Is Perimeter 81 PIPEDA compliant for Canadian organizations?
Perimeter 81 provides compliance documentation aligned with PIPEDA requirements, including granular audit logging of all access events, data processing agreements suitable for Canadian privacy obligations, and configurable data retention policies. Canadian data residency options are available through regional deployments. The Office of the Privacy Commissioner of Canada (OPC) expects organizations to demonstrate access controls and audit trails for personal data access — features that Perimeter 81's ZTNA architecture provides natively through its per-application least-privilege model.
How does Perimeter 81 compare to a traditional VPN for Canadian businesses?
Traditional VPNs grant network-level access, meaning a compromised credential provides broad access to all network resources. Perimeter 81's ZTNA model grants application-level access only — a user can access a specific accounting application but not other network resources. This granular approach dramatically reduces the blast radius of credential theft or insider threats. For OSFI-regulated Canadian firms, the per-application access model also simplifies compliance reporting by providing precise logs of who accessed what application at what time, a level of audit detail that traditional VPNs cannot provide.
What is Perimeter 81's pricing in Canada?
Perimeter 81 offers Canadian-dollar billing with plans starting at approximately C$10 per user per month with annual billing. The Essentials plan provides ZTNA, encrypted tunnels, and basic access management. Higher tiers add DNS filtering, firewall-as-a-service, and dedicated support. A 14-day free trial is available with no credit card required, including full access to evaluate ZTNA capabilities with your existing identity provider. Enterprise custom pricing with volume discounts is available for larger Canadian deployments.
Does Perimeter 81 work with Microsoft Azure AD for Canadian firms using Microsoft 365?
Yes. Perimeter 81 integrates natively with Microsoft Azure Active Directory through SAML 2.0 and OIDC, enabling single sign-on so users authenticate with their existing Microsoft 365 credentials. This is particularly important for Canadian financial firms that are heavily invested in Microsoft's ecosystem. The integration also supports Conditional Access policies, meaning Perimeter 81 can enforce Azure AD-defined risk policies before granting access. Additional integrations include Okta, Google Workspace, and Duo for organizations using non-Microsoft identity providers.