Hero mask

SaaS Connect

Redefining Connectivity for Application Service Providers

SaaS Connect enables Application Providers to deliver their applications and services through a closed, secure, and high-performance ecosystem, rather than over the public Internet.

In this environment:

  • Traffic is fully shielded from the public Internet
  • The infrastructure remains under the control of the Application Provider
  • End-users and business partners can easily connect, without complexity

Instead of routing sensitive traffic across uncontrolled Internet paths, users connect via a dedicated port at NL-ix. From there, traffic is automatically and securely routed to the SaaS application.

Adding new end-users is seamless:
NL-ix processes the orders and enables access — no changes are needed on the Application Provider’s side.

SaaS Connect
No advanced configuration is required on the user side beyond a simple one-time setup.

Supporting Sovereignty and Data Security

SaaS Connect offers a robust answer to growing concerns about:

  • Data sovereignty
  • Cloud exit strategies
  • Security and compliance obligations

By moving traffic off the public Internet and into a private interconnection fabric, SaaS Providers regain control over their digital supply chain. The service is particularly well-suited to organizations subject to EU regulations, such as NIS2 or DORA.

SaaS Connect makes migrating away from Cloud hyperscalers easier as well. Applications can be moved between environments or datacenters while maintaining connectivity to users — without those users needing to reconfigure anything.

Use Case: Simplified Security at Scale

SaaS Connect is ideal for organizations that deliver applications to multiple external customers. Instead of relying on the open Internet, each end-user accesses the service via a private, trusted route.

This minimizes exposure, simplifies compliance, and eliminates the operational complexity of managing dozens or even hundreds of individual connections.

Optional Access to Public Applications via Transit

While the core of SaaS Connect is a closed, private ecosystem, it is also possible to integrate Transit access.

This hybrid setup ensures full flexibility— end-users can decide how they want to reach the application: either via a private connection that bypasses the public Internet, or via public Internet using VPN.

NL-ix provides this Transit as part of the overall solution, ensuring centralized management and visibility.

Technical Summary

  • Closed ecosystem: L2 private interconnection between SaaS Provider and end-users
  • Fully routed through the NL-ix closed ecosystem
  • Supports 1:N architecture: one port can serve many customers
  • Zero touch when expanding: No need to reconfigure when adding or removing end-users. NL-ix takes care of the routing and activation via the ecosystem. The end-user only needs to realize a one-time technical connection
  • SaaS Connect is infrastructure-neutral: traffic can land in cloud or on-premise environments
  • Cloud agnostic: Works independently of the cloud provider used (e.g. AWS, Azure), so that migration to another Cloud has no impact on users
  • Scalable & future-proof: New services, new clouds or datacenter changes can easily be facilitated without impact all end-users
  • Integrated with the NL-ix backbone — ISO 27001 and ISO 22301 certified, EU-based
Screenshot 2024-06-06 at 13.37.23
Public Application

Frequently asked Questions

What is the benefit of using SaaS Connect for accessing applications compared to the public Internet?

Applications that handle privacy-sensitive data or essential processes and are accessed via the public Internet requires an encrypted VPN tunnel to saveguard security, which increases data size and bandwidth needs. Encryption adds processing steps, causing latency and delaying data delivery. Moreover, the route to the private application is uncertain over the public Internet, as the path cannot be controlled.

SaaS Connect offers a direct private connection that minimizes latency, guarantees stable performance, and enhances data privacy. It shields the network from potential risks, facilitating resilience for crucial applications, and accommodates scalability as demands increase.

What is the benefit of using SaaS Connect compared to traditional Transport solutions

For providers of software solutions that handle critical processes or sensitive data—such as insurers, healthcare providers, or financial institutions—customers frequently request direct connections for secure data exchange. However, accommodating these requests often leads to a proliferation of point-to-point connections that must be documented and managed.

SaaS Connect consolidates these individual connections into a streamlined solution that still enables users to establish private, secure connections but without requiring the software provider to manage numerous individual links. This also enables both the software supplier as well as the end-user to easily change datacenter in case required.

What is the difference between Cloud Connect and SaaS Connect?

A Cloud Connect is a 1:1 connection towards the the Azure, AWS, Oracle or Google instances hosted in their datacenters. SaaS Connect offers a 1:N environment for SaaS Suppliers and their end-users to establish private, secure connections without numerous individual links. Read more

What different design options can be made for SaaS Connect

There are a couple of design options within SaaS Connect:

Public versus private environment.
For public applications users might demand direct connections in order to safeguard privacy-sensitive data and essential processes. However, other users might still reach the application via VPN over the public Internet. In order to accommodate this, it is possible to add Transit to the same port. That way, end-users can decide how they want to reach the application: either via a private connection that bypasses the public Internet, or via public Internet.

For private applications it is possible to create a completely private environment that is not accessible via the public Internet and with restricted access.

End-users can optionally see each other
By default, the different end-users connected to SaaS Connect cannot see each other, it is however possible to allow them to see each other.

How 20 years of experience helps with SaaS Connect

At NL-ix we hold 20 years of experience with building an exchange. This knowledge and technic we now use to build a private exchange for your SaaS-application. We provide you IP addresses to connect to the Route Servers and setup BGP sessions.

Does SaaS Connect also work in combination with private IaaS environments?

Yes, SaaS Connect is designed in such a way that it works in combination with applications hosted on-prem or in Cloud services such as Microsoft Azure, AWS, Oracle or Google.

At what datacenters are end-users able to connect to SaaS Connect?

End-users are able to connect in any of the >100 NL-ix datacenter PoPs. Because of our large footprint, we are probably already present in the same datacenter, or very nearby. NL-ix is datacenter-neutral and works with a wide variety of datacenter operators, making it easy to switch datacenters in case required.

Next to SaaS Connect, it is possible to add other services on the same port. These can be services to connect with private clouds, other SaaS providers or advanced Internet services such as Peering and Transit. Configuring multiple services on a single port saves on monthly patch and port costs.

Where can I find information in regards my Onboarding and Configuration

If you have placed an order at the NL-ix you will receive an 'order confirmation' mail. After the order confirmation has been send, the NL-ix provisioning team gets to work to deliver your order.

When the order has been delivered, for normal products usually within 10 working days after the order confirmation, the provisioning team will send an ‘order delivery’ email. This email contains all details you need to setup your connection. The delivery date is also the start date of invoicing.

You can find more information in regards the Onboarding and Configuration proces at Support

Use Case:

Data Back-up

Data Back-up Use Case

Organisations increasingly embrace off-prem back-up services with multiple repositories. For the simple reason of protecting their data assets, but also driven by law enforcements such as GDPR.

For the Data Back-up provider, SaaS Connect provides customers a private connection without the need of physical rental lines or patches. This increases the business flexibility, because you can easily move to another datacenter, without complex migrations. Moreover, to activate this service you just refer to NL-ix.

The end-user has the ability to securely send (sensitive) data, commonly from their own datacenter and without the need of heavy encrypted VPNs or expensive rental lines, making it more performant, secure and reliable.


Need help?

sales@nl-ix.net or call +31 (0)70 3120710

Or leave your details and we will contact you!

First name

Last name

Company name

Your email

My question is:

* Required fields