Glossary
Agent-based
Connection mode in which a site or device is connected to the beemNet via the beem App, enabling additional security features over the agentless mode.
Agentless
Connection mode in which a site or device is connect directly to the beemNet via the Swisscom network (without the beem App).
beem Device Management
Feature to manage, monitor, and secure company devices across various operating systems by enforcing device policies and configurations.
beem Hub
Subpage in the My Swisscom Business portal (under the "Inventory" tab) with various tools for managing beem and its users.
beemNet
Swisscom's secure corporate network – the core of beem. beemNet protects all connected devices and networks and provides trustworthy access to the Internet.
Capacity Profile
The capacity profile determines the maximum amount of data traffic that can be protected by beem simultaneously.
Cloud Access Security Broker (CASB)
A security solution that monitors and controls access to cloud applications to protect data, enforce policies, and ensure compliance.
Concerto
Advanced portal for beem administrators to manage security policies, connection settings and view analytics.
Data Traffic Optimisation
beem optimises network performance by intelligently bypassing inspection for trusted traffic from verified secure sources.
Datagram Transport Layer Security (DTLS)
A security protocol that encrypts data sent over fast, connectionless networks (e.g., UDP) for private and secure communication.
Deep Packet Inspection (DPI)
An advanced firewall technology that examines packet contents and headers to detect, filter, and block malicious and unauthorized traffic.
Device Security Level
beem Device Management offers several security levels for client devices, each with a different strictness of posture and policy enforcement.
Edge Interceptor
A feature that enables secure access to networks, servers, and applications by intercepting incoming traffic and securely routing it to its destination.
Firewall as a Service (FWaaS)
A cloud-delivered firewall that provides network security and defence through extensive inspection and analysis of data traffic.
Identity & Access Management (IAM)
A framework of policies, technologies, and processes used to ensure the right users have access to digital resources.
Infrastructure as a Service (IaaS)
A cloud service (e.g., Microsoft Azure) that provides computing power, storage and other resources. beem supports the main IaaS.
IP Address Cloaking
Feature that hides the IP addresses of client devices and sites secured with beem. Only a generic public IP address from a shared pool is displayed.
My Swisscom Business
Swisscom’s online business customer portal. It allows companies to manage their services in one place, including beem (beem Hub).
Passkey
Device-stored private key that replaces traditional passwords by using biometrics and asymmetric encryption to deliver secure authentication.
Root Certificate Authority (Root CA)
A trusted authority whose certificate is installed by the beem App, allowing beem to inspect and secure encrypted traffic on your device.
Secure Access Service Edge (SASE)
An architecture that unifies network connectivity with security services (e.g., SWG, CASB, ZTNA, FWaaS) into a single cloud service.
Secure Web Gateway (SWG)
A security solution that protects against web threats by filtering traffic, enforcing policies and blocking malicious or unauthorized content.
Security Edition
beem is available in four editions (Essential, Standard, Plus and Premium), each tailored to different security and configurability needs.
Security Level
Essential Edition administrators can choose one of four progressively strict Security Levels. These pre-defined security policies are applied company wide.
Security Officer (SecOfr)
A dedicated tenant with unique credentials that provides administrators access to high-impact configuration tools (e.g., Concerto).
Single Sign-On (SSO)
An authentication method that allows users to log in once and gain access to multiple applications or services without needing to sign in separately.
Software as a Service (SaaS)
A software delivery model where applications (e.g., Office 365) are hosted online and accessed over the internet. beem supports many SaaS.
Software-Defined Wide Area Network (SD-WAN)
Alternative to regular WAN that uses software-based management to connect offices, remote users, and cloud services.
Solicited Data Traffic
Communication initiated by the receiving device, such as loading a webpage, downloading a file, or receiving a response from an API request.
Stateful Packet Inspection (SPI)
A firewall technology that tracks the state of active connections and only permits packets belonging to a known, legitimate session.
Swisscom Business Account
Personal user account for accessing online services (e.g., My Swisscom Business) and the beem App with secure authentication via Passkey.
Tenant
A dedicated and isolated instance that a company receives with beem (Standard Edition and upward). The beem tenant maintains all company specific beemNet settings and policies.
Transport Layer Security (TLS) Inspection
A process in which beem decrypts, inspects, and re-encrypts encrypted web traffic to detect threats and enforce policies.
Unsolicited Data Traffic
Communication without initiation from the receiving device, such as push notifications, incoming calls, or unexpected connection attempts.
Zero Trust Network Access (ZTNA)
A security approach that continuously verifies users and devices before granting specific and limited access to a network or application.
