# 坤安科技股份有限公司 / Kunan Technology > Kunan Technology (坤安科技) is a Taiwanese cyber security company. It builds Merak, an SDP-based zero trust platform that makes enterprise services invisible to unauthenticated requests, and runs red team and penetration testing engagements that validate those defences under real attack conditions. 坤安科技專注於零信任網路架構與攻擊面管理。核心產品 Merak 以 SDP(軟體定義邊界)為基礎,讓企業服務對未經驗證的請求完全不可見;另提供紅隊演練與滲透測試服務,以真實攻擊手法驗證防禦是否成立。 This file is generated at build time from the site content itself, in the format described at https://llmstxt.org. - Languages: 繁體中文 (zh-TW) at https://kunansec.com/; English (en-US) at https://kunansec.com/en/. Every page exists in both, and each declares the other through `hreflang`. - Contact: contact@kunansec.com - Founded: 2024. Country: TW. - Full URL list for crawlers: https://kunansec.com/sitemap-index.xml - Human-readable site map: https://kunansec.com/sitemap/ - Attribution: page content belongs to Kunan Technology and may be quoted with attribution. Links under the resources centre point at external documents from government agencies, standards bodies and non-profits — those belong to their publishers, and the publisher is authoritative. ## 主要頁面 (zh-TW) - [首頁](https://kunansec.com/): 坤安科技以 SDP 零信任架構打造 Merak 隱形網路防護平台,讓企業服務不暴露 IP、不開放連接埠,並提供滲透測試與紅隊演練服務。 - [關於我們](https://kunansec.com/about/): 坤安科技專注於零信任網路架構與攻擊面管理,開發 Merak 隱形網路防護平台,並提供紅隊演練與滲透測試服務。 - [聯絡我們](https://kunansec.com/contact/): 洽詢 Merak 零信任隱形網路防護平台的導入評估、預約產品 Demo,或討論紅隊演練與滲透測試需求。 ## 解決方案 (zh-TW) 坤安科技的解決方案涵蓋 Merak 零信任隱形網路防護平台,以及紅隊演練與滲透測試服務,從架構防護到攻擊驗證完整覆蓋。 Section index: https://kunansec.com/solutions/ - [Merak 隱形網路防護平台](https://kunansec.com/solutions/merak/): 基於零信任架構,讓企業服務對未驗證請求徹底隱形。控制平面與資料平面分離,資料點對點加密直連,絕不經過第三方伺服器。 - [紅隊演練與滲透測試](https://kunansec.com/solutions/red-team/): 由具備國際認證的攻擊團隊,以真實駭客手法檢驗系統、人員與流程的防禦落差。將測試結果轉化為「可執行的修補優先順序」。 ## 最新消息 (zh-TW) 坤安科技的公司公告、活動訊息與得獎榮譽。 Section index: https://kunansec.com/news/ - [坤安科技官方網站改版上線](https://kunansec.com/news/official-website-relaunch/): 官網完成改版,新增 Merak 產品專頁、資源中心與英文版本,並將每則消息獨立為可分享的網址。 — updated 2026-08-01 ## 資源中心 (zh-TW) 零信任、SDP 與資安實務的權威外部參考文獻(政府機關、標準組織與非營利機構),以及坤安的技術部落格。 Section index: https://kunansec.com/resources/ - [產品文件](https://kunansec.com/resources/docs/): 坤安科技產品文件索引:各項產品的線上說明手冊與可下載的操作手冊,目前收錄 Merak 零信任網路存取平台。 — 1 項產品 - [技術部落格](https://kunansec.com/resources/blog/): 坤安科技的技術文章:零信任架構設計、威脅分析、導入實務與合規對應。 — 10 篇文章 - [白皮書](https://kunansec.com/resources/whitepapers/): 零信任與 SDP 的基礎標準、框架與法規原文,來自各國政府機關與標準組織。 — 9 份參考資料 - [案例研究](https://kunansec.com/resources/case-studies/): 公開的實作指引、攻擊行為知識庫與威脅情資來源,可用來對照自身環境的風險。 — 10 份參考資料 - [標準與規範](https://kunansec.com/resources/standards/): 協定規格、身分驗證指引與測試方法論的權威原文,適合工程與稽核作業直接引用。 — 9 份參考資料 - [公開文件下載](https://kunansec.com/resources/downloads/): 坤安科技公司簡介、Merak 產品規格書、導入檢核表、資安實踐說明與保密協議範本下載。 — 1 份文件 ## Merak 零信任網路存取平台 (zh-TW) Merak 決定「誰可以透過哪一條路徑存取哪一個服務」。這份手冊以任務為單位編排,讓你用想完成的工作找到需要的章節,而不是用猜的找選單。 Section index: https://kunansec.com/resources/docs/merak/ - [快速上手](https://kunansec.com/resources/docs/merak/getting-started/): 登入、啟用帳號、找回密碼、設定 MFA,以及認識管理主控台的版面配置。 — updated 2026-09-03 - [成員](https://kunansec.com/resources/docs/merak/members/): 管理實際使用存取權的人:他們的帳號、他們的裝置,以及他們可以連到哪些服務。 — updated 2026-09-03 - [應用程式](https://kunansec.com/resources/docs/merak/applications/): 透過 Merak 發布一個服務:流量真正送到哪裡、成員用什麼名稱連它,以及誰可以連上它。 — updated 2026-09-03 - [組織](https://kunansec.com/resources/docs/merak/organizations/): 把成員與應用程式分組,讓授權以團隊為單位進行,而不是一次一個人。 — updated 2026-09-03 - [Merak Node](https://kunansec.com/resources/docs/merak/merak-nodes/): 真正在成員與服務之間承載流量的邊緣路由節點。 — updated 2026-09-03 - [審批](https://kunansec.com/resources/docs/merak/approvals/): 檢視並裁決那些正在等人決定的申請。 — updated 2026-09-03 - [日誌](https://kunansec.com/resources/docs/merak/logs/): 兩份唯讀紀錄:系統裡「誰做了什麼」,以及網路上「誰連上了什麼」。 — updated 2026-09-03 - [管理員與角色](https://kunansec.com/resources/docs/merak/administrators-and-roles/): 誰可以操作管理主控台,以及他到底能操作到什麼程度。 — updated 2026-09-03 - [批次作業](https://kunansec.com/resources/docs/merak/bulk-operations/): 對成百上千筆資料做同一件事:匯出清單、對選取的列執行操作,以及從試算表匯入。 — updated 2026-09-03 - [我的帳號](https://kunansec.com/resources/docs/merak/my-account/): 你自己的個人資料、密碼、第二道驗證因素,以及主控台在你手上的外觀與行為。 — updated 2026-09-03 - [Agentless 入口網站](https://kunansec.com/resources/docs/merak/agentless-portal/): 成員不必安裝任何東西,就能用瀏覽器連上自己服務的那個頁面。 — updated 2026-09-03 - [附錄 A · 權限對照表](https://kunansec.com/resources/docs/merak/appendix-permissions/): 每一個權限鍵值、它打開哪個頁面,以及它讓哪些按鈕出現。 — updated 2026-09-03 - [附錄 B · 狀態對照表](https://kunansec.com/resources/docs/merak/appendix-statuses/): 產品中每一種狀態值的意義,以及它讓你能做什麼。 — updated 2026-09-03 - [附錄 C · 疑難排解](https://kunansec.com/resources/docs/merak/appendix-troubleshooting/): 出了什麼事、為什麼會這樣,以及接下來該怎麼做。 — updated 2026-09-03 ## 技術部落格 (zh-TW) Section index: https://kunansec.com/resources/blog/ - [SDP v3.0 改了什麼:從單封包授權到身分原生](https://kunansec.com/resources/blog/sdp-v3-architecture-guide/): SDP v3.0 把單封包授權從「定義」降級成選項之一。新版實際改了哪幾件事、SPA 在 IoT 與雲端函數上為什麼撐不住、SDP 與微隔離的界線該畫在哪裡,以及導入時第一步該做什麼。 — updated 2026-09-14 - [VPN 漏洞為什麼補不完](https://kunansec.com/resources/blog/vpn-vulnerabilities/): 用 CISA 已知被利用漏洞目錄的實際數字回答:VPN 漏洞六年來累積了幾筆、為什麼集中在少數幾家廠商、為什麼補丁永遠慢一步,以及補完之後還必須做什麼。 — updated 2026-08-22 - [軟體定義邊界(SDP)是什麼、怎麼運作](https://kunansec.com/resources/blog/software-defined-perimeter/): 軟體定義邊界把邊界從網路入口搬到每個資源前面:三個角色與兩個平面、單封包授權為什麼讓掃描器連拒絕都收不到、它和連接埠敲門差在哪,以及這套架構擋不住什麼。 — updated 2026-08-13 - [你的公司在公網上暴露了什麼:攻擊面盤點](https://kunansec.com/resources/blog/attack-surface-inventory/): 攻擊面盤點要回答的是「從外面看得到什麼」:攻擊者從一個網域能推出多少資產、六類最常被漏掉的對外服務、不用買工具的五個步驟,以及每一項該關掉還是改成授權後才可達。 — updated 2026-08-12 - [VPN 替代方案怎麼選、怎麼汰換](https://kunansec.com/resources/blog/vpn-replacement-migration-path/): 評估 VPN 替代方案時真正該問的問題:汰換前要盤點什麼、並行期怎麼設計、第一批搬哪些服務、裝不了代理的老系統怎麼辦,以及怎麼驗證真的換掉了。 — updated 2026-08-12 - [勒索軟體入侵途徑:從暴露的服務到加密](https://kunansec.com/resources/blog/ransomware-attack-chain/): 拆解勒索軟體入侵途徑的每一段:初始入侵靠的是什麼、進來之後怎麼擴散、為什麼有備份還是被勒贖,以及整條攻擊鏈裡哪一環最便宜擋。 — updated 2026-08-12 - [紅隊演練與滲透測試差在哪](https://kunansec.com/resources/blog/pentest-vs-red-team/): 紅隊演練與滲透測試在目標、範圍、時長與交付物上的實際差別,什麼情況下該做哪一種,以及界定範圍、讀報告時最容易吃虧的地方。 — updated 2026-08-12 - [何謂零信任架構](https://kunansec.com/resources/blog/what-is-zero-trust/): 寫給不碰技術的經營者:零信任到底在解決什麼問題、和過去的資安做法差在哪、對公司實際值多少,以及該問資訊部門哪些問題。 — updated 2026-08-07 - [Merak 零信任網路是怎麼運作的](https://kunansec.com/resources/blog/how-a-zero-trust-network-works/): 從平面分離、憑證身分、分層加密、逐連線授權到出站撥號,用八張圖拆解零信任網路的每一個核心機制,以及它們各自的取捨與限制。 — updated 2026-08-02 - [傳統 VPN、閘道式 ZTNA 與 SDP 架構比較](https://kunansec.com/resources/blog/architecture-comparison/): 三種遠端存取架構在攻擊面、資料路徑、存取粒度與部署模式上的技術差異,以及各自適用的情境與限制。 — updated 2026-08-01 ## 公開文件下載 (zh-TW) Section index: https://kunansec.com/resources/downloads/ - [Merak Console 操作手冊](https://kunansec.com/Merak_%E6%93%8D%E4%BD%9C%E6%89%8B%E5%86%8A_v1.1.pdf): 從帳號啟用、Merak Agent 安裝與設備認證,到成員管理、應用程式與節點建置、角色與管理員權限設定的完整操作流程,並附常見問題與設備狀態對照表。適用 Merak Agent 1.4.2。 — PDF — updated 2026-09-04 ## Main pages (en-US) - [Home](https://kunansec.com/en/): Kunan Technology builds Merak, an SDP-based zero trust platform that removes exposed IPs and open ports from enterprise services, alongside penetration testing and red team engagements. - [About](https://kunansec.com/en/about/): Kunan Technology focuses on zero trust network architecture and attack surface management, developing the Merak invisible network platform alongside red team and penetration testing services. - [Contact](https://kunansec.com/en/contact/): Discuss a Merak deployment assessment, request a product demo, or scope a red team or penetration testing engagement. ## Solutions (en-US) Kunan Technology covers both sides of enterprise defence: the Merak zero trust invisible network platform, and red team and penetration testing services that validate it. Section index: https://kunansec.com/en/solutions/ - [Merak invisible network platform](https://kunansec.com/en/solutions/merak/): A zero trust architecture that leaves enterprise services entirely invisible to unverified requests. Control and data planes are separated, and traffic runs encrypted point to point, never through a third-party server. - [Red team and penetration testing](https://kunansec.com/en/solutions/red-team/): An internationally certified offensive team examines the gaps across systems, people and process using real attacker techniques. Findings are converted into a prioritised, executable remediation order. ## News (en-US) Company announcements, events and awards from Kunan Technology. Section index: https://kunansec.com/en/news/ - [Kunan Technology relaunches its website](https://kunansec.com/en/news/official-website-relaunch/): The site now carries a dedicated Merak product page, a resources centre and a full English version, with every news item on its own shareable URL. — updated 2026-08-01 ## Resources (en-US) Authoritative external references on zero trust, SDP and security practice — from government agencies, standards bodies and non-profits — plus our engineering blog. Section index: https://kunansec.com/en/resources/ - [Product documentation](https://kunansec.com/en/resources/docs/): An index of Kunan Technology product documentation: the online manual and the downloadable operating manual for each product, currently the Merak zero trust network access platform. — 1 products - [Engineering blog](https://kunansec.com/en/resources/blog/): Writing from the Kunan technical team on zero trust architecture, threat analysis, deployment practice and compliance. — 10 articles - [Whitepapers](https://kunansec.com/en/resources/whitepapers/): Foundational standards, frameworks and legislation on zero trust and SDP, published by government agencies and standards bodies. — 9 references - [Case studies](https://kunansec.com/en/resources/case-studies/): Public implementation guides, adversary behaviour knowledge bases and threat intelligence sources for benchmarking your own environment. — 10 references - [Standards and specifications](https://kunansec.com/en/resources/standards/): Protocol specifications, identity guidance and testing methodologies in their authoritative form, citable directly in engineering and audit work. — 9 references - [Document downloads](https://kunansec.com/en/resources/downloads/): Download the Kunan company profile, Merak datasheet, deployment checklist, security practices statement and NDA template. — 1 documents ## Merak zero trust network access platform (en-US) Merak governs who may talk to which service, through which route. This manual is task-oriented: find the page you need by naming the job you are trying to do, rather than by guessing a menu label. Section index: https://kunansec.com/en/resources/docs/merak/ - [Getting Started](https://kunansec.com/en/resources/docs/merak/getting-started/): Signing in, activating an account, recovering a password, setting up MFA, and finding your way around the Console. — updated 2026-09-03 - [Members](https://kunansec.com/en/resources/docs/merak/members/): Managing the people who consume access — their accounts, their devices, and what they are allowed to reach. — updated 2026-09-03 - [Applications](https://kunansec.com/en/resources/docs/merak/applications/): Publishing a service through Merak: where the traffic really goes, what name members address it by, and who may reach it. — updated 2026-09-03 - [Organizations](https://kunansec.com/en/resources/docs/merak/organizations/): Grouping members and applications so access can be granted by team rather than one person at a time. — updated 2026-09-03 - [Merak Nodes](https://kunansec.com/en/resources/docs/merak/merak-nodes/): The edge routing nodes that actually carry traffic between members and services. — updated 2026-09-03 - [Approvals](https://kunansec.com/en/resources/docs/merak/approvals/): Reviewing and deciding the requests that are waiting on a human. — updated 2026-09-03 - [Logs](https://kunansec.com/en/resources/docs/merak/logs/): Two read-only records: who did what in the system, and who reached what across the network. — updated 2026-09-03 - [Administrators & Roles](https://kunansec.com/en/resources/docs/merak/administrators-and-roles/): Who may operate the Console, and exactly how much of it they may operate. — updated 2026-09-03 - [Bulk Operations](https://kunansec.com/en/resources/docs/merak/bulk-operations/): Doing the same thing to hundreds of records: exporting a list, acting on a selection, and importing from a spreadsheet. — updated 2026-09-03 - [My Account](https://kunansec.com/en/resources/docs/merak/my-account/): Your own profile, your password, your second factor, and how the Console looks and behaves for you. — updated 2026-09-03 - [Agentless Portal](https://kunansec.com/en/resources/docs/merak/agentless-portal/): The browser page a member uses to reach their services without installing anything. — updated 2026-09-03 - [Permission Reference](https://kunansec.com/en/resources/docs/merak/appendix-permissions/): Every permission key, which page it opens, and which button it reveals. — updated 2026-09-03 - [Status Reference](https://kunansec.com/en/resources/docs/merak/appendix-statuses/): Every status value in the product, what it means, and what it lets you do. — updated 2026-09-03 - [Troubleshooting](https://kunansec.com/en/resources/docs/merak/appendix-troubleshooting/): What went wrong, why, and what to do next. — updated 2026-09-03 ## Engineering blog (en-US) Section index: https://kunansec.com/en/resources/blog/ - [What SDP v3.0 Changed: SPA Is No Longer the Definition](https://kunansec.com/en/resources/blog/sdp-v3-architecture-guide/): SDP v3.0 demotes single packet authorisation from definition to option. What the new guide actually changed, why SPA struggles on IoT and cloud functions, where the line between SDP and microsegmentation really falls, and what to do first. — updated 2026-09-14 - [VPN vulnerabilities: why patching is always late](https://kunansec.com/en/resources/blog/vpn-vulnerabilities/): What CISA’s exploited-vulnerability catalogue says about VPN vulnerabilities: how many in six years, why patching starts late, and what a patch cannot undo. — updated 2026-08-22 - [Software-defined perimeter (SDP): how it works](https://kunansec.com/en/resources/blog/software-defined-perimeter/): A software-defined perimeter puts the boundary at each resource: three roles, why single packet authorisation leaves scanners no reply, and what it misses. — updated 2026-08-13 - [Attack surface inventory: what you expose publicly](https://kunansec.com/en/resources/blog/attack-surface-inventory/): What an attack surface inventory answers: how one domain name becomes a target list, the six exposed assets most inventories miss, and what to do with each item you find. — updated 2026-08-12 - [Ransomware attack chain: exposed service to encryption](https://kunansec.com/en/resources/blog/ransomware-attack-chain/): Every stage of the ransomware attack chain: how initial access happens, how it spreads, why backups do not stop extortion, and which link is cheapest to break. — updated 2026-08-12 - [Choosing a VPN replacement and planning the migration](https://kunansec.com/en/resources/blog/vpn-replacement-migration-path/): What actually decides a VPN replacement: what to inventory, how to run the parallel period, which services move first, how to verify the old endpoint is gone. — updated 2026-08-12 - [Red team versus penetration testing: how they differ](https://kunansec.com/en/resources/blog/pentest-vs-red-team/): How red team engagements and penetration testing differ in goal, scope, duration and deliverable, which one fits your situation, and where scoping goes wrong. — updated 2026-08-12 - [What zero trust architecture actually is](https://kunansec.com/en/resources/blog/what-is-zero-trust/): For the people who sign off the budget rather than build the systems: what zero trust solves, how it differs from what came before, what it is worth, and what to ask your IT team. — updated 2026-08-07 - [How the Merak zero trust network works](https://kunansec.com/en/resources/blog/how-a-zero-trust-network-works/): Plane separation, certificate identity, layered encryption, per-connection authorisation and the outbound dial — eight diagrams covering each mechanism of a zero trust network, and what each one costs you. — updated 2026-08-02 - [Comparing traditional VPN, gateway-based ZTNA and SDP](https://kunansec.com/en/resources/blog/architecture-comparison/): How the three remote access architectures differ across attack surface, data path, access granularity and deployment, with the limits of each. — updated 2026-08-01 ## Document downloads (en-US) Section index: https://kunansec.com/en/resources/downloads/ - [Merak Console operations manual](https://kunansec.com/Merak_%E6%93%8D%E4%BD%9C%E6%89%8B%E5%86%8A_v1.1.pdf): The full operating procedure — account activation, Merak Agent installation and device enrolment, member management, application and node deployment, and role and administrator permissions — with a troubleshooting appendix and a device status reference. Covers Merak Agent 1.4.2. — PDF — updated 2026-09-04 ## Optional Policy pages and machine-readable endpoints. Skip these when context is limited. ### 法律與政策 (zh-TW) - [隱私權政策](https://kunansec.com/privacy/): 說明坤安科技官方網站蒐集哪些個人資料、如何使用與保存,以及當事人可行使的權利。 — updated 2026-08-01 - [服務條款](https://kunansec.com/terms/): 坤安科技官方網站的使用規則、智慧財產權聲明與責任限制。 — updated 2026-08-01 - [資安政策](https://kunansec.com/security/): 坤安科技的資安實踐、資料保護措施與弱點通報管道(Responsible Disclosure)說明。 — updated 2026-08-01 ### 機器可讀資源 (zh-TW) - [最新消息 RSS](https://kunansec.com/rss.xml): 最新消息的訂閱來源,每則消息含標題、摘要、發布日期與永久連結。 - [XML Sitemap](https://kunansec.com/sitemap-index.xml): 給搜尋引擎的完整網址清單,包含每個頁面的多語言對應版本。 - [llms.txt](https://kunansec.com/llms.txt): 以 Markdown 條列全站頁面與摘要,供大型語言模型在不爬取整站的情況下取得結構。 - [robots.txt](https://kunansec.com/robots.txt): 爬蟲存取規則與 sitemap 位置。本站對搜尋引擎與 AI 檢索爬蟲皆為開放。 ### Legal and policies (en-US) - [Privacy Policy](https://kunansec.com/en/privacy/): How Kunan Technology collects, uses and retains personal data submitted through this website, and the rights available to data subjects. — updated 2026-08-01 - [Terms of Service](https://kunansec.com/en/terms/): Rules for using the Kunan Technology website, intellectual property notice and limitation of liability. — updated 2026-08-01 - [Security Policy](https://kunansec.com/en/security/): Kunan Technology’s security practices, data protection measures and responsible disclosure process. — updated 2026-08-01 ### Machine-readable resources (en-US) - [News RSS feed](https://kunansec.com/en/rss.xml): Subscription feed for the news section, with a title, summary, date and permalink per item. - [XML sitemap](https://kunansec.com/sitemap-index.xml): The full URL list for search engines, including the alternate language version of every page. - [llms.txt](https://kunansec.com/llms.txt): A Markdown outline of the whole site, so a language model can take in its structure without crawling every page. - [robots.txt](https://kunansec.com/robots.txt): Crawler access rules and the sitemap location. This site is open to both search and AI retrieval crawlers.