Product overview

One access model, from a phone to a private service.

People connect with the NetSeed App, servers and automation use ns, administrators manage access in NSD, and NSGW provides the gateway roles a Network needs. Everything is scoped to one active Organization and Network Space.

App + nsOrganization + NetworkNodes + Services + Exit
Four product surfaces

Use the surface that matches the job.

The same names and access decisions carry across the App, terminal, console and gateway.

Connect

NetSeed App

People sign in, select a Space, view authorized Nodes and Services, choose an Exit and connect from iPhone, Android, macOS or Windows.

Download the App →
Terminal

ns

Servers and terminal users join a Network, inspect status, expose a Node or declared Service, and support repeatable automation.

Open CLI reference →
Manage

NSD

Administrators manage Organizations, Networks, members, resources, Grants, gateway configuration, public ingress and activity.

Open NSD →
Gateway

NSGW

A gateway reports Relay, Service Egress, Internet Exit and Public Ingress readiness separately. Online does not mean every role is ready.

Read the NSGW guide →
Organization + Network = Space

One clear context for every connection.

An Organization contains people and administrative ownership. A Network contains the Nodes, Services, gateways and access rules they use together. Their selected pair is the active Space.

Organization

Who owns and administers the environment.

Network

Which resources and access configuration are in view.

Space

The active Organization and Network pair used by the App or ns.

Switching

Changing Space stops the current runtime, commits the newly selected context, and remains disconnected until the user explicitly connects; two Spaces are not active at once.

Choose the access scope

A whole Node, one Service, or an approved Exit.

Each choice solves a different problem. Authorization is explicit and always belongs to the active Space.

L3 Node

Share an authorized machine

Cross-account sharing uses a directional Grant for the whole Node. Same-account access to its own resources remains system-managed, and the destination firewall stays final.

Explore Node access →
L4 Service

Share one declared endpoint

Cross-account sharing can select users, groups, or source Nodes for an exact protocol, host and port instead of the complete Node.

Explore Service access →
Internet Exit

Use a company-operated IPv4 route

Select an authorized Exit for the IPv4 default route or configured IPv4 CIDRs, with automatic usable WG/WSS transport selection and fail-closed behavior. IPv6 is not routed through NSGW.

Explore company Exit →
Clear boundaries

Management decides what is allowed. The chosen path carries the connection.

NSD handles sign-in, Organization and Network state, resource metadata and Grants. The App or ns then connects within that active context, using an NSGW role where the selected path requires one.

Private access

Cross-account sharing uses explicit Grants; same-account access to its own Nodes and private Services remains system-managed. Current availability still applies.

Gateway readiness

Relay, Service Egress, Internet Exit and Public Ingress are independent capabilities, not one combined status.

Protected public L7

Every L7 path pairs its authentication or explicit anonymous mode with a compatible Grant; source-IP rules can add a narrower boundary.

Public TCP / UDP

Public L4 ingress uses source-IP allow and deny rules; it does not inherit identity-aware L7 authentication.

Next step

Start with the path your team needs today.

Install NetSeed to connect, or open the complete guide for setup, access models and operational details.