Cloud
Managed control plane and global PoP mesh. The fastest path to production for teams that want access, not infrastructure.
Choose the deployment model that matches your control, compliance, and operational requirements. Every model runs the same zero-trust architecture — you choose which planes to own.
The same separated planes, site-side enforcement, and key isolation run in every model. The difference is who operates each plane.
Managed control plane and global PoP mesh. The fastest path to production for teams that want access, not infrastructure.
Run NSD on your own infrastructure with full sovereignty over config, keys, and audit data. Air-gap and offline activation supported.
Managed control plane with self-hosted gateways and site nodes — keep data and enforcement boundaries where you need them while cutting control-plane maintenance.
You want to evaluate quickly, run a small to medium fleet, or don't want to operate infrastructure. Managed upgrades, no ops burden, and pay-as-you-go.
You need full data residency, are operating in a regulated sector, or have an air-gap requirement. You take on the ops burden in exchange for complete control.
You want the managed control plane for availability but need enforcement to happen inside your perimeter — or when you have multiple regions with different data requirements.
WireGuard private keys are generated on each device and node, stored locally, and never transmitted — regardless of deployment model.
NSN applies access control next to your workloads. Even if the control plane is unavailable, existing sessions are governed by the last-known policy at the site.
Every authorized flow produces a structured audit record: identity, device, destination, matched policy, bytes. The schema is the same in every deployment model.
Data-plane tunnels use WireGuard. The control channel between every component is mutually authenticated TLS 1.3 with short-lived certificates.
相同的分离平面、站点侧强制执行与私钥隔离在每种模式下都一样运行。区别只在于谁来运营每个平面。
托管的控制面与全球 PoP 网状网络。对于只想要访问能力、而非基础设施的团队,这是最快的上线路径。
在你自己的基础设施上运行 NSD,对配置、密钥与审计数据拥有完全主权。支持气隙(air-gap)与离线激活。
托管控制面搭配自托管的网关与站点节点——在削减控制面运维负担的同时,把数据与强制执行边界保留在你需要的位置。
你希望快速评估、运营中小规模的集群,或不想自行运维基础设施。托管升级、零运维负担,并按量付费。
你需要完整的数据驻留、身处受监管行业,或有气隙(air-gap)要求。你承担运维负担,换取完全的管控。
你希望借助托管控制面获得高可用,但需要强制执行发生在你的边界之内——或当你有多个区域、各自的数据要求不同时。
WireGuard 私钥在每台设备与节点上本地生成、本地存储,永不传输——无论采用哪种部署模式。
NSN 在你的工作负载旁执行访问控制。即使控制面不可用,现有会话仍由站点上最近一次已知的策略进行管控。
每一条被授权的流量都会生成一条结构化审计记录:身份、设备、目的地、命中的策略、字节数。该模式在每种部署模式下都相同。
数据面隧道采用 WireGuard。各组件之间的控制通道是采用短期证书的双向认证 TLS 1.3。