Unified private access and secure connectivity

Reach what matters.
Not the whole network.

NetSeed brings private device and service access, authorized company internet exit, and protected public ingress into one platform—without opening the whole network.

  • Nodes
  • Private services
  • Internet exit
  • Public ingress
NetSeedConnected
Current organization & networkNorthwindProduction
Office nodestudio-mac
Online
Private serviceinventory-api · 443
Available
Internet exitCompany HQ
Access GrantEngineering → inventory-api
Active pathWG / WSS · automatic

Made for the way work actually happens

One access platform. Many real-world scenarios.

Here are six featured examples—not an exhaustive list. Each path stays inside the right Organization, Network, identity, and policy boundary.

Explore all scenarios
Enterprise VPN / Internet Exit

Travel through an exit your company controls.

Select an authorized NSGW in the current Space for the IPv4 default route or approved IPv4 CIDRs. IPv6 is not routed through NSGW and is fail-closed by default.

Explore enterprise exit
ARemote laptopNetSeed App
Encrypted path
GCompany HQApproved NSGW
Company egress
InternetIPv4 policy applied
  • Route scopeIPv4 default / CIDRs
  • TransportWG / WSS · automatic
  • SafetyFail-closed · IPv6 not via NSGW

Enterprise VPN / Internet Exit

Your internet exit, under your rules.

An Exit is selected by the user, authorized by policy, and scoped to the active Space. Send the IPv4 default route or approved IPv4 CIDRs through your own NSGW; IPv6 is not routed through it.

01
Chosen, never assumed

The Exit switch stays off until the user selects an authorized gateway.

02
Automatic path selection

WireGuard and secure WebSocket paths are selected automatically as network conditions change.

03
No silent bypass

If the Grant is revoked or transport is lost, captured traffic fails closed.

Internet exitRoute through your company
On
Active SpaceNorthwind / ProductionAuthorized
Company HQNSGW · Default route
Partner networkNSGW · Approved CIDRs
Available
Remote deviceWG / WSS · AutoCompany HQInternet

Fail-closed guardrailAuthorization and transport are continuously required.

Cross-account sharing, two scopes

Share a Node—or only one Service.

Explicit Grants shape cross-account access. Same-account members keep system access to their own Nodes and private Services. Visibility, online state, authorization, and reachability remain separate signals.

L3Grant active

Node access

Directional cross-account whole-node access for SSH, administration, or protocols the destination host already controls.

SourceEngineeringDestinationbuild-server
Host firewall remains final
L4Grant active

Private Service access

A narrower path to an explicitly declared protocol, host, and port—without exposing the rest of the Node.

TCPdb.internal5432
VisibleOnlineGrantedReachable

Gateway & Public Ingress

One gateway. Each role proves its own readiness.

Being online is only the beginning. NSGW reports Relay, Service Egress, Internet Exit, and Public Ingress readiness independently—so operators know which job is actually ready.

G
hk-edge-01NSGW · Company managed
Online
R

RelayReady

S

Service egressReady

E

Internet exitReady

P

Public ingressConfiguration needed

!

Online does not mean every role is ready.

L7 web applicationProtected
portal.example.com
VisitorOIDC + GrantPrivate app
Identity-aware options include OIDC, API Key, Basic, mTLS, Signed URL, or explicitly anonymous access.
Public TCP / UDPSource policy
git-ssh.example.com:22
Source IPAllow / denyEndpoint
Public TCP and UDP use source-IP policy, not user identity or L7 authentication.

One product, distinct surfaces

The right surface for every job.

People connect in the App. Administrators shape access in NSD. Servers and automation use ns and the API.

A
For people

NetSeed App

Use the active Space to connect, then consume authorized Nodes, private Services, and an Exit.

Northwind / ProductionConnected
Nodeoffice-nasOnline
Serviceinventory-apiAvailable
ExitCompany HQSelected
N
For administrators

NSD Console

Manage Organizations, Networks, resources, Gateways, ingress, and directional Access Grants.

Northwind/Production
Nodes24Services11Gateways3
Engineeringcan accessinventory-api
›_
For servers & automation

ns CLI & API

Connect servers, inspect machine-readable state, and integrate operational workflows through supported interfaces.

$ ns info$ ns status --json$ ns space listAPI tokens · Webhooks · JSON output

Trust & control

Clear boundaries you can explain.

NetSeed makes the identity, direction, scope, and state of an access path visible—without turning every user into a network operator.

Explore the architecture
01

Local device identity

Browser authorization creates or restores the device identity used by that App or ns profile.

02

Explicit cross-account sharing

Directional Grants define who can reach which Node or Service across accounts. Each account keeps built-in access to its own Nodes and private Services.

03

Observable changes

Activity events expose administrative changes and important state transitions for review.

Built for the devices your team already uses

Start where you work.

  • macOS
  • Windows
  • Linux
  • iOS
  • Android
Your network, one clear next step

Choose how you want to begin.

Install NetSeed to connect, open NSD to manage an existing Space, or talk with us about a team rollout.