Unified private access and secure connectivity
Reach what matters.
Not the whole network.
NetSeed brings private device and service access, authorized company internet exit, and protected public ingress into one platform—without opening the whole network.
- Nodes
- Private services
- Internet exit
- Public ingress
Made for the way work actually happens
One access platform. Many real-world scenarios.
Here are six featured examples—not an exhaustive list. Each path stays inside the right Organization, Network, identity, and policy boundary.
Explore all scenariosTravel through an exit your company controls.
Select an authorized NSGW in the current Space for the IPv4 default route or approved IPv4 CIDRs. IPv6 is not routed through NSGW and is fail-closed by default.
Explore enterprise exit- Route scopeIPv4 default / CIDRs
- TransportWG / WSS · automatic
- SafetyFail-closed · IPv6 not via NSGW
Your office computer, NAS, or server—without opening the office LAN.
Use a directional L3 Grant when access crosses account boundaries. Same-account access to its own Nodes and private Services remains built in, and the destination firewall keeps final say.
Explore remote access- Access scopeOne Node · whole-host L3
- Cross-accountDirectional Grant
- Final boundaryDestination host firewall
Open the database, API, or dashboard—not its whole host.
Declare the protocol, host, and port as a private Service, then share it across accounts with only the users, groups, or source Nodes that need it.
Explore private services- DeclarationProtocol · host · port
- Cross-account subjectsUsers · groups · source Nodes
- ExposureOnly the declared Service
Give distributed environments one controlled way to meet.
Connect Nodes and declared Services across offices, clouds, and data centers while keeping each access path explicit.
Explore hybrid connectivity- EnvironmentsOffice · cloud · IDC
- ResourcesNodes + declared Services
- BoundaryExplicit paths in one Space
Publish an application with authentication in front.
Place identity-aware L7 protection in front of a web application, or use source-IP policy for public TCP and UDP endpoints.
Explore public ingress- Public L7Auth mode + compatible Grant
- Optional narrowingSource-IP policy
- Public L4Source-IP control only
Give automation or a partner only the path it needs.
For public L7 access, pair workload identity with an enabled compatible Consumer Grant. For cross-account sharing, scope a Grant from selected people, groups, or source Nodes to the approved Node or private Service—without sharing a flat network credential.
Explore workload access- IdentityWorkload credential
- AuthorizationConsumer Grant · enabled
- ReachPublished public L7 only
Enterprise VPN / Internet Exit
Your internet exit, under your rules.
An Exit is selected by the user, authorized by policy, and scoped to the active Space. Send the IPv4 default route or approved IPv4 CIDRs through your own NSGW; IPv6 is not routed through it.
The Exit switch stays off until the user selects an authorized gateway.
WireGuard and secure WebSocket paths are selected automatically as network conditions change.
If the Grant is revoked or transport is lost, captured traffic fails closed.
Fail-closed guardrailAuthorization and transport are continuously required.
Cross-account sharing, two scopes
Share a Node—or only one Service.
Explicit Grants shape cross-account access. Same-account members keep system access to their own Nodes and private Services. Visibility, online state, authorization, and reachability remain separate signals.
Node access
Directional cross-account whole-node access for SSH, administration, or protocols the destination host already controls.
Private Service access
A narrower path to an explicitly declared protocol, host, and port—without exposing the rest of the Node.
Gateway & Public Ingress
One gateway. Each role proves its own readiness.
Being online is only the beginning. NSGW reports Relay, Service Egress, Internet Exit, and Public Ingress readiness independently—so operators know which job is actually ready.
RelayReady
✓Service egressReady
✓Internet exitReady
✓Public ingressConfiguration needed
!Online does not mean every role is ready.
One product, distinct surfaces
The right surface for every job.
People connect in the App. Administrators shape access in NSD. Servers and automation use ns and the API.
NetSeed App
Use the active Space to connect, then consume authorized Nodes, private Services, and an Exit.
NSD Console
Manage Organizations, Networks, resources, Gateways, ingress, and directional Access Grants.
ns CLI & API
Connect servers, inspect machine-readable state, and integrate operational workflows through supported interfaces.
Trust & control
Clear boundaries you can explain.
NetSeed makes the identity, direction, scope, and state of an access path visible—without turning every user into a network operator.
Explore the architectureLocal device identity
Browser authorization creates or restores the device identity used by that App or ns profile.
Explicit cross-account sharing
Directional Grants define who can reach which Node or Service across accounts. Each account keeps built-in access to its own Nodes and private Services.
Observable changes
Activity events expose administrative changes and important state transitions for review.
Built for the devices your team already uses
Start where you work.
- ⌘macOS
- ⊞Windows
- ◆Linux
- ●iOS
- ▲Android
Choose how you want to begin.
Install NetSeed to connect, open NSD to manage an existing Space, or talk with us about a team rollout.