ZERO TRUST ACCESS PLATFORM

Access without a perimeter.

NetSeed connects users, agents, and services through a zero-trust overlay — separated control and data planes, policy enforced at the edge, and private keys that never leave the node. Supports access via peer-to-peer tunnel or clientless browser.

Architecture Control / Gateway / Data split
Security Keys stay on-node, policy executes at the edge
Deployment SaaS / Self-hosted / Hybrid

Built for remote access, engineering, Kubernetes, databases, and AI workloads.

Developer Access Private Infrastructure Hybrid Network AI Workloads Compliance Ready
The problem

Legacy VPNs trust the network. NetSeed trusts no one.

A flat tunnel is an implicit grant: one credential opens every reachable host, keys get copied across devices, and the audit log can't tell you what was actually touched. NetSeed replaces the perimeter with per-flow, per-identity access.

01

Flat network trust

Once a legacy VPN session is up, the whole subnet is reachable. NetSeed grants access per service, per identity — lateral movement has nowhere to go.

02

Shared, unrotated secrets

Appliance VPNs ship keys around in config files. NetSeed generates keys on each node and device, never transmits them, and rotates session certificates automatically.

03

Audit logs without answers

Connection logs say someone connected — not what they reached. NetSeed emits a structured record per flow: identity, device, destination, matched policy, bytes.

Integrations

Integrates with the systems you already trust.

Connect identity providers, device trust signals, and security event pipelines to NetSeed without rebuilding your existing operational model.

Identity providers

OIDC / SSO

Connect OIDC-compatible identity providers to centralize authentication and map group-based policy into NetSeed.

Identity provisioning

Directory & group sync

Sync users, groups, and access assignments through directory or provisioning workflows to keep access boundaries current.

Device trust

Posture inputs

Use device trust and posture signals as conditions in your access model — restrict flows to managed or compliant endpoints.

Security events

Streaming / SIEM

Export per-flow audit records to HTTP endpoints, object storage, or SIEM pipelines without installing proprietary agents.

API & automation

IaC-ready

Automate user onboarding, service publishing, and policy management through a programmable control surface.

View all integrations
Architecture

Control, gateway, and site — separated by design.

No single component owns the full access context. The control plane coordinates but never carries traffic; the gateway decides at ingress; the site keeps the final say. Failures stay isolated, and audits stay clean.

Control plane

Coordinates, never carries

NSD handles org, identity, config, and policy coordination without touching production traffic — or your keys.

Gateway plane

Access decided at the edge

Client traffic reaches NSGW first; policy is enforced at ingress instead of opening the entire network.

Site plane

The site keeps real control

NSN proxies and restricts access next to workloads, so keys and resource boundaries remain on the site side.

NSC work laptop / user agent
Browser clientless · example.web.com
NSGW ingress auth / gateway enforcement
NSN private NAS / database / workloads
client or browser → gateway → private site
Why NetSeed

Honest defaults, not marketing.

01

Keys never leave the node

NSD coordinates trust without ever holding private material. WireGuard keys are generated and stay at the edge.

02

Multi-NSD by default

Run multiple coordinating NSDs across regions. Control-plane availability is not a single-tenant concern.

03

.ns names + VIPs without root

Userspace name resolution and virtual IPs. No kernel modules, no system rewires, no privileged install dance.

04

Managed relay, off by default

Managed PoPs relay encrypted traffic only. Termination is opt-in, per-tunnel, and clearly logged.

05

ACL terminates at the site

Site nodes have the final say on what reaches your workloads — even if control-plane policy lags or is contested.

06

Open clients, open metrics

Clients are open-source where it counts. Prometheus-shaped telemetry; no proprietary observability tax.

Access scenarios

Built for users, workloads, and private services.

NetSeed gives developers, agents, CI jobs, and internal applications scoped access paths instead of flat network exposure.

PEOPLE

Developer & team access

Give engineers, operators, and remote workers scoped access to internal services and environments — no flat-tunnel VPN, no shared credential bundles.

+.ns service names · local VIP resolution
+Identity-bound sessions · user-level least privilege
+Per-flow audit record per connection
WORKLOADS

Agent & CI access

Issue scoped identities to AI agents, CI jobs, and automation pipelines so they reach only what they need — and the access path is audited and revocable.

+Workload identity · no shared secrets
+Service-level boundary between model gateways and data
+Revocation without network reconfiguration
PRIVATE SERVICES

Internal application access

Publish internal services over a controlled ingress path — browser, API, or client access to back-office apps and restricted APIs without exposing the surrounding subnet.

+NSGW controlled ingress · NSN site-side decision
+Publish the service path, not the network
+Fits internal platforms, back-office, restricted APIs
Deployment

Your infra, your rules.

Every model runs the same architecture — you choose which planes to own.

SAAS

NetSeed Cloud

Managed control plane and global PoP mesh. The fastest path to production for teams that want access, not infrastructure.

+Managed NSD · global PoPs
+Pay-as-you-go
for fast-moving teams
SELF-HOSTED

Self-hosted

Run NSD on your own infrastructure with full sovereignty over config, keys, and audit data. Air-gap supported.

+Full data residency · air-gap
+BYO observability
for regulated workloads
HYBRID

Hybrid

Managed control plane with self-hosted gateways and site nodes — keep data boundaries while cutting maintenance.

+Managed NSD, your gateways
+Per-region residency policies
for global enterprises
Quickstart

Production-ready in under five minutes.

Install the client, authenticate, register a site node — the access path comes online by itself. Keys are generated locally and never uploaded.

quickstart / secure bootstrap
FAQ

Common questions, answered directly.

How is NetSeed different from a mesh VPN?

Mesh VPNs collapse identity, policy, and forwarding into one plane. NetSeed splits them: NSD owns control, NSGW owns transport, NSN owns enforcement. Failures stay isolated; audits stay clean.

Where does my traffic actually flow?

Direct and peer-to-peer when reachable; otherwise through a managed relay that forwards encrypted packets without inspecting them. Termination at a PoP is opt-in and visibly logged.

Is NetSeed open source?

Clients and data-plane reference implementations are open. NSD is open-core: a fully featured self-hosted edition plus a managed Cloud edition.

What about data residency?

Self-hosted keeps everything inside your boundary. Hybrid pins data-plane and audit storage to chosen regions. Cloud offers EU and US residency tiers.

Can I run this air-gapped?

Yes. The self-hosted distribution runs without outbound internet, with offline license activation and signed update bundles.

How do I evaluate it?

The free tier is the full product at small scale. Procurement-grade trials run through sales, with architecture deep-dives and a security questionnaire.

Get started

Start building on NetSeed.

Free tier available. No credit card required. Deploy your first site node in under five minutes.