Zero-trust control on a SafeZoneNet-managed mesh
Natural-language ACL drafting, policy simulation, posture checks, route approval, audit tamper evidence, and BYOK / HSM encryption.
Security
Zero-trust architecture with defense in depth
Zero Trust Architecture
Every connection is verified. No implicit trust based on network location. Authenticate and authorize every request with cryptographic proofs.
- Device certificate auth
- 6-point posture (TPM 2.0 / DeviceCheck / SafetyNet)
- Least-privilege access via custom RBAC
WireGuard Encryption
Modern, fast, audited encryption. ChaCha20-Poly1305 with Curve25519 key exchange — the same primitives used by signal-grade messaging.
- ChaCha20-Poly1305 / Curve25519
- Perfect forward secrecy
- Field-level AES-256-GCM at rest
BYOK / Managed / HSM
Three encryption modes for the full enterprise spectrum. Bring your own key, let us manage them, or integrate with AWS / GCP / Azure KMS — including dual-key online rotation.
- BYOK (upload your own master key)
- AWS / GCP / Azure KMS / HSM
- Dual-key rotation without downtime
Audit & Tamper Evidence
Every audit row is HMAC-chained to its predecessor. A modified or deleted row breaks the chain — making the entire audit log forensically tamper-evident, not just append-only.
- HMAC-SHA256 hash chain integrity
- Plain-language audit queries
- SIEM integration + 365-day retention
Review Assistance
Policy, threat, audit, and compliance workflows with human approval paths
Threat Review
Rule-based anomaly scoring with LLM-driven incident explanations. Surfaces lateral movement, credential anomalies, and impossible-travel events before they spread.
- Reviewable threat context
- LLM-generated explanations
- Lateral-movement detection
Policy Drafting
Describe access intent in plain language, then validate and simulate ACL changes before rollout.
- Natural language input
- Policy simulation
- Conflict prevention
Drift Signals
Recent access patterns highlight policies worth tightening. Find unused rules and over-broad grants before they become incidents.
- Policy review suggestions
- Unused-rule detection
- Over-grant insights
Approved Response
Signals become reviewable actions so operators can approve isolation, session revocation, or policy changes with audit evidence.
- Approval queue
- Audited decisions
- Human-in-loop
Audit Query
Query network and admin events in plain English to speed investigation and evidence collection.
- Plain-language queries
- Forensic search
- Compliance reports
Infrastructure
Global, high-performance network
Global Relay Network
Multi-region relay locations help keep tenant traffic reachable when direct peer-to-peer paths are not available.
- Multi-region
- Relay-assisted reachability
- Tenant-scoped routes
SafeZoneNet-Managed Mesh
Direct WireGuard peer-to-peer when possible, managed-relay-assisted when NAT prevents it. MagicDNS for automatic name resolution; split-DNS for tenant-private zones; subnet routes and exit nodes for legacy network reachability.
- SafeZoneNet control plane + managed relay tiers
- MagicDNS · split-DNS · subnet routes · exit nodes
- Geo-routed nearest-relay selection
Data Residency
Pin your control-plane data to a region. Five regions available today with regulatory tagging for SOC 2 / GDPR / ISO 27001 / FedRAMP / C5.
- 5 regions: us-east-1, us-west-2, eu-west-1 (Ireland), eu-central-1 (Frankfurt), ap-southeast-1 (Singapore)
- Configurable async/sync replication
- GDPR Article 15 / 17 / 20 export tooling
Real-time Analytics
Deep visibility into network traffic, connection patterns, and usage trends. Make data-driven security decisions.
- Traffic analytics
- Usage trends
- Custom dashboards
Network Health Score
Composite health score derived from live connectivity, performance, relay availability, and coverage signals. See trends before issues hit users.
- Connectivity & performance
- Relay availability
- Trend visibility
Enterprise
Built for organizational scale
SSO & Identity
Enterprise identity integration with all major providers. Pre-built templates for Google Workspace, Microsoft Entra (Azure AD), and Okta; standards support for any SAML 2.0 or OIDC IdP.
- SAML 2.0 / OIDC
- Google Workspace · Azure AD · Okta presets
- Custom RBAC roles + audit chain
Sub-Organizations
Isolated workspaces within a single contract — perfect for MSPs managing multiple customers, or large enterprises separating business units. Full RLS-enforced tenant isolation, optional policy inheritance.
- Up to 5 (Pro) or unlimited (Enterprise)
- Row-level security isolation
- Optional parent-org policy inheritance
AI Compliance Reports
On-demand SOC 2, ISO 27001, HIPAA, and GDPR reports generated by the platform — drawing from your real audit chain, posture data, and access patterns. No more manual evidence-gathering.
- SOC 2 / ISO 27001 / HIPAA / GDPR
- Pulls live evidence from your tenant
- Exportable for auditor review
API, CLI & Automation
Full REST API plus a multi-platform CLI (`safezonenet up`, `peers`, `routes`, `netcheck`). Webhook events stream into Slack, Teams, PagerDuty, Datadog, Splunk, or any custom endpoint.
- REST API + OpenAPI contract
- CLI for Win / Mac / Linux
- Slack · Teams · webhook · PagerDuty · Datadog · Splunk
Guided Onboarding
Enroll devices with tenant-scoped join tokens and guided setup for managed mesh access.
- Guided setup
- Device enrollment
- Join tokens
Security Center
Centralized security management with API key rotation, MFA enforcement, and device trust policies. Full control over your security posture.
- API key management
- MFA enforcement
- Device trust
Billing & Usage
Transparent usage-based billing with detailed breakdowns. Export invoices, manage subscriptions, and track costs.
- Usage tracking
- Invoice exports
- Cost analytics
Ready to get started?
Start with mesh access, ACLs, DNS, and audit history. No credit card required.
Start Free