Features

Zero-trust control on a SafeZoneNet-managed mesh

Natural-language ACL drafting, policy simulation, posture checks, route approval, audit tamper evidence, and BYOK / HSM encryption.

Security

Zero-trust architecture with defense in depth

Zero Trust Architecture

Every connection is verified. No implicit trust based on network location. Authenticate and authorize every request with cryptographic proofs.

  • Device certificate auth
  • 6-point posture (TPM 2.0 / DeviceCheck / SafetyNet)
  • Least-privilege access via custom RBAC

WireGuard Encryption

Modern, fast, audited encryption. ChaCha20-Poly1305 with Curve25519 key exchange — the same primitives used by signal-grade messaging.

  • ChaCha20-Poly1305 / Curve25519
  • Perfect forward secrecy
  • Field-level AES-256-GCM at rest

BYOK / Managed / HSM

Three encryption modes for the full enterprise spectrum. Bring your own key, let us manage them, or integrate with AWS / GCP / Azure KMS — including dual-key online rotation.

  • BYOK (upload your own master key)
  • AWS / GCP / Azure KMS / HSM
  • Dual-key rotation without downtime

Audit & Tamper Evidence

Every audit row is HMAC-chained to its predecessor. A modified or deleted row breaks the chain — making the entire audit log forensically tamper-evident, not just append-only.

  • HMAC-SHA256 hash chain integrity
  • Plain-language audit queries
  • SIEM integration + 365-day retention

Review Assistance

Policy, threat, audit, and compliance workflows with human approval paths

Threat Review

Rule-based anomaly scoring with LLM-driven incident explanations. Surfaces lateral movement, credential anomalies, and impossible-travel events before they spread.

  • Reviewable threat context
  • LLM-generated explanations
  • Lateral-movement detection

Policy Drafting

Describe access intent in plain language, then validate and simulate ACL changes before rollout.

  • Natural language input
  • Policy simulation
  • Conflict prevention

Drift Signals

Recent access patterns highlight policies worth tightening. Find unused rules and over-broad grants before they become incidents.

  • Policy review suggestions
  • Unused-rule detection
  • Over-grant insights

Approved Response

Signals become reviewable actions so operators can approve isolation, session revocation, or policy changes with audit evidence.

  • Approval queue
  • Audited decisions
  • Human-in-loop

Audit Query

Query network and admin events in plain English to speed investigation and evidence collection.

  • Plain-language queries
  • Forensic search
  • Compliance reports

Infrastructure

Global, high-performance network

Global Relay Network

Multi-region relay locations help keep tenant traffic reachable when direct peer-to-peer paths are not available.

  • Multi-region
  • Relay-assisted reachability
  • Tenant-scoped routes

SafeZoneNet-Managed Mesh

Direct WireGuard peer-to-peer when possible, managed-relay-assisted when NAT prevents it. MagicDNS for automatic name resolution; split-DNS for tenant-private zones; subnet routes and exit nodes for legacy network reachability.

  • SafeZoneNet control plane + managed relay tiers
  • MagicDNS · split-DNS · subnet routes · exit nodes
  • Geo-routed nearest-relay selection

Data Residency

Pin your control-plane data to a region. Five regions available today with regulatory tagging for SOC 2 / GDPR / ISO 27001 / FedRAMP / C5.

  • 5 regions: us-east-1, us-west-2, eu-west-1 (Ireland), eu-central-1 (Frankfurt), ap-southeast-1 (Singapore)
  • Configurable async/sync replication
  • GDPR Article 15 / 17 / 20 export tooling

Real-time Analytics

Deep visibility into network traffic, connection patterns, and usage trends. Make data-driven security decisions.

  • Traffic analytics
  • Usage trends
  • Custom dashboards

Network Health Score

Composite health score derived from live connectivity, performance, relay availability, and coverage signals. See trends before issues hit users.

  • Connectivity & performance
  • Relay availability
  • Trend visibility

Enterprise

Built for organizational scale

SSO & Identity

Enterprise identity integration with all major providers. Pre-built templates for Google Workspace, Microsoft Entra (Azure AD), and Okta; standards support for any SAML 2.0 or OIDC IdP.

  • SAML 2.0 / OIDC
  • Google Workspace · Azure AD · Okta presets
  • Custom RBAC roles + audit chain

Sub-Organizations

Isolated workspaces within a single contract — perfect for MSPs managing multiple customers, or large enterprises separating business units. Full RLS-enforced tenant isolation, optional policy inheritance.

  • Up to 5 (Pro) or unlimited (Enterprise)
  • Row-level security isolation
  • Optional parent-org policy inheritance

AI Compliance Reports

On-demand SOC 2, ISO 27001, HIPAA, and GDPR reports generated by the platform — drawing from your real audit chain, posture data, and access patterns. No more manual evidence-gathering.

  • SOC 2 / ISO 27001 / HIPAA / GDPR
  • Pulls live evidence from your tenant
  • Exportable for auditor review

API, CLI & Automation

Full REST API plus a multi-platform CLI (`safezonenet up`, `peers`, `routes`, `netcheck`). Webhook events stream into Slack, Teams, PagerDuty, Datadog, Splunk, or any custom endpoint.

  • REST API + OpenAPI contract
  • CLI for Win / Mac / Linux
  • Slack · Teams · webhook · PagerDuty · Datadog · Splunk

Guided Onboarding

Enroll devices with tenant-scoped join tokens and guided setup for managed mesh access.

  • Guided setup
  • Device enrollment
  • Join tokens

Security Center

Centralized security management with API key rotation, MFA enforcement, and device trust policies. Full control over your security posture.

  • API key management
  • MFA enforcement
  • Device trust

Billing & Usage

Transparent usage-based billing with detailed breakdowns. Export invoices, manage subscriptions, and track costs.

  • Usage tracking
  • Invoice exports
  • Cost analytics

Ready to get started?

Start with mesh access, ACLs, DNS, and audit history. No credit card required.

Start Free