Platform

Zero trust that fits in one afternoon

Identity-based, least-privilege access to every resource — enforced on every connection, on every device, with nothing implied and everything logged.

Concentric trust rings with one verification gate and one authorized path

Identity is the new perimeter

Network location stopped meaning safety years ago. In OpenVLAN, users authenticate through your SSO and every device gets its own short-lived identity — so access decisions are made about a person on a specific machine, not about an IP address that could be anyone behind the router.

connect — identity check
mei@corpMacBook · posture compliantsso ✓CONNECT
sam@corppersonal phone · unmanagedsso ✓RESTRICTED
ci-botworkload identity · scope:deploycert ✓CONNECT
ex-employeedisabled in IdP—DENIED
Access follows the person — offboarding is instant and complete.

Deny by default, grant explicitly

No rule means no access — there is no implicit trust anywhere in the mesh. ACLs read like sentences your auditors can parse without a consultant: who, from which device, may reach which resource, on which port. Every change lands in version control with a reviewer's name attached.

acl — evaluation
engineers+ corp-laptop → ssh prodrule 12ALLOW
support→ ssh prodno ruleDENY
finance→ billing-db:5432rule 31ALLOW
anyone→ ai:unsanctionedrule 44LOG
Default deny everywhere — grants are explicit, reviewed, and versioned.

Zero trust in three moves

You don't rip out the network on day one. You move the fence, then the keys, then the rules.

Move identity to the front

Users log in with the SSO you already run. Every device gets a short-lived identity — not a shared secret that outlives employment.

Shrink the perimeter to each resource

Firewalls stop being the only lock. Each host, database, and cluster checks the caller's identity and device posture itself.

Default to deny, grant explicitly

ACLs read like sentences: "engineers on company laptops may SSH to production, everyone else may not." Nothing is implied.

Every control, in one place

The pieces vendors usually sell separately — identity, policy, audit — arrive together.

SSO everywhere

Okta, Entra, Google, or any OIDC provider. One login session governs every resource.

Device identity

Every machine gets its own node identity and keypair — laptops, servers, CI runners alike.

Short-lived keys

Credentials rotate on a short clock. Stolen material ages out in minutes, not quarters.

Device posture checks

Unmanaged or non-compliant devices connect into a restricted scope, or not at all.

Default deny

No rule, no access. Nothing is implied by network position anywhere in the mesh.

Human-readable ACLs

Rules read like sentences — auditors parse them without a consultant in the room.

Policy in git

Every change is a reviewed pull request. Roll back any rule and see who approved it.

Per-resource granularity

Scope by user, group, tag, port, or protocol — down to a single database login.

Who connected

Every session maps to a person and a device. Anonymous service access is opt-in only.

What they touched

Destination, port, duration, and bytes for each session — exportable as JSON or CSV.

Policy change log

Who changed which rule, when, and with whose approval — recorded automatically.

SIEM streaming

Ship access and policy events to Datadog, Splunk, or any webhook endpoint.

Questions and answers

Do we need to replace our existing security tools?
No. OpenVLAN slots in beside your EDR, SIEM, and MDM — it handles the network trust layer they don't. Most teams keep everything and simply stop managing firewall rules for remote access.
Is this just a VPN with marketing?
The tunnel is the plumbing; the trust model is the difference. No implicit access by network position, per-resource identity checks, default-deny policy in version control, and audit trails that name people — none of which a perimeter VPN does.
How long until we're actually zero trust?
Meaningful controls land the first afternoon: SSO on, one ACL file, default deny. Full least-privilege granularity across every resource is iterative — most teams tighten for a quarter as access patterns surface.
What happens if the identity provider goes down?
Existing sessions keep working on their current credentials and re-check on a schedule, not per packet. New logins queue until the provider returns — fail closed, never open.
Can we enforce MFA per resource?
Yes — step-up prompts attach to ACL rules. Day-to-day work needs one login; production databases can demand a fresh challenge at connect time.
How do contractors and partners fit in?
Scoped identities with email auth and expiry dates. They see exactly what a policy names — one service, one window — and everything they do lands in the same audit trail.
Does zero trust slow the network down?
No. Identity is proven at connect time; packets then flow on direct AmneziaWG paths at line speed. There's no proxy in the middle inspecting every byte.

Trust nothing. Access everything you should.

Turn on SSO, write one ACL file, and watch implicit access disappear.