Deny by default, grant by identity, log everything. The posture your auditors keep asking about.
A fresh tailnet can reach nothing — every capability is a grant you write down, review, and version. That's least privilege as the starting state, not a maturity-roadmap line item for next fiscal year.
"Show us the session" stops being a scramble: SSH and terminal sessions are recorded for replay, every network flow lands in the audit log, and offboarding takes seconds. The evidence the audit demands is generated while the work happens — not reconstructed afterwards.
A fresh tailnet reaches nothing until rules grant it. Least privilege is the starting state, not a project.
ACLs reference users, groups, and tags from your IdP — policies survive IP changes and cloud redeploys.
SSH and terminal sessions captured for replay — evidence generated as a byproduct of work.
Privileged access →Every flow visible in the console; stream to Splunk, Datadog, or S3 for retention and alerting.
Keys live on devices, never shared; revoke any device in seconds. MFA enforced at the IdP.
No public ingress, no bastions, no split-tunnel loopholes — the internet stops seeing your infrastructure.
| Question | With OpenVLAN |
|---|---|
| Who could reach prod DBs last quarter? | ACL history + audit log export |
| Show us evidence of the session | Recorded replay (asciinema) |
| How fast is offboarding? | Seconds, via SCIM |
| Where does traffic terminate? | End-to-end on your devices; coordinator never sees payload |
| Who changed network policy and when? | Config-as-code history (Git + Terraform) |
Access controls, logging, and change management map cleanly to the criteria.
Compliance →Identity + device + least privilege + logging — the practical version of the whitepaper.
Zero Trust →Report findings through the Trust Center; credited disclosures welcome.
Security page →Security review in an afternoon: export ACLs, walk the logs, replay a session.