Solutions

For security teams

Deny by default, grant by identity, log everything. The posture your auditors keep asking about.

Deny-by-default, before the kickoff meeting

A fresh tailnet can reach nothing — every capability is a grant you write down, review, and version. That's least privilege as the starting state, not a maturity-roadmap line item for next fiscal year.

  • ✓Policies reference users, groups, tags — never IPs
  • ✓Every rule change tracked in git like code
  • ✓Effective access for any principal, queryable in seconds
policy — effective grants
group:sre→ prod:22,443 · check-in3 rulesGRANTED
group:eng→ staging:* · 8h ttl2 rulesGRANTED
group:contractors→ expired 2026-01-310 rulesLAPSED
everyone else→ no grantsdenyDEFAULT

Evidence as a byproduct of work

"Show us the session" stops being a scramble: SSH and terminal sessions are recorded for replay, every network flow lands in the audit log, and offboarding takes seconds. The evidence the audit demands is generated while the work happens — not reconstructed afterwards.

audit — this week
mei@corpssh db-prod-02 · 41 minreplay ✓RECORDED
sam@corppolicy change · PR #77git ✓TRACKED
raj@contractoroffboarded · 0 live sessions0.8 sREVOKED

Controls you get on day one

🚫

Deny by default

A fresh tailnet reaches nothing until rules grant it. Least privilege is the starting state, not a project.

🪪

Identity-based rules

ACLs reference users, groups, and tags from your IdP — policies survive IP changes and cloud redeploys.

🎥

Session recording

SSH and terminal sessions captured for replay — evidence generated as a byproduct of work.

Privileged access →
📜

Network audit log

Every flow visible in the console; stream to Splunk, Datadog, or S3 for retention and alerting.

🔑

Device trust

Keys live on devices, never shared; revoke any device in seconds. MFA enforced at the IdP.

📉

Shrinking attack surface

No public ingress, no bastions, no split-tunnel loopholes — the internet stops seeing your infrastructure.

Answers for the audit

QuestionWith OpenVLAN
Who could reach prod DBs last quarter?ACL history + audit log export
Show us evidence of the sessionRecorded replay (asciinema)
How fast is offboarding?Seconds, via SCIM
Where does traffic terminate?End-to-end on your devices; coordinator never sees payload
Who changed network policy and when?Config-as-code history (Git + Terraform)

Compliance postures supported

SOC 2 alignment

Access controls, logging, and change management map cleanly to the criteria.

Compliance →

Zero Trust initiatives

Identity + device + least privilege + logging — the practical version of the whitepaper.

Zero Trust →

Responsible disclosure

Report findings through the Trust Center; credited disclosures welcome.

Security page →

Security team FAQs

Can we see the cryptography and architecture?
The protocol is AmneziaWG — 4,000 auditable lines, formally verified. The architecture, threat model, and third-party pen test summaries are in the Trust Center, no NDA required for the summaries.
What does the coordination server actually see?
Identity, device public keys, and routing metadata — never packet payloads. Data flows device-to-device, end-to-end encrypted; the coordinator is the phone book, not the wire.
How do you handle a compromised laptop?
Revoke the device from the console: its keys die, sessions drop, and the audit trail shows everything it touched. Blast radius ends at that device's grants — credentials aren't shared.
Can we require managed devices only?
Yes — device posture checks gate the tunnel itself. Unmanaged devices can be blocked entirely or limited to browser-based funnel access, per policy.
Does this help with PCI / HIPAA scope?
Teams use it to collapse network segmentation spreadsheets into enforced ACLs — flat per-source-destination rules with logs. Whether it reduces scope depends on your assessor, but the evidence package generally makes those conversations shorter.

Demo it to your auditors

Security review in an afternoon: export ACLs, walk the logs, replay a session.