Pillar one

Encrypted access between known devices and known applications.

The agent connects an authenticated user on an attested device to the resource they were granted, and only that resource. There are no flat networks behind it and no standing routes that outlive the session.

The shortest path from a user to a resource is the only path the platform builds.

In depth

What the access layer actually does.

Each connection is point-to-point and short-lived, scoped by policy, and recorded by the audit chain. The user experience stays familiar; the operational guarantees are very different.

Per-application path

Each session terminates between the device and the resource. There is no implicit network access surface.

Always-on connectivity

Connections survive sleep, network roaming, and silent re-authentication so end users do not learn to bypass them.

Native cross-platform agents

First-class clients for Windows, macOS, and Linux. Installed via your MDM with the rest of the corporate baseline.

Always-on RA-VPN

The agent restores its session after reboot using the operating system's keychain. The user does not see a re-authentication prompt.

Per-application policy

Access is scoped to a named service. The user never sees a resource that policy did not list.

Split-tunnelling by policy

Routes are chosen by platform decision, not by user preference, and the decision is logged.

Protocol-aware forwarding

TCP, SSH, and HTTP handlers built in. SOCKS5 is available for application-level routing.

Mesh-aware routing

Direct device-to-device connections where the network allows; relay-mediated paths when it does not.

The platform is the same in either deployment shape. The walk-through is thirty minutes.