Security Operations

Turn access into operational control.

Turn access decisions, service exposure, and audit events into operational controls.

Overview

Access decisions that security teams can reason about.

NetSeed turns identity, service boundaries, and audit events into operational controls that security and platform teams can reason about — without replacing your existing monitoring or SIEM stack.

IDENTITY

Identity-Based Access

Bind access decisions to identity, policy, and service scope instead of static network trust. Who a user is determines what they can reach — not which IP range they connect from.

DEVICE

Device Trust

Use device trust conditions to narrow access to managed and approved endpoints. An unmanaged device with valid credentials is a different access tier from the same identity on a compliant device.

BOUNDARY

Service-Level Boundaries

Expose only the service path that is needed, not the surrounding subnet. Lateral movement within a site requires a separate, explicit policy decision — not just network proximity.

Audit & Event Export

Stream access and policy events into your monitoring, SIEM, or internal security workflows. Every authorized flow produces a structured per-flow audit record at the site — identity, device, destination, matched policy, duration, and bytes transferred.

+Per-flow structured records — not connection logs
+HTTP endpoint delivery to any collector
+Object storage export for long-term retention
+SIEM ingestion without proprietary agents
EVENT EXPORT

Security stack integration

Events stream continuously from the site node — no batch export delays. Route them into your existing SIEM, log management platform, or internal audit pipeline without transforming the schema.

Revocation & Temporary Access

Support short-lived access paths and clear revocation boundaries for users, workloads, and external operators. Access grants can be time-limited by design — when the window closes, the path closes with it.

+Immediate revocation — no session lingering
+Time-boxed grant windows for external operators
+Workload and CI identity revocation
+Approval-gated grant flows
netseed access
# revoke an active access grant
netseed access revoke --grant g-7f2a
Grant g-7f2a revoked.
identity: alice@example.com
service: db.prod.ns
active sessions terminated: 1
audit record emitted.
Control model

Every layer of the access decision is auditable.

Policy is distributed from NSD and applied at the site node — enforcement is always close to the resource. Every grant, every flow, and every revocation produces a record.

POLICY

Centrally distributed

NSD distributes policy to every site. Changes propagate without touching network configuration or restarting services.

ENFORCEMENT

Site-side final decision

NSN applies ACL next to the workload. The enforcement point is always close to the resource — not in a remote control plane.

KEYS

Keys stay on-device

WireGuard private keys are generated and stored on the device. Nothing is centrally distributed that could be intercepted or leaked.

SCOPE

Least privilege by design

Access is scoped to the named service, not the surrounding network. Broad access requires explicit, additional policy — it is not the default.

Next step

Access controls that security operations can rely on.

Identity, device trust, audit export, and revocation — all in the same binary, no additional agents required.