Zero Trust Network Access
One private network, deny by default
Every device joins one private network, encrypted end to end. It reaches nothing until a rule names its group, and the device requirements are checked continuously.
Free plan · No card
Works with
open inbound ports
Every device dials out. Nothing to scan, nothing to reach without an identity.
to a first connection
From installation to secure device-to-device access in minutes.
per device / month
Professional pricing that scales with the number of devices your organization needs.
to start
Up to 5 devices. No credit card, no expiry.
How it works
Up and running in three steps
No firewall change, no public endpoint.
Install the agent
One command, or a silent push from your MDM.
Devices find each other
They exchange reachability details, then connect directly. No tunnel to configure.
Write one rule
Support reaches the ticketing system on 443. Nothing else.
Access rules
Joining the network is not access
A device that joins reaches nothing until a rule allows it.
- Rules name groups, not addressesEngineering to staging-db on 5432. Still readable a year later.
- Identity first, then device requirementsThe rule checks who you are. The device requirements are checked on the machine. Both can only take access away.
- Refused before it opensNo rule, no connection: it stops at setup, not at the application. The device requirements are checked after that too.
Connectivity
Direct connections, even through NAT
Two devices behind different firewalls normally can't reach each other. Here they do.
- Discovery finds the pathEach device reports how it can be reached, then a direct connection opens.
- Relay only when a network refusesCarrier-grade NAT or symmetric firewall? The session relays instead of failing, still encrypted.
- Direct or relayed, and you can tell whichThe agent reports it on the device. A slow link is a fact you can look up.
Controls
Built in, not bolted on
The controls a security review asks about, in the product already.
Device requirements
Checked continuously: agent version, OS, expected country. A device that drifts loses access.
Read moreAccess rules
Group to group, with the ports spelled out. Nothing else gets through.
Read morePrivate DNS
Internal names resolve inside the network, per group.
Read moreActivity log
Append-only. Nothing in the product can edit an entry.
Read moreOrganizations
One account, separate networks for client, staging and production.
Read moreRoutes and internet gateway
Reach a subnet nothing runs an agent on. Send internet traffic out through a device you choose.
Read moreBefore and after
What you stop running
Three things every traditional setup has. This one doesn't.
A concentrator in a rack
Every packet between two colleagues detours through one box, then queues.
Direct device-to-device links
Two machines on the same floor talk directly. Capacity grows as you add devices.
Open inbound ports
A box on a public address to harden, and a port-forward to justify.
Outbound only
Nothing is exposed, so there is nothing to scan.
Rules written as IP ranges
Nobody remembers what 10.4.0.0/22 was for, or who is in it.
Rules written as groups
Still true after the next re-addressing.
Use cases
Start from the problem you have
Five common ones, one network underneath.
Remote access
People at home or in airports reach what their role allows, nothing else.
Read moreBusiness VPN
Retire the concentrator. Nothing left to size or fail over.
Read moreSite to site
An office, a cloud region and a rack as one network. Nothing renumbered.
Read moreKubernetes
Reach services and the API with no bastion and no public endpoint.
Read moreOn-premises sites
One routing device inside the building. Printers and controllers are named one by one.
Read moreAWS and cloud VPCs
One instance carries the route into a private VPC. No inbound rule, no public address.
Read moreHosted
Nothing to host or patch
SXAccess is a hosted service. No server to install, no self-hosted edition.
- The control plane never carries trafficIt hands out configuration only. A relayed session passes through us encrypted, in a form we can't read.
- Documented in fullThe connection model, the ports and every screen are in the docs.
- No pager for youWe scale it, patch it and carry the pager.
FAQ
Questions people ask first
Is the free plan really free?
Yes. 5 members and 5 devices, with SSO and the full mesh. No card, no trial clock.
What does it cost after free?
Up to 5 devices, nothing is charged. From the sixth device on, Professional is $2 a month for every device, not just the ones past five.
How is this different from a mesh VPN?
Connecting devices is the easy half. Here a rule between two named groups decides access, device requirements are checked continuously, and the price is a flat $2 per device once you pass five.
Do I need to open any ports?
No. Every device dials out. There is nothing to forward or harden.
What if two devices can't connect directly?
It relays instead, and the agent on the device reports the connection as relayed.
Can I run the control plane myself?
No. SXAccess is hosted only. If self-hosting is a hard requirement, this isn't the product for you.
Your first connection in about three minutes
Install the agent, add a second machine, write one rule.
No card · Nothing expires