Node Vertex Enterprise

VPN-level reach. Zero network trust.

Node Vertex Enterprise is a Zero Trust communication fabric for humans, agents, apps, services, and devices - authenticated by your IdP and governed at the vertex level.

You are authenticated, but you may only interact with this exact vertex, for this purpose, under this policy, for this duration.

Vertex Firewall Finance approval path
allow:
  group: Finance-Approvers
  device: compliant
  mfa: phishing-resistant
  action: write
  vertex: /acme/finance/invoices/approval
  ttl: 15m
/acme/apps/payroll /acme/admin/server-12/ssh /acme/agents/soc/enrich-ip

From Network Access To Vertex Access

Legacy VPNs extend the network. Node Vertex publishes controlled communication vertices.

Instead of granting a user access to a subnet, VPC, or private network, enterprises grant access to specific vertices - each with identity, policy, TTL, audit, routing, and optional transformation.

/acme/apps/payroll /acme/admin/server-12/ssh /acme/files/legal-drop /acme/logs/firewall-stream /acme/agents/soc/enrich-ip /acme/actions/isolate-device

Identity Boundary

Authenticated by your IdP

Node Vertex Enterprise consumes enterprise identity and turns identity claims into vertex-level authorization decisions. Your IdP remains the source of identity.

Microsoft Entra ID Okta Ping Identity Google Workspace ADFS SAML OIDC SCIM group sync Conditional access
User Group Role Department Device compliance MFA status Risk score Location Session age Tenant Agent identity Workload identity Service account NRN / vertex identity

VPN Alternative

Stop treating authentication as permission to enter the network.

Node Vertex Enterprise keeps access named, scoped, observable, and revocable by default.

Traditional VPN/ZTNANode Vertex Enterprise
Grants network accessGrants vertex access
Subnet-level trustResource/action-level trust
Long-lived network sessionsTTL-bound vertex sessions
Hard to audit intentEvery interaction has a named vertex
Lateral movement riskNo network adjacency by default
Human-centricHuman, agent, app, service, and device-centric
IP/routing heavyIdentity, policy, and vertex routing fabric

Enterprise Use Cases

Publish precise surfaces instead of opening broad paths.

Private App Access

Publish internal apps through App Vertices instead of VPN. The user gets access to the app surface, not the network.

https://n-v.io/acme/apps/payroll
localhost:8080
internal-payroll.acme.local
10.40.2.18:443
k8s service
private VPC endpoint

JIT Admin Access

Replace standing VPN plus SSH/RDP access with short-lived admin vertices that include approval, MFA, ticket number, session recording, audit, and TTL.

/acme/admin/server-12/ssh
/acme/admin/sql-prod/query
/acme/admin/k8s/prod/action

Agent and Workload Communication

Agents receive scoped read-only or action vertices, not broad VPN access, global API tokens, or permanent secrets.

/acme/agents/helpdesk/read-ticket
/acme/agents/soc/enrich-ip
/acme/agents/secops/request-isolation
/acme/agents/legal/summarize-contract

Secure File and Workflow Exchange

Use secure file drops, legal intake, contractor exchanges, forms, and one-time workflow vertices with policy and lifecycle built in.

/acme/files/legal-drop
/acme/forms/vendor-intake
/acme/workflows/contract-review

Log and Signal Streaming

Publish log stream vertices for secure telemetry ingestion, stream fanout, and named signal paths.

/acme/logs/firewall-stream
/acme/logs/endpoint-alerts
/acme/signals/siem-events

Enterprise Primitives

The fabric is built from governed vertices.

Identity Vertex

Represents a user, agent, device, service, or workload.

/acme/id/users/jdoe/acme/id/agents/soc-agent-7/acme/id/devices/macbook-123/acme/id/services/payroll-api

Access Vertex

A policy-controlled surface for communicating with something.

/acme/apps/hr/acme/db/payroll/query/acme/files/legal-drop/acme/logs/firewall-stream

Action Vertex

A governed action a user or agent may take.

/acme/actions/approve-access/acme/actions/reset-password/acme/actions/isolate-device/acme/actions/deploy-service

Session Vertex

A short-lived live connection with auth context, policy decision, TTL, audit trail, source identity, target vertex, device posture, risk score, and recording metadata where applicable.

/acme/sessions/01J...

Audit Vertex

Immutable event history for access, admin actions, agent actions, approvals, denials, and policy changes.

/acme/audit/access/acme/audit/admin/acme/audit/agent-actions

How It Works

A policy layer between identity and private resources.

User / Agent / Device Enterprise IdP Node Vertex Policy Layer Session Vertex Enterprise Connector / Sidecar Private App / Service / Workflow / Action Audit Vertex

Enterprise Access Fabric MVP

The first deployment surface is practical, governable, and CLI-friendly.

  • OIDC/SAML login with Entra and Okta
  • SCIM group sync
  • App Vertex private app publishing
  • Connector/sidecar inside customer network
  • Per-vertex RBAC
  • MFA claim enforcement
  • Session TTL
  • Full audit log
  • Admin approval flow
  • CLI support for publishing private apps/services
nv enterprise enroll --tenant acme

nv publish app payroll \
  --internal-url https://payroll.internal.local \
  --path /acme/apps/payroll \
  --groups "HR,Finance" \
  --require-mfa \
  --ttl 30m

Security Promises

Every interaction is named, scoped, logged, and revocable.

No broad subnet access No default network adjacency No permanent exposed endpoints No shared service-account sprawl No standing tunnels unless explicitly configured No access without identity and policy

Beyond MCP

Built for the age of enterprise agents

AI agents should not receive VPN access, global API tokens, database passwords, or unrestricted admin roles. They should receive scoped communication vertices with explicit permissions, approval gates, TTL, and audit.

Read-only vertices Action vertices Human approval gates Revocable agent sessions Full auditability Policy-controlled automation Safer MCP-style tool access
/acme/agent/soc/read-alert
/acme/agent/soc/enrich-ip
/acme/agent/soc/draft-response
/acme/agent/soc/request-isolation

Node Vertex Enterprise

Stop extending the network. Start publishing controlled communication vertices.

Give CISOs, platform teams, AI governance leaders, and builders a fabric where private communication is identity-aware by default.