Enterprise Products · Closed source
Acksess
Replace the VPN with access that checks every device.
- to connect your first devices
- ~5 min
- to cut access when a device drifts
- < 2 s
- by default: nothing is reachable without a rule
- Deny
- for 5 members and 5 devices, every feature
- Free
Overview
Acksess is Zero Trust network access built on WireGuard. People reach exactly the servers, databases and networks a rule allows, and only while their device is encrypted, patched and firewalled. Everything else is denied by default. Each organisation gets its own private, isolated control server, so there is nothing for you to host, and a device that drifts out of compliance loses access in under two seconds. Available in two editions: PingTrust and a NetBird-based edition.
How it works
From setup to enforcement
- Step 01
Create your organisation
Sign up with Google, an email link or a password. Your organisation gets its own private control server, isolated from every other customer.
- Step 02
Add devices
Install the app on laptops and run one command on servers. Each device joins with its owner's identity or a scoped enrolment key.
- Step 03
Write one rule
Nothing is reachable until a rule says so, for example "Engineering may reach the staging database on 5432, from a compliant device". Test it in the simulator before you save.
- Step 04
Identity and posture decide, continuously
Each rule is evaluated as identity plus device posture, and the result is pushed to devices as an explicit allow-list. When a device falls out of compliance, its access is removed in under two seconds.
Features
Key features
Device posture checks
Disk encryption, host firewall, secure boot, OS version, country and named processes. Every signal records how much it can be trusted: server-observed, third-party verified, or self-reported.
Rules you can test
Target groups, devices, CIDRs or named networks, and preview who gains or loses access in the simulator before you save.
Just-in-time access
Request production for an hour, get approved by someone else, and lose it on time. No standing access to what matters.
An audit log you can prove
Every administrative change is hash-chained and verifiable, and streams to Splunk, Microsoft Sentinel or a signed webhook.
Your identity provider, or ours
Start with Google or email, then connect Okta, Microsoft Entra ID or any OIDC provider with SCIM provisioning.
Routes, gateways and DNS
Reach whole office and cloud subnets through a router device, send internet traffic out through a gateway you choose, and resolve internal names.
WireGuard encryption
Every connection is encrypted end to end with WireGuard, device to device.
Isolated control plane per customer
A dedicated control server per organisation, with database-level tenant isolation behind it.
Who it's for
Built for how teams actually work
Retire the VPN
Give people access to the specific systems their role needs instead of a whole network, with no concentrator to size, patch or fail over.
Production access that expires
Engineers request time-boxed access to production, a second person approves it, and it ends on schedule, with every step in the audit log.
Reach office and cloud networks
A single router device exposes an office or cloud subnet, and a gateway carries internet traffic when you need a fixed exit point.
Answer the auditor
Show who can reach what, from which compliant devices, and prove every change with a verifiable, hash-chained log.
Technical details
Works with your stack
- Protocol
- WireGuard, encrypted device to device
- Devices
- Desktop app for laptops; one-command enrolment for servers
- Enrolment
- Owner's identity or a scoped enrolment key
- Identity
- Google, email link or password; Okta, Microsoft Entra ID or any OIDC provider, with SCIM
- Posture signals
- Disk encryption, firewall, secure boot, OS version, country (server-observed), named processes
- Access rules
- Groups, devices, CIDRs and named networks, with a pre-save simulator
- Audit export
- Splunk, Microsoft Sentinel, signed webhook
- Hosting
- Fully hosted; a private, isolated control server per organisation
- Editions
- PingTrust, and a NetBird-based edition
Pricing
Plans
Free for 5 members and 5 devices, with every feature included and no expiry. Pro adds more users and devices, priority support and rollout help.
Free
For small teams getting started.
- 5 members and 5 devices
- Every feature included
- Device posture, JIT access and audit log
Pro
PopularFor teams rolling out across the organisation.
- More people and devices
- Priority support
- Help rolling out
FAQ
Questions teams ask
How is this different from a VPN?
A VPN puts a device on a network. Acksess grants access to specific servers, databases and subnets per rule, only while the device passes its posture checks, and denies everything else.
What happens when a device falls out of compliance?
Its access is removed automatically, in under two seconds in our end-to-end tests, and restored when it passes its checks again.
Do we need to host anything?
No. Acksess is fully hosted, and each organisation gets its own private control server. You install the app on devices and nothing else.
Which edition should we use?
Both editions give you Zero Trust access over WireGuard. Talk to us and we will recommend the edition that fits your environment.
Products
More from Cyphlon
Chainsaw
Block malicious packages before they download.
DSO
Scheduled code scans, AI pentests, and fixes you approve.
SHD Investigation Platform
AI-enabled data fusion and investigation for signals intelligence.