01
⊘
Identity-First VPN
Access tied directly to corporate SSO — Google Workspace, Okta, and Entra ID. No SSO, no access. Period.
Core02
⚡
Instant Access Revocation
Removing a user from the IdP immediately cuts off VPN access. Zero delay, zero lingering credentials, zero manual steps.
Security03
⬡
Role-Based Access Control
Enforce least-privilege access based on team, role, and service. Engineers get exactly what they need — nothing more.
Access04
◎
Multi-Cloud Connectivity
Single VPN spanning AWS, GCP, and Azure VPCs. One policy layer, one audit trail, across your entire multi-cloud footprint.
Infrastructure05
◈
Sensitive Service Classification
Tag critical services and enforce stricter access policies for them. Production databases get a different policy to staging.
Policy06
≡
Full Audit Trail
Every connection logged with complete context — who, what, when, and where. Export-ready for compliance reviews.
Compliance07
⚿
MFA Enforcement
Support for TOTP and WebAuthn for high-security environments. MFA required before any VPN session is established.
Auth08
⏱
Session Management
Control sessions with idle timeouts, real-time tracking, and forced disconnects. No stale sessions left open overnight.
Sessions09
⊕
Geo & Device Policies
Restrict access based on user location and device type. Engineers on unmanaged devices or unexpected locations are blocked automatically.
Policy10
⇌
Split Tunneling
Route only required traffic through the VPN for efficiency. Everything else goes direct — no unnecessary latency for non-sensitive requests.
Network11
⚑
Suspicious Activity Alerting
Detect failed logins, unusual locations, and anomalous access patterns. Shankh routes the alert — Legion investigates.
Monitoring12
⟳
Automated User Lifecycle + Open-Core Architecture
Zero-touch onboarding and offboarding synced with your identity provider. And because Dvarpala is built on open-core architecture, your network infrastructure is transparent and inspectable — no black boxes securing your access layer.
Lifecycle