Give each internal service a private name that only your mesh can resolve. No public gateway, no flat network, no detour through anyone's cloud — including ours.
VPN here means the remote-access VPN — the corporate gateway your employees tunnel into for internal apps. Not site-to-site links between data centers, and not consumer VPNs; those are different animals.
That remote-access VPN hurts three rooms at once. Security lives with a public door that attackers scan for. Infrastructure lives with a concentrator every packet must visit. And users live with one more thing to log into, slow enough that they eventually turn it off.
65% of enterprises plan to replace their VPN with ZTNA (Gartner). But most ZTNA fixes these pains by routing your traffic through the vendor's cloud — you trade the old middleman for a new one, this time outside your jurisdiction.
That's not a feature gap they'll ship past next quarter; it's their business model. Cloud ZTNA creates value by working on your traffic — inspection, filtering, DLP, behavioral analytics. To work on traffic they must see it; to see it, it must flow through them. When you require "no third party on my data path," they can't comply without switching off the very thing they sell.
A question you can put to any vendor: "If we turn off the path through your cloud, what's left of the product?" For cloud ZTNA, the honest answer is: almost nothing. For Ankayma, everything — the control plane only coordinates connections and was never on the data path, and there's a Prove-it button so you don't have to take our word for it.
One honest boundary: this argument targets cloud-routed ZTNA. Peer-to-peer overlays share our data-plane answer — with them, the comparison is about who holds your identity, your control plane, and your logs. That story is on the front page.
Most ZTNA works per-app, as a Layer-7 proxy. That one design choice is where the pain comes from: you need a full application inventory before you can write the first policy, server-initiated and legacy protocols break through a proxy, and the realistic timeline for a 500-person organization runs 9 to 14 months — the parallel-run phase alone eats 3 to 6 of them (migration field guide). The common end state: two systems running side by side — ZTNA for web apps, the old VPN kept alive as fallback for SSH, RDP and everything the proxy can't carry — double the administration, with the VPN attack surface still standing (Venn).
The prize on the other side is real — VPNs eat 25 to 40% of helpdesk tickets in mature organizations, and completing the move cuts access tickets by half or more (Meriplex). It's the road there that's expensive.
Everything ZTNA promises, at the network layer — legacy apps just work, no VPN fallback, no broker in your path. Ankayma is an overlay at the network layer, not a per-app proxy: two-way and legacy protocols run in the mesh the way they run on a LAN, by architecture. And coexistence isn't a risky migration phase here — it's the designed state: what you bring into the mesh gets secured, what you leave outside stays exactly as it was. Start with one service in five minutes, not with an inventory project.
The other public door most teams keep open is SSH. The average organization holds around 23,000 SSH keys and 90% of them are unmanaged; 46% of organizations never rotate (Ponemon / Venafi — magnitudes hold across surveys). Keys don't expire and don't leave when people do — on average, every server carries one orphan root key of someone who already left (Venafi).
A static key is a mechanical key cut in dozens of copies and handed out over the years — nobody remembers who holds which copy, to which door. NoKey swaps that for a door that opens on the person plus a badge that expires: engineers reach machines by device identity, root is a signed grant that lives at most fifteen minutes and falls away on its own, every session start lands in your ledger, and the SSH server binds inside the overlay — no port on the internet, no bastion, and it never touches your existing sshd. Fifteen minutes isn't an exotic number: the industry's short-lived credentials already speak in minutes — Cloudflare mints 3-minute SSH certificates, EC2 Instance Connect keys live 60 seconds. Offboarding a person is revoking one identity. Works from a laptop — and from the phone in your pocket. See the 5-minute walkthrough →
The freelancer who sells with demos — each project pinned to its own private domain, the client's device invited into the mesh, and the demo opens on their side with nothing public. The team with an internal portal — wikis, dashboards, admin panels that today sit behind a VPN nobody enjoys, tomorrow carry private names with per-identity access and a ledger.
Does this sound like your network?
Tick what's true. Nothing is sent — this is for you.
That's the door. Put one internal app on a private name in five minutes — free, nothing public.
Download freeReach for us when you want internal apps off the public internet with no broker on your data path, you run real infrastructure rather than a single cloud that already covers you, and you'd rather not route internal traffic through a vendor's cloud or another jurisdiction.
Reach for someone else when you need a global, browser-delivered SASE today, or your apps are all standard web behind a cloud proxy you're happy with. And with a peer-to-peer overlay like Tailscale the data-plane answer is the same as ours — there the honest comparison is control plane, identity, and logs, not the path.
One choice among several — this page exists so you can tell which one you're looking at.
We publish what this doesn't do yet, in plain words: our honest limits →