VPN Works Scope live demo vpnw.com

Who on this VPN needs to reach what?

An office of 30 people and 12 internal systems on a flat VPN, where any login can reach anything. Scope learns who uses what from two weeks of traffic and drafts rules. A person reviews them. Then the week after is replayed under the draft, and so is a stolen login. Every number below is computed in this page by Scope's own code.

Loading Scope's engine

Step 1 of 6

A flat VPN: every login reaches every system

Thirty people in five teams connect to the office over one VPN. Twelve internal systems sit behind it. Like many company VPNs, this one is flat: once someone is logged in, every system and every port is in reach.

People, by team

Internal systems

Three weeks of traffic new connections per day

the two weeks Scope learns from the week after, replayed in step 4

On this VPN, a stolen login reaches all 12 systems. Step 5 shows it.

What is real here

Real

  • The code: Scope's own Go code, compiled to WebAssembly for this page. It learns the draft, reads your edits, decides every replayed connection and writes the rules.
  • The numbers: the same as in the Scope Alpha report, which ran the same code on the same generated office with the vpnw-scope command.
  • The rules: in the tests, the nftables script was loaded into Linux in a private test network and checked against Scope's simulator on 4,464 real connections, and on 36,881 for a generated office of 2,000 people. They agreed on every one.

Generated

  • The office: its people, teams, systems and three weeks of traffic, made from seed 20260907 by the same generator the tests and the report use.
  • No network: nothing in this page connects anywhere. In step 5, "reached" and "refused" are Scope's decisions, which the tests matched against the kernel.