Coming soon Monitored by the AI SOC

Arsenal Tunnel

Granular zero-trust remote access, managed from AlertMonitor.

Choose the user. Choose the devices. Choose the ports. Arsenal Tunnel builds the secure connection for you, expires it on your schedule, and monitors it for attacks the whole time it is open. The user gets exactly what they need — and nothing else on your network exists to them.

Arsenal Tunnel is in development and not generally available yet.

The problem

A vendor needs one port. Your VPN hands them the network.

A contractor needs RDP to one server. A vendor needs to reach the management page on one appliance. A new hire needs SSH to a single box for a week. Traditional VPNs answer all three the same way: put them on the network and hope segmentation holds.

The alternative is usually a firewall ticket — scoped rules, routes, an account, and a calendar reminder to tear it all down that nobody honors. So the access stays open long after the work is done. Arsenal Tunnel makes least privilege the fast option instead of the expensive one.

The broad-VPN way

  • Access to the network, then rules to claw it back
  • Firewall and routing work for every new request
  • Access outlives the project it was created for
  • One compromised laptop is a route into everything

The Arsenal Tunnel way

  • Nothing reachable until you select it
  • No manual configs, keys, rules, or routing
  • Access expires on a schedule you set
  • Two ports on two devices means exactly that

How it works

Four steps, all of them in the AlertMonitor portal you already use. No firewall change request, no config file to email.

1

Pick the user

In the AlertMonitor portal, an admin selects the person who needs access — a vendor, a contractor, or an employee.

2

Pick the devices and ports

Choose the specific devices they may reach and the specific services and ports on each one. Nothing outside that list is reachable.

3

The platform builds the connection

No manual VPN configs, keys, firewall rules, or routing to set up. The secure connection is built for you from the selections you made.

4

The user enrolls and connects

They install the app, enter the invite code sent to them, and open it. They reach only the defined devices, on only the assigned ports.

And then it ends by itself

When you create the access you also set the window — a duration, or specific hours and date ranges. When the window closes, access expires automatically. There is no follow-up ticket and no standing access left behind.

In the portal

One screen defines the entire blast radius.

The grant below is the whole permission. This vendor can open an RDP session to one server and an SSH session to one appliance, on Monday, between 09:00 and 17:00. At 17:00 the access is gone. Everything not on this screen was never reachable.

  • Selections are per device and per port — not a subnet
  • The connection is generated from these choices automatically
  • The invite code is what the user enters in the app
  • Revoke early from the same screen at any time
Arsenal Tunnel — New Access Grant
M. Alvarez — Northwind HVAC
Vendor · malvarez@northwind-hvac.com
USER
Devices & assigned ports
SRV-BMS-01
10.20.4.18 · Building management server
RDP 3389
APP-HVAC-CTRL
10.20.4.44 · Controller appliance
SSH 22HTTPS 443
All other devices, ports, and networks — not reachable
Time window
Valid 2026-08-03 09:00 → 17:00 CST
Access expires automatically · revoke earlier at any time
Invite code
TNL-7QK4-2M9X
SOC monitoring
ACTIVE

Controls and guarantees

What the admin holds, and what the user can never quietly acquire.

  • Least privilege by default — nothing is reachable until you explicitly select it
  • Per-device and per-port scoping, not a network route
  • Time-boxed access: a fixed duration, or specific hours and date ranges
  • Access expires automatically when the window closes — no cleanup ticket
  • Instant revoke from the AlertMonitor portal
  • Invite-code enrollment — no keys, profiles, or config files to hand out
  • No standing access sitting open between sessions
  • The live connection is monitored for attacks by the same AI SOC that runs AlertMonitor

Scoped by selection

Access is defined by the devices and ports an admin picked — not by what a routing table happens to allow.

Expires on schedule

Set a duration or specific hours and dates. When the window ends, so does the access.

Invite-code enrollment

The user installs the app and enters a code. No keys, profiles, or configuration to distribute.

Watched while open

The same AI SOC behind AlertMonitor monitors the live connection for attacks for as long as it exists.

Which one do I need?

Shield, Tunnel, and Verify solve different problems.

They are not alternatives to each other, and none of them assumes you are throwing out your existing VPN. Shield keeps a travelling device safe on the internet. Tunnel gives one person precise access to specific internal systems. Verify opens a firewall port on demand for someone who already has a path in.

The travel VPN

Arsenal Shield

Use it when: Staff are working from hotels, airports, and coffee shops.

Outbound — safe internet access anywhere

  • Gives the device access to the internet only — never to internal networks
  • No logging, no tracking of user activity
  • AI SOC monitoring stays on the device wherever it goes
  • One invite code, native apps, tap to connect
Granular zero-trust access

Arsenal Tunnel

Use it when: One person needs one system — and nothing else.

Inbound — precise access to specific internal systems

  • Admin selects the user, the devices, and the ports
  • The platform builds the connection — no manual VPN or firewall work
  • Time-boxed: valid for a duration, or set hours and dates
  • Connection monitored for attacks the whole time it is open
This page — coming soon
AlertMonitor feature

Verify

Use it when: Your team already reaches systems over RDP or SSH through your firewall.

Inbound — on-demand firewall opening

  • SMS MFA before any remote access is permitted
  • Opens a dynamic firewall rule for that user, that port, that session
  • Zero standing access — the rule closes on schedule
  • Full audit log of who accessed what, from where, for how long

The short version: Arsenal Shield is about getting your people safely outto the internet from untrusted Wi-Fi — it never gives a device access to internal networks. Arsenal Tunnel is about letting a specific person in to specific systems, on specific ports, for a specific window. Verify is the on-demand firewall gate for RDP and SSH access your team already has a path to.

Arsenal Tunnel FAQ

Coming soon

Tell us who keeps asking for access.

Arsenal Tunnel is still in development. If scoped vendor, contractor, or single-system access is a problem you are working around today, get on the early access list and we will share timing and shape the rollout around real cases.