The platform

One fabric. Five backend groups. 186 operations.

SASE Mesh is not a demo. It fronts five GA shared services on StratoGroup's 60-service, 1,420-operation platform — 186 operations across networking, DNS, threat detection, the edge gateway and observability — stitched into one sovereign fabric with a single identity, tenancy and audit boundary.

60 platform services1,420 operations5 groups in this fabric186 mesh operations

Capability groups

Each group is a real GA service — and a deep-dive.

Every card maps to one backend shared service with a real operation count from its API reference. Open any group for its sub-capabilities, real method + path endpoints, worked examples, and where it sits in the architecture.

How it fits together

One identity, one tenancy boundary, one audit chain.

The groups are not five products bolted together — they share the platform's spine. Requests enter only through the SS-07 edge, carry one SS-01 identity and X-Tenant-Id, and every state change is written to the SS-06 audit chain.

SS-07Edge WAF

TLS · JWT · WAF · rate-limit · admit & proxy

SS-26SASE & mesh

ZTNA · mesh · WireGuard coord · SD-WAN · UPO

SS-25DNS steering

zones · GeoDNS · DNSSEC · serve-stale

SS-28SecOps

detections · Zeek mesh audit · containment

SS-06Observability

metrics · SLOs · probes · signed audit index

Supporting services under every call: SS-01 identity (OIDC), SS-05 Vault (keys), SS-02 claims (state), SS-60 metering and SS-10 billing — the same dogfooded path that onboards you.

See it running

Watch the fabric operate in the console.

A realistic control-plane mockup: the mesh topology, ZTNA policies and access log, the UPO compile + apply-diff, threat events and the node enrollment board.