The platform
SASE Mesh is not a demo. It fronts five GA shared services on StratoGroup's 60-service, 1,420-operation platform — 186 operations across networking, DNS, threat detection, the edge gateway and observability — stitched into one sovereign fabric with a single identity, tenancy and audit boundary.
Capability groups
Every card maps to one backend shared service with a real operation count from its API reference. Open any group for its sub-capabilities, real method + path endpoints, worked examples, and where it sits in the architecture.
ZTNA, the sovereign mesh, native WireGuard coordination, SD-WAN and the UPO policy compiler — one fabric.
Authoritative DNS, GeoDNS steering, health-checked answers and a DNSSEC ceremony — the resolution layer under the mesh.
Detections-as-code, guard-railed containment, threat intel, and the Zeek mesh chaos-rig auditor.
The Envoy edge in front of the whole fabric: TLS, JWT, WAF, rate-limits, routes and weighted canaries.
Metrics, logs, traces, SLOs with burn-rate routing, synthetic probes and the signed audit index for the whole fabric.
How it fits together
The groups are not five products bolted together — they share the platform's spine. Requests enter only through the SS-07 edge, carry one SS-01 identity and X-Tenant-Id, and every state change is written to the SS-06 audit chain.
TLS · JWT · WAF · rate-limit · admit & proxy
ZTNA · mesh · WireGuard coord · SD-WAN · UPO
zones · GeoDNS · DNSSEC · serve-stale
detections · Zeek mesh audit · containment
metrics · SLOs · probes · signed audit index
Supporting services under every call: SS-01 identity (OIDC), SS-05 Vault (keys), SS-02 claims (state), SS-60 metering and SS-10 billing — the same dogfooded path that onboards you.
See it running
A realistic control-plane mockup: the mesh topology, ZTNA policies and access log, the UPO compile + apply-diff, threat events and the node enrollment board.