Limit access and verify the connection state that actually exists.
Nanami links an account, device, access policy, and route without hiding important decisions behind one generic status.
Identity and access chain
Role scope and session state gate every network action.
Access is checked at each layer
Each state answers a separate question: who signed in, which device is enrolled, what is allowed, and whether a connection is active.
Verified account
Password, MFA, and configured SSO providers are offered only when the selected environment supports them.
Enrolled device
Repeated sign-in reuses stable device identity. A revoked device cannot silently regain access.
Explicit access policies
Users and teams can reach only the networks and resources assigned to them.
Observed connection
Authentication, device presence, and an active connection remain separate states.
Security boundaries stay visible
Primary UI shows the outcome and next action. Technical context appears only as sanitized diagnostics after authentication.
What the interface protects
Support context remains available without exposing internals in ordinary messages.
Review the model against your use case
Start with the docs or sign in to Nanami. We do not claim certifications or absolute security without evidence.
Need practical steps?
Quickstart covers environment choice, sign-in, and the first device.
Need to review access?
Access policies show who can reach each network.