# Choose business VPN or private-resource access — classification

Observed / calculated: 2026-09-12, Australia/Sydney  
Method: original calculation over stored `business_controls` rows.  
Not: a product ranking, a numeric security score, a live-app test, an inspected SOC 2, a guarantee of anonymity, or a compliance certificate.

## Cells

1. Yes / no / unknown / not-applicable / plan_dependent as stored when the control key exists.
2. Unknown: the `business_controls` key is missing, or that control key is missing, or the stored value is unknown. Unknown is not unsupported.
3. plan_dependent is not a universal yes.
4. Object-level `plan_dependent: true` is not a cell value.
5. A consumer VPN is not private-resource access.

## Hand arithmetic

- Private-resource access: `3+1=4`. NordLayer Lite shared gateway is plan_dependent.
- Device posture: `3+1=4`.
- Access policies: `3+1=4`.
- Public-internet egress: `3+1=4`. Twingate Exit Networks are not on Teams.
- SSO: `4+0=4`. Stored yes on Teams is Google Workspace, not Okta.
- Family split: `12+4=16`. Missing `business_controls` is unknown, not unsupported.
- NordLayer seat floor: `5≠1`. Integer seats, not a billed total.

## Office laptop filter

`business_remote_access` AND `private_resource_access` yes. Unknown cannot satisfy. plan_dependent is not a universal yes. Result on the stored dataset: 3 pass.

## Team-control filter

Office filter plus SSO yes, MFA yes, device posture yes and audit logs yes. Result: 3 pass. NordLayer Lite fails both.

Stored `audit_logs` yes is vendor logging, not an inspected SOC 2. Inspected SOC 2 count: 0.

See `/guides/business-vpn-vs-remote-access`.
