Choose business VPN or private-resource access

Consumer public-internet exits versus private network and application access, SSO, device controls, logging and team deployment on stored records. A consumer VPN is not private-resource access. Not a ranking.

What this isA source-based reading of stored business_controls rows already on this site. Official Australian guidance is used for Australian claims. It is not a ranked winner list, not a numeric security score, and not a claim that SSO, a kill switch or a tunnel makes you untraceable, legally compliant or universally protected. Live app tests remain not tested.

A consumer VPN is not private-resource access

A personal VPN encrypts traffic from a device to a vendor exit and out to the public internet. That can hide a café network from the sites you visit. It does not put you on the office file server, the admin console or an internal app. This site keeps two collections: Personal VPN and Business remote access. Category: VPN.

ASD’s Australian Cyber Security Centre tells people on public Wi-Fi to consider a VPN and to read the provider’s privacy policy because the operator can see a large amount of user data. That page does not name a ZTNA product. ACSC, Connecting to public Wi-Fi and hotspots (last updated 11 Apr 2023; fetched 12 Sep 2026).

A different threat is remote access into an organisation. ACSC’s October 2021 Using Virtual Private Networks publication is about site-to-site and remote-access VPNs onto a network: separate VPN accounts, least privilege, MFA, device authentication, termination in a DMZ, disable split tunnelling on those organisational connections, and log authentication and sessions. It is organisational guidance, not a consumer product list. ACSC Using VPNs (October 2021 PDF). Essential Eight still expects organisations to patch, use MFA and log. Essential Eight explained.

NIST SP 800-77 Rev. 1 describes IPsec as network-layer encryption of packets. That is confidentiality on a path, not identity-aware application access, and not anonymity. NIST SP 800-77 Rev. 1 (June 2020; fetched 12 Sep 2026).

How stored cells are read

Missing business_controls is unknown, not unsupported. Missing a control key is unknown for that control, not a product-wide no. plan_dependent is not a universal yes. Object-level plan_dependent: true is not a cell value — read SSO, posture and private-resource access separately. Unknown cannot satisfy a hard requirement.

Twelve personal products have no business_controls object. Four business products have one. Hand check 12+4=16. A consumer VPN is not private-resource access. Same class is not a ranking. Counts are integers, not billed totals.

Private network and application access

Office-resource filter: business remote access and private_resource_access documented yes. Unknown cannot satisfy. plan_dependent is not a universal yes. Result on this dataset: 3 pass.

NordLayer Lite is documented for Virtual Shared Gateways (internet access). Virtual Private Gateways, dedicated IPs and IP allowlisting start on Core. Stored private-resource access is plan_dependent. Lite shared-gateway egress is not private-resource access. NordLayer shared gateways. NordLayer private gateways. NordLayer review.

Tailscale ACLs, subnet routers and peer-to-peer WireGuard are the product on the stored Standard SKU. Exit nodes are opt-in. A documented public_internet_egress yes is not a consumer country-picker VPN. Tailscale access control. Tailscale review.

Twingate Resources via customer Connectors are the product, including on Teams. Exit Networks (full-tunnel via your Connectors) are on Home and Business, not on the Teams card. Stored public-internet egress is plan_dependent. Twingate Resources. Twingate Exit Networks. Twingate review.

Cloudflare One private-resource access is a customer-deployed Tunnel plus Access policies, on Free and PAYG. Gateway SWG is public-internet filtering on those SKUs, not a consumer country VPN. Magic WAN and Email security are Contract add-ons, not the PAYG seat. Consumer WARP is not this product. Cloudflare Tunnel. Cloudflare One review.

Hand check 3+1=4: three business SKUs document private-resource access yes; NordLayer Lite is plan_dependent. Public-internet egress is the inverse shape: 3+1=4 with Twingate plan_dependent.

SSO and MFA

Stored SSO is yes on all four starting business SKUs. Hand check 4+0=4. That is not Okta on every plan. Twingate Teams documents Google Workspace SSO; Okta, Entra ID and JumpCloud SCIM start on Business. Stored SSO yes on Teams is Google Workspace, not Okta. It is not relabelled as plan_dependent. Twingate two-factor authentication.

Tailscale is not an identity provider. MFA is whatever the IdP enforces. NordLayer documents MFA and SSO (Okta, Entra ID, OneLogin, Google, JumpCloud) on Lite; SCIM user provisioning is an add-on until Premium. Cloudflare Access documents IdP SSO including SAML/OIDC on the Zero Trust platform table for Free and PAYG. NordLayer SSO. Tailscale identity providers. Cloudflare One identity providers.

A consumer VPN login is not SSO. Do not infer Entra ID from a personal NordVPN, Surfshark or Proton account.

Device controls

Device posture is documented yes on Tailscale Standard, Twingate Teams and Cloudflare One PAYG. NordLayer Device Posture Security is an add-on on Core and included on Premium, so the Lite starting SKU is plan_dependent. Hand check 3+1=4. Access policies use the same split. NordLayer Device Posture security. Tailscale device posture.

Logging

Stored audit_logs is yes on all four business SKUs. That is vendor activity or configuration logging, not an inspected SOC 2. Business SOC 2 and ISO rows on this dataset are announcement or gated; none were opened. Inspected SOC 2 reports here: 0. How this site classifies audits. Twingate audit logs.

Team deployment

NordLayer Lite/Core/Premium cards print a 5-user minimum. Tailscale Standard, Twingate Teams and Cloudflare One PAYG store minimum_seats 1. Hand check 5≠1. That 5 is a seat floor, not a billed total, and not 5*9600=48000 from the cost tool. Cloudflare One Free is a 50-user cap on a US$0 tier, not a 5-seat commercial floor.

Tailscale Personal is non-commercial. Twingate Home and Starter are not the commercial Teams SKU. Do not buy those for office resources.

Worked example: classify stored rows

Independent count over records already on this site. Hand checks: 3+1=4 private-resource access, 3+1=4 device posture, 3+1=4 access policies, 3+1=4 public-internet egress, 4+0=4 SSO, 12+4=16 personal unknown plus business classified, 5≠1 NordLayer seat floor. Same class on two products is not a ranking. Counts are integers, not billed totals.

Office laptop filter: business remote access and private-resource access yes. Unknown cannot satisfy. plan_dependent is not a universal yes. A consumer VPN is not private-resource access. Result on this dataset: 3 pass.

Team-control filter: the office filter plus SSO yes, MFA yes, device posture yes and audit logs yes. Result: 3 pass. NordLayer Lite fails both filters because private-resource access and device posture are plan_dependent.

Office-resource filter from stored business_controls rows. A consumer VPN is not private-resource access. Not a ranking.
ProductPrivate resourcePublic-internet egressOffice filterInspected SOC 2
NordLayerPlan-dependentYesFailNo
TailscaleYesYesPassNo
TwingateYesPlan-dependentPassNo
Cloudflare OneYesYesPassNo

Team controls

Team SSO, MFA, device posture and audit logs plus private-resource access. plan_dependent is not a universal yes. Not a ranking.
ProductSSOMFADevice postureAudit logsSeats floorTeam filter
NordLayerYesYesPlan-dependentYes5Fail
TailscaleYesYesYesYes1Pass
TwingateYesYesYesYes1Pass
Cloudflare OneYesYesYesYes1Pass

Yes versus plan_dependent

Stored yes versus plan_dependent on the four business starting SKUs. Same class is not a ranking. Counts are integers, not billed totals.
ProductPrivate resourceDevice postureAccess policiesInternet egressMinimum seats
NordLayerPlan-dependentPlan-dependentPlan-dependentYes5
TailscaleYesYesYesYes1
TwingateYesYesYesPlan-dependent1
Cloudflare OneYesYesYesYes1

Machine-readable formula and counts: classify.json. Method: How we test.

Decision checklist

  • If the need is café Wi-Fi on a phone, stay on Personal VPN. A business overlay is not a consumer public-internet exit.
  • If the need is the office file server or an internal app, require documented private-resource access. NordLayer Lite shared gateways do not satisfy that cell.
  • Read the starting SKU. Twingate Teams SSO is Google Workspace. Okta is not on that card.
  • Treat stored audit logs as vendor logging. Stored audit_logs yes is not an inspected SOC 2.
  • Count the seat floor. NordLayer’s 5-user minimum is 5≠1 versus Tailscale Standard.
LimitsNo live tunnels, SSO logins, device-posture checks or SOC 2 downloads were run. Apps were not installed. Checkout was not started. Trust Center and dashboard-gated reports were not opened. This guide is not legal advice and not a compliance certificate.

Sources

Shortlist

0 of 3 products

Add products from a review, category table or finder results. Maximum 3.

Add two or three products in the same category to compare.