Outbound agent connection
Reach the gateway from behind ordinary NAT or CGNAT without opening an inbound port.
ASL Tunnel connects an outbound agent to a permanent ASL gateway so authorized users can reach selected local HTTP or WebSocket services without opening an inbound router port.
A local service may need temporary remote access even when inbound networking is unavailable. Generic tunnels can create long-lived forgotten exposure. ASL Tunnel gives each route an identity, expiration, visibility mode, credential lifecycle, traffic controls, and audit history.
Reach the gateway from behind ordinary NAT or CGNAT without opening an inbound port.
Use a stable path-based route for an approved HTTP or WebSocket service.
Choose an appropriate viewer boundary for each route rather than one global exposure mode.
Expire, rotate, suspend, or revoke route and agent access.
Monitor counters, limits, connection status, last seen, and a global kill switch.
Review and control routes from the protected dashboard and Android admin application.
Choose the local service, allowed viewers, expiration, traffic limit, and responsible owner.
Create a route and pair the outbound agent without placing long-lived secrets in command history.
Monitor activity, rotate credentials, disable when unused, and retain the required audit evidence.
ASL Tunnel is intentionally not a general VPN. The current scope is approved HTTP and WebSocket forwarding. High-risk protocols remain deferred until stronger visitor authorization, network restrictions, and abuse controls exist.
No. The agent establishes the connection outbound.
Not in the documented current scope. Raw TCP, SSH, RDP, databases, and VPN-like access are deferred.
Yes. Expiration, suspension, rotation, revocation, and traffic limits are part of the MVP.
The Android app is administrative; it monitors and controls routes rather than publishing an Android-local port.
Yes. The product supports private and public route modes.
Capabilities reflect the documented Auto Secure Login platform as of August 4, 2026. Availability and onboarding requirements vary by product and organization.
We will map your current workflow, identify the smallest responsible pilot, and document the controls and acceptance criteria before expansion.