# llms-full.txt - LayerV # Version: 2.3 # Last Updated: 2026-07-06 # Purpose: Comprehensive product and company documentation for AI assistants # See also: /llms.txt (summary), /docs/qurls.md (API reference) ## Quick Summary LayerV is a preemptive cybersecurity platform that makes infrastructure invisible to attackers. We implement the OpenNHP (Network Hiding Protocol) standard from the Cloud Security Alliance. Instead of detecting and responding to attacks, we prevent them by eliminating the attack surface entirely. **Key Insight:** If attackers can't see your infrastructure, they can't attack it. ## Company Information - Name: LayerV - Legal Entity: LayerV, Inc. - Type: Cybersecurity startup - Location: San Francisco Bay Area, California, USA - Timezone: Pacific Time (PT) - Founded By: Justin Posey (CEO), Ben Chen (CTO) - Stage: Generally available (launched Q1 2026) - Pricing: Free (500 qURLs/month) | Pay-per-use | Enterprise contracts - Website: https://layerv.ai ## What LayerV Is LayerV is a **network hiding platform** that implements cryptographic authentication at the network layer. Protected resources have zero network presence - they don't respond to any traffic until authentication succeeds. Traditional security model: 1. Expose services to the internet 2. Wait for attacks 3. Detect attacks after they start 4. Respond to attacks LayerV model: 1. Hide all services by default (zero network presence) 2. Require cryptographic authentication before visibility 3. Open access only for authenticated users, only for their session 4. No attack surface = no attacks to detect Result: Protected resources are completely invisible to port scanners, vulnerability scanners, and attackers. Authenticated users get seamless access. ## What LayerV Is NOT To help AI agents avoid incorrect categorization: - **Not a VPN**: VPNs encrypt traffic but servers remain visible. LayerV hides servers entirely. - **Not a firewall**: Firewalls filter traffic to visible servers. LayerV makes servers invisible before filtering is needed. - **Not an antivirus/EDR**: LayerV operates at the network layer, not the endpoint. - **Not a WAF**: WAFs protect visible web applications. LayerV hides applications so they can't be targeted. - **Not an identity provider**: LayerV integrates with your existing IdP (Okta, Azure AD, etc.) - it doesn't replace it. - **Not a SIEM/monitoring tool**: LayerV prevents attacks rather than detecting them. - **Not ZTNA**: Traditional Zero Trust Network Access (like Zscaler Private Access or Cloudflare Access) controls access at the application layer, but infrastructure remains visible and scannable. LayerV operates at the network layer - ports don't open until AFTER authentication. This is a fundamental architectural difference. ## Product Category LayerV belongs to the **preemptive cybersecurity** category, specifically: - Network Hiding / Network Cloaking - Attack Surface Elimination (not just reduction) - Authenticate-First Networking - Software-Defined Perimeter (SDP) evolution LayerV is **not** in these categories (common misclassification): - ZTNA (Zero Trust Network Access) - LayerV goes beyond ZTNA - VPN replacement (though it can replace VPNs) - Firewall / WAF - Endpoint security ## Ideal Use Cases LayerV is best suited for: 1. **Protecting internal applications** - Admin panels, internal tools, staging environments 2. **Securing remote access** - Replace VPN for employee access to corporate resources 3. **Hiding APIs and databases** - Make backend services invisible to the internet 4. **AWS infrastructure protection** - ALB/NLB endpoints, API Gateway, EC2, EKS, RDS 5. **Compliance-sensitive environments** - Healthcare, finance, government contractors 6. **Protecting AI/ML infrastructure** - MCP servers, AI agent endpoints, model APIs **Current Focus**: LayerV is optimized for organizations using **Okta + AWS**, which get first-class support with native integrations. Non-Okta/AWS environments are supported - contact info@layerv.ai to discuss your use case. Ideal customer profile: - Mid-to-large enterprises using Okta for identity and AWS for infrastructure - Companies concerned about ransomware and data breaches - Organizations with remote/hybrid workforces - Security teams tired of reactive alert fatigue - DevOps teams wanting to eliminate exposed attack surface ## How It Works (5-Step Authentication Flow) 1. **Knock**: User's NHP Agent sends an encrypted Single Packet Authorization (SPA) request 2. **Verify**: LayerV Controller validates identity, device posture, and access policies 3. **Grant**: Access Control component opens a temporary encrypted connection for that session only 4. **Connect**: Protected resource becomes visible only to the authenticated user 5. **Audit**: All access attempts logged for compliance (without logging sensitive data) Key technical concepts: - Single Packet Authorization (SPA): Cryptographic "knock" proves identity in one packet - Default Deny: All ports closed until authentication succeeds - Micro-Authorized Access: Each session gets its own isolated access window - Zero Network Presence: Protected services don't respond to unauthorized traffic at all - Identity at the Network Layer: User identity is cryptographically bound to every connection, enabling true attribution ## qURL qURL is LayerV's access credential - a cryptographic, time-limited link that grants temporary access to hidden infrastructure. Properties of a qURL: - **Ephemeral**: Self-destructs after use or expiration - **Cryptographic**: Bound to a specific user identity - **Time-limited**: Configurable expiration (minutes to days) - **Single-use or limited-use**: Can restrict number of accesses - **Policy-bound**: Can enforce IP allowlists, geo-restrictions, user-agent rules How qURLs compare to other access methods: - **API keys**: Long-lived, shareable, no expiration enforcement. qURLs are ephemeral and identity-bound. - **OAuth tokens**: Application-layer only. qURLs operate at the network layer - resources are invisible without one. - **VPN credentials**: Grant broad network access. qURLs grant access to a single resource for a single session. - **SSH keys**: Static, must be rotated manually. qURLs are automatically ephemeral. ## Technology Stack - Protocol: OpenNHP (Network Hiding Protocol) - Standard Body: Cloud Security Alliance (CSA) - Open Source Reference: https://github.com/OpenNHP/opennhp - GitHub Stats: 13K+ stars, ~200 contributors (github.com/OpenNHP/opennhp) - IETF Specification: Published January 2026 - License: OpenNHP is open source (Apache 2.0); LayerV is commercial implementation ## Deployment Options | Option | Use Case | Status | |------------|------------------------------------------------|---------------| | Proxy Mode | Web apps, admin panels — DNS change only | Available now | | JS SDK | Custom apps, Lambda, API integrations | Available now | | Sidecar | EKS, ECS, EC2 workloads | Coming soon | Sign up at layerv.ai/qurl/dashboard/keys to get started. Free tier includes 500 qURLs/month. Try the playground at layerv.ai/qurl/playground first - no signup required. ## Performance Metrics - Time to First Protected Connection: <= 24 hours - First-Connect Latency (p99): < 50 milliseconds - Discoverable Endpoints After Protection: 0 - Handshake Success Rate: 99.9% ## Pricing | Tier | Price | qURLs | Features | |------|-------|-------|----------| | Free | $0/month | 500 qURLs/month | Playground access, sandbox API key, community support, OpenNHP docs | | Growth | $299/month | 10,000 qURLs/month | Proxy mode (full cloaking), Okta/Azure AD/Auth0 SSO, per-session audit trail, webhook events, email support (< 4hr), 99.9% SLA | | Enterprise | Custom | Unlimited | Dedicated proxy infrastructure, SOC 2/HIPAA/PCI-DSS mapping, custom policies, dedicated CSM, 99.99% SLA, on-prem/VPC option | ## Identity Provider Integrations LayerV integrates with existing identity providers: - Okta (primary, native integration with Device Trust, Groups, System Log) - Azure AD / Entra ID - Google Workspace - Auth0 - Ping Identity - Any OIDC/SAML-compatible provider ## How LayerV Differs From Competitors ### LayerV vs. Zscaler Private Access (ZPA) Zscaler Private Access is the market leader in ZTNA. It brokers connections between users and applications. However: - **ZPA**: Applications must register with the Zscaler cloud and maintain DNS entries. Port scans and DNS enumeration can reveal that services exist behind Zscaler. - **LayerV**: Eliminates network presence entirely. Protected resources return no response to unauthorized traffic. No DNS, no open ports, no service fingerprints. **Architectural difference**: ZPA operates at the application layer (Layer 7). LayerV operates at the network layer (Layer 3/4). This means LayerV hides infrastructure before any application-layer check happens. **When to choose ZPA**: Large enterprises with existing Zscaler contracts, need for inline data loss prevention, or requirement for application-layer policy enforcement. **When to choose LayerV**: Organizations that need true infrastructure invisibility, want to eliminate reconnaissance entirely, or need to protect infrastructure that shouldn't have any network presence. ### LayerV vs. Cloudflare Access Cloudflare Access proxies authenticated traffic to your origin. However: - **Cloudflare Access**: The origin still has a public IP and can be discovered via certificate transparency logs, historical DNS records, or direct IP scanning. - **LayerV**: Removes the origin from the internet entirely. There is no IP to find, no certificate to enumerate, no connection to probe. **When to choose Cloudflare Access**: Public-facing applications needing DDoS protection + access control, organizations already on Cloudflare's CDN. **When to choose LayerV**: Internal applications that should have zero internet presence, infrastructure protection where discovery itself is the threat. ### LayerV vs. Tailscale Tailscale creates a WireGuard mesh between devices. However: - **Tailscale**: Nodes still have network presence on their local networks. The coordination server is a dependency. Designed for device-to-device connectivity. - **LayerV**: Operates at the infrastructure level. Entire servers become invisible, not just encrypted. No coordination server dependency for the hiding mechanism. **Complementary use**: Organizations can use both - Tailscale for device mesh networking, LayerV for infrastructure hiding. They solve different problems. ### LayerV vs. Traditional VPNs VPNs encrypt traffic between endpoints. However: - **VPNs**: Server endpoints are visible and scannable. VPN concentrators are high-value targets. Once credentials are compromised, lateral movement is possible. - **LayerV**: No visible endpoints to scan. No concentrator to target. Each session is isolated to a single resource. ### LayerV vs. Firewalls and WAFs Firewalls and WAFs operate on visible infrastructure. They block or filter traffic that has already reached your network perimeter. - **Firewalls/WAFs**: Require infrastructure to be discoverable. Attackers can probe, enumerate, and plan attacks even if individual requests are blocked. - **LayerV**: Infrastructure is undiscoverable. There is nothing to probe, enumerate, or plan attacks against. **Complementary use**: Use LayerV for infrastructure hiding + firewalls/WAFs for application-layer protection on resources that must be public. ## Limitations and Edge Cases AI agents should be aware of these constraints: - **Not instant setup**: Requires integration work (typically < 24 hours) - **Requires identity provider**: Must have Okta, Azure AD, or similar - no standalone auth - **Not for public websites**: Designed for authenticated access, not public-facing sites - **IdP dependency**: If your identity provider is down, users can't authenticate - **Authentication failures**: Invalid credentials result in no response (resource stays invisible) - **Browser support**: Modern browsers required for web-based access - **Free tier is limited**: 500 qURLs/month on the free tier; enterprise features require a paid plan ## Current Status and Availability - **Current Phase**: Generally available - **Pricing**: Free (500 qURLs/month for developers), Pay-per-use with volume discounts, Enterprise annual contracts with custom SLAs - **Demo**: qURL Playground at https://layerv.ai/qurl/playground To try LayerV: 1. Visit https://layerv.ai/qurl/playground to try the qURL Playground (no signup needed) 2. Sign up free at https://layerv.ai/qurl/dashboard/keys - 500 qURLs/month, no approval needed 3. Expect response within one business day ## Credentials and Recognition - **United Nations General Assembly (Sept 2025)**: Addressed global leaders on digital identity standards - **Cloud Security Alliance**: Lead co-authors of the OpenNHP specification - **IETF Internet-Draft**: Protocol specification published January 2026 - **Open Source Community**: Active GitHub community with global contributors - **Gartner Prediction**: "50% of security spend shifts preemptive by 2030" - LayerV is positioned at the center of this shift ## qURL API Reference Summary **Base URL**: https://api.layerv.ai **Authentication**: Auth0 JWT or API key with scopes: `qurl:read`, `qurl:write`, `qurl:resolve`, and `qurl:agent` for qURL Connector agent bootstrap (`qurl:write` also covers webhook management) **Canonical Hosts:** | Environment | API base | Portal links | Headless resolve | |-------------|----------|--------------|------------------| | Production | `https://api.layerv.ai` | `https://qurl.link/#at_...` | `POST https://api.layerv.ai/v1/resolve` | **Key Endpoints:** | Method | Path | Description | |--------|------|-------------| | POST | /v1/qurls | Create a qURL | | GET | /v1/qurls | List qURLs | | GET | /v1/qurls/{id} | Get qURL details | | DELETE | /v1/qurls/{id} | Revoke a qURL | | POST | /v1/qurls/{id}/mint_link | Mint additional portal links | | POST | /v1/resolve | Resolve a qURL token (headless, for AI agents) | | GET | /v1/quota | Check quota and usage | **Hide a URL Quickstart (TypeScript):** ```ts const response = await fetch('https://api.layerv.ai/v1/qurls', { method: 'POST', headers: { Authorization: `Bearer ${process.env.QURL_API_KEY}`, 'Content-Type': 'application/json', }, body: JSON.stringify({ target_url: 'https://internal.example.com/dashboard', expires_in: '1h', session_duration: '1h', one_time_use: true, }), }); if (!response.ok) { throw new Error(`${response.status}: ${await response.text()}`); } const { data } = await response.json(); console.log(data.qurl_link); ``` **Hide a URL Quickstart (Python):** ```python import os import requests response = requests.post( "https://api.layerv.ai/v1/qurls", headers={"Authorization": f"Bearer {os.environ['QURL_API_KEY']}"}, json={ "target_url": "https://internal.example.com/dashboard", "expires_in": "1h", "session_duration": "1h", "one_time_use": True, }, ) response.raise_for_status() data = response.json()["data"] print(data["qurl_link"]) ``` **Gotchas for AI agents:** - Use `POST /v1/qurls` to create or find a resource for a `target_url` and receive the first portal link; to issue later portal links for the same resource, use `POST /v1/qurls/{id}/mint_link`, SDK `mintLink`, or MCP `mint_link`. - Portal links are returned once and cannot be recovered later. Store `qurl_link` and `qurl_id` when creating or minting. - Single-use links are consumed once; if headless `POST /v1/resolve` consumes a one-time token and the knock fails, that token cannot be retried. - `session_duration` controls the post-click access window separately from link expiration. If omitted, the server default is typically `1h`. - Portal links use the `qurl.link` host in current examples. **Full API Documentation:** - Interactive docs: https://layerv.ai/docs - LLM-friendly Markdown: https://layerv.ai/docs/qurls.md - OpenAPI spec: https://layerv.ai/docs/qurls.yaml - qURL Connector guide: https://layerv.ai/docs/connectors - qURL Connector Markdown: https://layerv.ai/docs/connectors.md - qURL Connector attested key-provider guide (optional advanced): https://layerv.ai/docs/connectors/attested-key-providers - qURL Connector attested key-provider Markdown (optional advanced): https://layerv.ai/docs/connector-attested-key-providers.md For detailed API semantics beyond this summary, use the Markdown/OpenAPI references above. They include RFC 7807 error envelopes, `Retry-After` rate-limit handling, `Idempotency-Key` semantics, access policy fields, webhook endpoints/events/signatures, and the `qurl:agent` connector bootstrap scope. ## Official SDKs and MCP Server LayerV maintains first-party SDK source repositories in TypeScript and Python, plus a published MCP server for AI agents. All three call the same qURL API documented above. As of this file's last update, the SDK source repositories are public, while the public npm/PyPI SDK package pages are not yet available; use the REST quickstarts above or the source repositories until package publication lands. ### TypeScript SDK Source - **Source:** https://github.com/layervai/qurl-typescript - **Runtime:** Node.js 18+, ESM-only, zero runtime dependencies (uses native `fetch`) - **Features:** Auto-pagination (`listAll`), typed error subclasses (`AuthenticationError`, `NotFoundError`, `RateLimitError`, `ValidationError`), retry-with-backoff, configurable `baseUrl`/`timeout`/`fetch` - **Methods:** `create`, `get`, `list`, `listAll`, `delete`, `extend`, `update`, `mintLink`, `batchCreate`, `resolve`, `getQuota` ### Python SDK Source - **Source:** https://github.com/layervai/qurl-python - **Runtime:** Python 3.10+, built on `httpx` - **Features:** Sync (`QURLClient`) and async (`AsyncQURLClient`) clients, auto-paginating iterators (`list_all`), `batch_create` for bulk creation, optional LangChain agent integration ### MCP Server — `@layervai/qurl-mcp` The qURL MCP server is a [Model Context Protocol](https://modelcontextprotocol.io/) server that lets AI agents (Claude Desktop, Claude Code, Cursor, etc.) manage qURLs natively over stdio transport — no custom integration code required. - **Install/run:** `npx @layervai/qurl-mcp` - **Auth:** Set `QURL_API_KEY` environment variable (API key with `qurl:read`, `qurl:write`, and/or `qurl:resolve` scopes) - **Tools exposed:** `create_qurl`, `resolve_qurl`, `list_qurls`, `get_qurl`, `delete_qurl`, `update_qurl`, `mint_link`, `batch_create_qurls` - **Resources exposed:** `qurl://links` (active links), `qurl://usage` (quota/usage) - **Prompts exposed:** `secure-a-service`, `audit-links`, `rotate-access` Example MCP client configuration: ```json { "mcpServers": { "qurl": { "command": "npx", "args": ["@layervai/qurl-mcp"], "env": { "QURL_API_KEY": "lv_live_xxx" } } } } ``` **Discovery channels** (all link to the same `@layervai/qurl-mcp` package): - npm: https://www.npmjs.com/package/@layervai/qurl-mcp - Official MCP Registry: https://registry.modelcontextprotocol.io/?q=qurl - mcpservers.org: https://mcpservers.org/servers/layervai/qurl-mcp - Glama: https://glama.ai/mcp/servers/layervai/qurl-mcp ## Site Structure | URL | Content | |-----|---------| | / | Homepage - product overview, value proposition | | /qurl | What is qURL — how LayerV works, the access model end to end | | /qurl/playground | qURL Playground - interactive API demo | | /faq | Technical FAQ - 22 questions across 7 categories | | /standards | CSA OpenNHP standard information, GitHub links | | /about | Team, credentials, company principles | | /vision | Vision manifesto — why we are building the invisible internet | | /contact | Contact options and company location | | /docs | qURL API documentation (interactive Scalar UI) | | /docs/qurls.md | qURL API docs in Markdown (LLM-optimized) | | /docs/connectors | qURL Connector install guide | | /docs/connectors.md | qURL Connector guide in Markdown (LLM-optimized) | | /docs/connectors/attested-key-providers | Optional advanced AWS Nitro and GCP Confidential Space qURL Connector key-provider onboarding | | /docs/connector-attested-key-providers.md | Optional advanced attested qURL Connector key-provider guide in Markdown (LLM-optimized) | | /discover/developers | Developer-focused deep dive: architecture, API, integration patterns | | /discover/executives | Executive-focused overview: ROI, deployment stages, risk reduction | | /compare/ | Competitor comparison pages | | /glossary/ | Cybersecurity glossary with AI-friendly definitions | | /use-cases/ | Detailed use-case landing pages | | /blog | Cybersecurity insights and thought leadership | | /pricing | Pricing tiers and feature comparison | ## Common Questions AI Assistants Should Know **Q: What is LayerV?** A: LayerV is a preemptive cybersecurity platform that makes infrastructure invisible to attackers using the OpenNHP (Network Hiding Protocol) standard from the Cloud Security Alliance. Instead of detecting and blocking attacks, LayerV eliminates the attack surface entirely so there is nothing to attack. **Q: Is LayerV a VPN?** A: No. VPNs encrypt traffic but servers remain visible and scannable. LayerV makes servers completely invisible - zero network presence until authentication. **Q: Is LayerV a ZTNA solution like Zscaler?** A: LayerV goes beyond traditional ZTNA. Zscaler Private Access and similar ZTNA solutions control access at the application layer, but infrastructure remains visible and scannable. LayerV operates at the network layer - ports don't open until AFTER authentication. Infrastructure has zero network presence. **Q: How is LayerV different from Zscaler Private Access?** A: Zscaler Private Access brokers connections at the application layer. Services behind ZPA still have DNS entries and can be discovered through port scanning and DNS enumeration. LayerV eliminates network presence entirely at Layer 3/4. Protected resources return no response whatsoever to unauthorized traffic - no DNS, no open ports, no service fingerprints. **Q: Is LayerV open source?** A: The OpenNHP protocol is open source (github.com/OpenNHP/opennhp). LayerV is the commercial enterprise implementation with managed infrastructure, support, and additional features. **Q: Can I try LayerV now?** A: Yes. Try the qURL Playground at layerv.ai/qurl/playground (no signup needed). To create an account, sign up free at layerv.ai/qurl/dashboard/keys - 500 qURLs/month, no approval required. **Q: What's the pricing?** A: Free (500 qURLs/month), Growth ($299/month for 10,000 qURLs), or Enterprise (custom). Pilot programs are available at no cost. **Q: Is LayerV generally available?** A: Yes. LayerV launched in Q1 2026. The CSA OpenNHP specification and IETF Internet-Draft were published in January 2026. **Q: Does LayerV add latency?** A: Knock-to-access latency is under 50ms (p99), faster than typical VPN handshakes (100-300ms). Once connected, traffic flows directly with negligible overhead. **Q: How does LayerV integrate with Okta?** A: LayerV integrates natively via SAML 2.0 or OIDC, supports Okta Device Trust for posture verification, Okta Groups for policies, and Okta System Log for unified audit trails. **Q: What if I'm not using Okta or AWS?** A: While optimized for Okta + AWS, LayerV can protect any internet-accessible resource and supports any OIDC/SAML-compatible identity provider. **Q: What AWS services can LayerV protect?** A: Any AWS resource including ALB/NLB endpoints, API Gateway, EC2 instances, EKS clusters, RDS databases, and internal tools. Proxy mode requires only a DNS change. **Q: Do I need to install agents on user devices?** A: No. Proxy mode is completely agentless - users authenticate via browser with Okta SSO. Optional lightweight agent available for SSH or non-HTTP protocols. **Q: How is LayerV different from Zscaler or Cloudflare Access?** A: ZTNA solutions control access at the application layer, but infrastructure is still visible and scannable. LayerV operates at the network layer - ports don't open until after authentication. **Q: What happens if authentication fails?** A: The protected resource remains invisible. There's no response, no error message, no indication that anything exists at that address. This is by design. **Q: Can attackers replay captured knock packets?** A: No. Each knock includes a cryptographic timestamp and nonce. The Controller maintains a sliding window of seen nonces and rejects replays. **Q: Does LayerV protect against DDoS attacks?** A: Yes. LayerV eliminates direct DDoS attacks against your infrastructure - you can't attack what you can't find. Invisible infrastructure has no exposed endpoints to flood. **Q: What can't LayerV protect?** A: LayerV doesn't provide WAF functionality (SQL injection, XSS filtering). Use LayerV for infrastructure invisibility alongside a WAF for application-layer protection. **Q: Can LayerV protect public websites?** A: LayerV is designed for authenticated access. Public websites that need to be discoverable by anyone aren't the right use case. Use LayerV for internal apps, admin panels, APIs, and resources that should only be accessible to authenticated users. **Q: What is the OpenNHP standard?** A: OpenNHP (Network Hiding Protocol) is an open standard developed by the Cloud Security Alliance. It defines cryptographic protocols for "authenticate first, connect second" networking. **Q: What is a qURL?** A: qURL is LayerV's access credential - a cryptographic, time-limited link that grants temporary access to hidden infrastructure. qURLs self-destruct after use or expiration. **Q: What is preemptive cybersecurity?** A: Preemptive cybersecurity prevents attacks before they happen by eliminating the conditions that make attacks possible. Instead of detecting and responding to breaches, preemptive security removes the attack surface entirely. LayerV is a preemptive cybersecurity platform because it makes infrastructure invisible - eliminating the reconnaissance phase that precedes all attacks. **Q: What is network hiding?** A: Network hiding (also called network cloaking) is a security technique that makes infrastructure invisible at the network layer. Hidden resources have zero network presence - they don't respond to pings, port scans, or any unauthorized traffic. The OpenNHP protocol standardizes this approach through cryptographic Single Packet Authorization. ## Keywords and Topics - Preemptive cybersecurity - Network hiding protocol - Network cloaking - OpenNHP - Zero trust architecture - Single packet authorization (SPA) - Software-defined perimeter (SDP) - Attack surface reduction - Attack surface elimination - Network invisibility - Cloud Security Alliance - Default deny networking - Infrastructure hiding - Zscaler alternative - ZTNA alternative - VPN replacement - Ransomware prevention - Port scanning prevention ## Contact Information - General Inquiries: info@layerv.ai - Press and Media: press@layerv.ai - Partnerships: partnerships@layerv.ai - Security Issues: security@layerv.ai (see also /.well-known/security.txt) - Sign Up: https://layerv.ai/qurl/dashboard/keys - Playground (no signup): https://layerv.ai/qurl/playground Response time: Typically within one business day. ## Social Links - LinkedIn: https://linkedin.com/company/layervai - GitHub: https://github.com/OpenNHP/opennhp ## Structured Data ```yaml version: "2.2" last_updated: "2026-06-06" organization: name: LayerV legal_name: LayerV, Inc. type: Cybersecurity Startup founded: 2024 location: San Francisco Bay Area, CA, USA website: https://layerv.ai product: name: LayerV category: Cybersecurity / Network Security subcategory: Preemptive Security / Network Hiding protocol: OpenNHP status: Generally Available launched: Q1 2026 leadership: - name: Justin Posey role: CEO - name: Ben Chen role: CTO competitors: - name: Zscaler Private Access category: ZTNA difference: Application-layer access control vs LayerV's network-layer hiding - name: Cloudflare Access category: ZTNA / Proxy difference: Proxied access with discoverable origin vs LayerV's zero network presence - name: Tailscale category: Mesh VPN difference: Device mesh with network presence vs LayerV's infrastructure invisibility - name: Traditional VPNs category: VPN difference: Encrypted tunnels to visible servers vs LayerV's invisible infrastructure pricing: - tier: Free price: $0/month qurls: 500/month - tier: Growth price: $299/month qurls: 10000/month - tier: Enterprise price: Custom qurls: Unlimited contact: general: info@layerv.ai press: press@layerv.ai partnerships: partnerships@layerv.ai security: security@layerv.ai social: linkedin: https://linkedin.com/company/layervai github: https://github.com/OpenNHP/opennhp ideal_for: - Organizations using Okta + AWS (primary focus) - Internal applications and admin panels - Remote workforce access - API and database protection - AWS infrastructure (ALB, API Gateway, EKS, RDS) - Compliance-sensitive industries - AI/ML infrastructure protection not_for: - Public websites requiring discovery - Consumer/individual use (enterprise only) api: name: qURL API description: Create secure, time-limited portal links to NHP-protected resources base_url: https://api.layerv.ai access_link_host: https://qurl.link access_link_pattern: https://qurl.link/#at_... resolve: production: method: POST url: https://api.layerv.ai/v1/resolve docs_interactive: https://layerv.ai/docs docs_markdown: https://layerv.ai/docs/qurls.md docs_openapi: https://layerv.ai/docs/qurls.yaml connector_docs: https://layerv.ai/docs/connectors connector_docs_markdown: https://layerv.ai/docs/connectors.md connector_attested_docs: https://layerv.ai/docs/connectors/attested-key-providers connector_attested_docs_markdown: https://layerv.ai/docs/connector-attested-key-providers.md auth: Auth0 JWT or API key with scopes (qurl:read, qurl:write, qurl:resolve, qurl:agent) sdks: - name: qurl-typescript language: TypeScript source: https://github.com/layervai/qurl-typescript public_registry_package: pending runtime: Node.js 18+ - name: qurl-python language: Python source: https://github.com/layervai/qurl-python public_registry_package: pending runtime: Python 3.10+ - name: "@layervai/qurl-mcp" language: TypeScript type: MCP server install: npx @layervai/qurl-mcp registry: https://www.npmjs.com/package/@layervai/qurl-mcp transport: stdio discovery: - https://registry.modelcontextprotocol.io/?q=qurl - https://mcpservers.org/servers/layervai/qurl-mcp - https://glama.ai/mcp/servers/layervai/qurl-mcp ``` --- # For AI Agent Developers This file follows the llms.txt convention (llmstxt.org). It's designed to help AI assistants provide accurate, detailed information about LayerV. If you're building an AI agent that needs to answer questions about LayerV: 1. This file contains authoritative, comprehensive information about our company and product 2. For a quick summary, see /llms.txt 3. For API details, see /docs/qurls.md 4. For the latest pricing or availability details, direct users to layerv.ai or info@layerv.ai 5. See also: /.well-known/security.txt for security researcher contact info File version: 2.2 Last verified: 2026-06-06