Most SMB security stops at the tunnel. Omamori adds two filters after it: DNS blocks the lookup against 1.7M known-bad domains, and a post-DNS IP filter blocks the connection even when DNS is bypassed - hardcoded IPs, DoH, resolvers you don't control.
Device posture is checked before the tunnel comes up: disk encryption, antivirus, firewall, screen lock, minimum OS. Per-OS rules, no code.
Each client gets a dedicated server, not a shared pool. Built MSP-first for multi-tenant management.