One private network,every device on it.

An encrypted WireGuard mesh that connects your team, servers and services as if they shared a LAN — access granted by identity, reachable from anywhere, off the public internet.

Mesh

Every device, directly connected.

Laptops, phones and servers form one encrypted WireGuard mesh automatically — no gateway to bottleneck, no routes to maintain, no public IPs to expose.

  • Direct, encrypted tunnels between every device.
  • No gateway, no single point of failure.
  • On-prem, cloud and home labs on one network.

Access

Access by identity, not IP.

Write access rules in terms of people and roles — engineers to production, everyone to the wiki — and revoke a device the moment you need to. Nothing is reachable unless a rule says so.

  • Grant and revoke by person and role, in one click.
  • Default-deny: nothing reachable without a rule.
  • A log of who reached what, and when.

Capabilities

A network your firewall wishes it was.

Private, identity-aware connectivity for your whole team and fleet — without the legacy VPN pain.

Zero-config mesh

Devices and servers form an encrypted mesh automatically — no gateways, no static routes to maintain.

Identity-based access

Grant access by person and role, not by IP — revoke a device in one click.

WireGuard fast

Built on WireGuard for a fast, modern tunnel that barely touches your battery or throughput.

Private services

Reach databases, dashboards and internal tools as if you were on the same LAN — off the public internet.

Every device

Laptops, phones, servers and CI runners on one network, across every OS.

Access logs

See who connected to what, and when — an audit trail for every session.

Get started

Connected in three steps.

1

Install the agent

One command or app per device. It joins your private network in seconds.

2

Set who reaches what

Write access rules by person and role — engineers to prod, everyone to the wiki.

3

Connect from anywhere

Your team reaches internal services securely, on any network, as if on the LAN.

Pricing

Pricing by the people on it.

Prices in USD, shown in your currency via the switcher above. Billing is monthly, cancel anytime.

Personal

For solo and small setups.

$4/mo
Get started
  • Up to 5 devices
  • Full encrypted mesh
  • WireGuard tunnels
  • 1 admin
  • Community support
Most popular
Team

For growing teams.

$10/user/mo
Get started
  • Unlimited devices
  • Identity-based access rules
  • Access logs
  • SSO (Google)
  • Priority support
Enterprise

For security and scale.

Custom
Talk to sales
  • SCIM & SSO
  • Device posture checks
  • Audit export & SIEM
  • SLA & 24/7 support
  • Dedicated onboarding

FAQ

Questions, answered.

What is a mesh VPN?
Instead of routing everything through one gateway, every device connects directly and securely to the others it is allowed to reach. It's faster, has no single choke point, and needs no manual routes.
What is it built on?
WireGuard, a modern, audited, high-speed tunnel. It's light on battery and throughput, so the network stays fast even on mobile.
How is access controlled?
By identity, not IP. You write rules in terms of people and roles — 'engineers can reach prod' — and revoke a person or device in one click. Nothing is reachable unless a rule allows it.
Can I reach on-prem or another cloud?
Yes. Run the agent on a server in any network — a data centre, another cloud, a home lab — and it becomes reachable to whoever your rules allow, no public IP required.
Do you keep logs?
We record connection metadata — who connected to what, and when — for your audit trail. We do not inspect the encrypted traffic itself.

Ready when you are.

Create an account and launch your first product in minutes — or talk to our team about a managed setup for your business.