CONNECT
Reach anything. Expose nothing.
Bring a desktop, a database, a camera, a factory PLC, or a whole cluster onto your private mesh with one outbound-only command. No VPN, no firewall tickets, no open ports, and deny-by-default until you say who reaches it.
CONNECT SOMETHING
Three steps, no network ticket.
Pick what you are connecting, run one outbound-only command on the host (or scan a QR), and choose who is allowed to reach it. No inbound rule ever changes.
- 1
Pick an intent
Desktop, cloud VM, database, camera, factory OT, Kubernetes, or anything with a host and port.
- 2
Run one command
An outbound-only connector phones home. Scan the QR to enroll from a device.
- 3
Pick who reaches it
Map access to your existing roles. Everything else stays denied.
- Resource
- Location
- 3Reach
- 1 Location reachable ok
- 2 Service resolves ok
- 3 Endpoint answers ok
- 4 Guard applied ok
THE LIVE ENROLL MOMENT
Watch the host phone home.
The moment the connector starts, the console waits for it to reach out, then flips to connected. A built-in test walks the whole path end to end, four green hops, so you know it works before anyone relies on it.
PRIVATE BY DEFAULT
Private on the mesh, or public on purpose.
Keep a connection mesh-only so it is reachable exclusively inside your network, or publish an HTTPS link fronted by a Keycloak login guard. Access groups map to the roles you already have, and everything starts denied.
Mesh-only. Reachable exclusively from inside the mesh.
HTTPS, fronted by a Keycloak login guard.
Access groups
Sites
Bridges
A SELF-HEALING MESH
One console. A network that keeps itself true.
See every site, its status, and its bridges in one place. A reconciler runs continuously, converging the live network back to the intent you declared: re-enrolling, trapping stale routes, and cleaning up orphans on its own.
ZERO-TRUST BY CONSTRUCTION
Nothing is exposed to reach it.
Connectors dial out; you never open an inbound port or change a firewall. Access is deny-by-default and scoped to your existing roles. A connection is reachable only by exactly who you named.
- Outbound-only
- Hosts phone home. No inbound rule, no port forward, no VPN.
- Deny-by-default
- A new connection reaches no one until you grant access.
- Mapped to your roles
- Access groups resolve to the Keycloak roles you already manage.
CONNECT SOMETHING
Reach anything. Expose nothing.
Run one outbound-only command, pick who is allowed, and watch the four green hops confirm it end to end.