The VPN your organization controls.
WireGuard-based tunnels with single sign-on, device management, and a gateway fleet you operate.
Built for teams that run their own infrastructure.
Private keys never leave the device
Each client generates its own keypair locally. The server registers public keys only; it never sees, logs, or stores the private half.
One identity
Sign in with Microsoft, Google, or Apple. Access ends the moment you revoke the account.
Organizations first
Members, roles, and devices are managed per organization, with immediate revocation.
A fleet you can see
Every gateway reports health, capacity, and active sessions. Drain one for maintenance without dropping the sessions already on it.
Native clients for every platform your team uses, managed from one console.
- iOS
- macOS
- Android
- Windows
Not set up yet? Request access.
No account needed — tell us about your team and we'll set it up.