The VPN your organization controls.
WireGuard-based tunnels with single sign-on, device management, and a gateway fleet you operate.
Built for teams that run their own infrastructure.
Private keys never leave the device
Each client generates its own keypair locally. The server registers public keys only; it never sees, logs, or stores the private half.
pub: xTIBA5rboUvnH4htodjb6e697QjLERt1NAB4mZqp8Dg=
One identity
Sign in with Microsoft, Google, or Apple. Access ends the moment you revoke the account.
Organizations first
Members, roles, and devices are managed per organization, with immediate revocation.
A fleet you can see
Every gateway reports health, capacity, and active sessions. Drain one for maintenance without dropping the sessions already on it.
Native clients for iOS, macOS, Android, and Windows, all managed from one console.