VPNNet
Zero trust networking. On an instance that's yours alone.
VPNNet connects your people, servers, and sites in a private WireGuard mesh with zero trust access controls, built on the open-source NetBird platform. The difference: every company gets its own dedicated instance. Your control plane, your keys, your network. Not a tenant in someone else's cloud.
- laptop · jane@acme connected
- hq-fileserver connected
- plant-2 gateway connected
- contractor · temp access expires in 6 days
- policy: finance → erp only enforced
Every device authenticated. Every connection encrypted. Every rule yours.
The Problem
The VPN you have. The SaaS you're offered.
The traditional company VPN is a single door with a long hallway behind it: one concentrator, full network access once you're in, and a performance tax on every packet. One stolen credential and the whole hallway is open.
The modern alternative (mesh VPN as SaaS) fixes the architecture but introduces a different dependency: your network's brain lives in someone else's multi-tenant cloud, alongside thousands of other companies, on their terms and their outage schedule.
Zero trust shouldn't stop at your devices. It should include your control plane.
How it works
Sign up. Your instance spins up. Connect everything.
-
1. Your company signs up
Tell us who you are. No network redesign, no hardware order, no consultants required.
-
2. We spin up your dedicated instance
A NetBird control plane that belongs to your company alone: your own management console, your own identity integration, isolated from every other customer.
-
3. Enroll devices and set policy
Laptops, servers, cloud VMs, site gateways. They form an encrypted peer-to-peer mesh, and your access policies decide exactly who reaches what.
-
4. We keep it running
Updates, monitoring, and care of the platform are on us. The network and its rules stay yours.
Link your networks
Full mesh between sites. No static IPs to rent.
The old way to connect offices meant business-class circuits, a static IP at every site, and tunnels hair-pinned through headquarters. VPNNet retires all three.
Each site gets a small gateway box. Drop it on the network, plug it into any spare switch port, and it goes to work. It dials out, like any laptop on the network, so you keep your existing router and firewall from whatever vendor you already have: no replacement hardware, no inbound firewall rules, no port forwarding.
Your instance introduces the peers to each other, they punch through NAT, and the sites connect directly to one another over encrypted WireGuard tunnels. Traffic between the branch and the cloud never detours through headquarters, and headquarters going down doesn't cut anyone off. That's a mesh, not a hub and spokes.
Because every connection starts outbound, ordinary internet service is enough: cable, fiber, LTE, satellite, whatever each site happens to have, from any provider. Dynamic IPs are fine, since peers find each other through your instance, not at a fixed address. No static IPs to lease, and no business-class circuit requirement.
The honest fine print: on the rare connection where NAT is too hostile for a direct path (some carrier-grade NATs), traffic falls back to an encrypted relay. Still end-to-end encrypted, still policy-controlled. We just don't pretend otherwise.
What you get
Modern networking, without the fine print.
WireGuard mesh
Fast, modern encryption with direct peer-to-peer paths. No hairpinning through a distant concentrator.
Zero trust access
Identity-based policies per user, group, and resource. Access to what's allowed, nothing else.
Dedicated instance
Your own control plane, not a shared tenant. Isolation by architecture, not by promise.
Open-source foundation
Built on NetBird. Auditable code, no proprietary lock-in, and an exit path that keeps your network intact.
Managed for you
Provisioning, upgrades, and monitoring handled by people who run never-fail networks for a living.
Works everywhere
Drop-in gateway boxes for sites, clients for every major platform. Offices, clouds, plants, and laptops in one mesh.
Why dedicated
Multi-tenant is their architecture. Not yours.
When your network's control plane is shared, you inherit everyone else's blast radius: their outages, their noisy neighbors, their breach headlines. A dedicated instance means your network's brain answers to one company. Yours.
It also means real answers to the questions your auditors and customers ask: where the data lives, who can touch it, and what happens when you want to leave.
Be first on the list.
VPNNet is onboarding early access companies now. Tell us about your network and we'll tell you when your instance can be ready.