Customers

40,000 businesses choose OpenVLAN

From two-person startups to global enterprises — one network, zero appliances. Here's what changed for teams like yours.

Every story starts with the same stack of pain

Hardware concentrators, bastion hosts, shared SSH keys, firewall rules nobody dares delete. When we ask customers what they replaced, the inventory reads like a museum catalog — and the migration reads like spring cleaning.

  • ✓Nothing inbound to attack — nodes dial out, no public IPs
  • ✓Access follows identity from your existing IdP
  • ✓One audit log instead of a screenshot scramble
what 40,000 networks left behind
vpn concentratorsmaintenance contracts2×RETIRED
bastion hostsshared ssh keys14RETIRED
dmz appsscanned 24/70CLOSED
firewall tickets3-week change queue—GONE
identity meshsso + scim + auditliveACTIVE

Migration is weeks, not quarters

The pattern held across every story below: pilot for two weeks, production inside a month, the old appliance powered off the following quarter. No maintenance window, no forklift, no big-bang cutover weekend.

# the rollout every customer is a version of
week 1 connect IdP · pilot of ten
week 2 subnet router in the VPC
week 3 production, region by region
week 4 stragglers · old VPN frozen
quarter decommission · reclaim the rack
 
# the whole company kept working throughout

Read their stories

Seven teams, seven industries, one common ending.

What they have in common

They replaced something painful

Hardware VPNs, bastion hosts, shared SSH keys, "temporary" firewall rules from 2021.

They kept their identity provider

Access rules follow the same users and groups their IT team already manages.

They rolled out gradually

Pilot team → early adopters → whole company, with the old system running in parallel until confidence caught up.

NORTHWINDAcme LabsVertexBluefinQuantaHalcyonFerry

Company names and logos shown are illustrative examples for this demo site.

Customer story FAQs

How long does a typical migration take?
Pilot for two weeks alongside the old system, full rollout inside a month, decommission the following quarter. The teams above ran both networks in parallel the whole time — no maintenance windows, no cutover weekend.
Do we have to rip out the old VPN on day one?
No — and nobody does. The old VPN keeps running while pilot users move over. Most teams freeze it when ticket volume hits zero, then power it off when the lease renews or the rack space is needed.
What size team are these stories from?
From eight founders (Vertex) to 500+ staff across three continents (Bluefin). The mesh scales by adding devices, not headcount — the workflow that works at 10 people is the one that works at 5,000.
Can we talk to a customer in our industry before committing?
Yes. Contact sales and we'll arrange a reference call, or browse the filtered stories above for teams that look like yours. The community forum is also full of unedited rollout threads.
What if our environment is "too complicated" for a story like this?
Every team in this grid thought that too — three clouds, regulated finance, warehouse networks that block VPN protocols. Start with a pilot subnet and keep the old system running until the mesh proves itself.

Write the next case study

Your migration story starts with a free tailnet — or read the numbers first.