Platform

Business VPN that people actually enjoy using

Give your global team secure access to internal apps and data — with none of the concentrator maintenance, dropped tunnels, or helpdesk tickets of a legacy VPN.

Global team laptops connected through one mesh to office and cloud

The same network, wherever the day takes you

Every employee gets the same private network at the office, at home, or on hotel wifi. No region-specific gateways, no client profiles per office, no "reconnect and pray". The tunnel is always on, silently roaming between wifi and LTE, and NAT is something the mesh solves for you — not a ticket you file.

devices — live
mei@corpMacBook · cafe LTE42 msDIRECT
sam@corpdesktop · office wire1 msDIRECT
ana@corpiPhone · home wifi18 msDIRECT
kiosk-02retail store · broadband31 msRELAY
ci-runnerdatacenter · wire4 msDIRECT
Direct peer-to-peer paths through almost any NAT; relay is the rare fallback.

Retire the appliance — and everything that came with it

Decommission your VPN concentrators. OpenVLAN is serverless from your point of view: nothing to patch, size, or fail over. The public endpoint you've been defending disappears entirely, the shared secret that lived in a spreadsheet gets revoked, and the "can't connect" ticket queue dries up on its own.

decommission — checklist
concentrator x3HA pair + sparerack unit 4POWERED OFF
vpn.corp:443public endpointinboundCLOSED
shared secretquarterly rotationspreadsheet.xlsxREVOKED
client profiles14 office configsper-siteDELETED
helpdesk"can't connect" ticketsthis month−73%
Most teams run both VPNs in parallel and cut over per-office in weeks.

Legacy VPN vs OpenVLAN

CapabilityLegacy VPN applianceOpenVLAN
Deployment timeWeeks of planning and hardwareMinutes per site
Public attack surfaceVPN endpoint exposed to internetNone — no inbound ports
Access rulesIP ranges and shared secretsUser and device identity
OffboardingManual cert revocationInstant via SCIM sync
Hardware maintenancePatches, capacity, HA pairsNothing to maintain
User experience"Reconnect and pray"Always-on, silent

Everything a business VPN should do

One identity-aware mesh replaces appliance clusters, per-office hardware, and shared credentials.

Same network anywhere

Office, home, hotel, plane — one network, no region-specific gateways or per-site profiles.

NAT & CGNAT traversal

Direct peer-to-peer paths form behind almost any NAT. No port forwarding, no tickets.

Silent roaming

Wifi to LTE mid-session without dropping a tunnel or re-typing a password.

Every OS your team uses

Windows, macOS, Linux, iOS, and Android clients with the same policy engine.

No public exposure

Publish internal apps to authorized users only. Nothing listens on a public IP to scan.

Always-on encryption

AmneziaWG-encrypted end to end — including the hotel wifi leg you don't trust.

ACL scopes per team

Finance and legal systems live in their own policy scope. Same client, separated permissions.

Scoped contractor access

Invites that grant exactly one project's resources and expire on the date you set.

Retire the appliance

Serverless from your point of view — nothing to patch, size, or fail over.

MDM rollout

MSI and PKG packages for silent mass deployment, config pushed centrally.

Flat multi-cloud overlay

VPCs, on-prem racks, and Kubernetes clusters all join one network reachable by name.

Instant offboarding

Disable the account in your IdP and network access dies with it, in seconds.

Questions and answers

Do users have to "connect" like a traditional VPN?
No. The client is always on after login. Devices join the network silently at boot and roam between networks without anyone clicking anything — there's no connect button to forget.
Will it slow my team down?
Traffic takes direct peer-to-peer paths at AmneziaWG speeds — usually faster than hauling everything through a concentrator in another region. A relay only appears when direct paths are impossible.
What about split tunneling?
It's the default: only private ranges route through the mesh, everything else stays on the local network at full speed. Route specific traffic through an exit node when you want the opposite.
Can contractors join without our SSO?
Yes — scoped invites let external collaborators join with email auth, limited to exactly the resources you name, expiring on the date you choose.
Can we run it alongside our existing VPN?
Yes, and most teams do during migration. Publish resources on the mesh while the old VPN keeps running, then cut over office by office at your own pace.
How is it priced?
Per user, with a free tier for personal and small team use. See the pricing page for plan details — infrastructure costs don't scale with traffic.
What if a user's device is lost or stolen?
Revoke the device from the admin console and it's off the network instantly. Keys on the device age out in minutes even if you never notice the loss.

Replace your legacy VPN this week

Start free, keep the old VPN running in parallel, and cut over when your team is ready.