Platform

AmneziaWG for enterprise

All of AmneziaWG's speed and cryptographic hygiene — with the identity, key management, and auditability your organization actually requires.

Why AmneziaWG won

~4,000 lines of code. Modern crypto, boringly applied. Connections that set up in milliseconds.

Fast

Kernel-speed performance and instant roaming between networks. No multi-second handshake dances.

Simple

A codebase small enough to audit in an afternoon — a feature, not a limitation.

Sound crypto

Curve25519, ChaCha20, Poly1305, BLAKE2s: conservative, well-reviewed primitives.

What enterprises still need

Raw AmneziaWG is a building block. OpenVLAN is the enterprise product built on it.

Identity & SSO

AmneziaWG keys are anonymous. OpenVLAN binds keys to users from your identity provider, with SCIM provisioning and offboarding that actually revokes access.

Key management

No manual key exchange over chat. Nodes authenticate once via your IdP; keys rotate automatically, invisible to users.

ACLs & policy

Point-to-point tunnels are all-or-nothing. OpenVLAN adds a policy layer: who may reach what, per port, per group — as code.

Audit & compliance

Flow logs, session recording, and configuration history export to your SIEM — SOC 2, ISO 27001, and HIPAA-friendly.

Comparison at a glance

AmneziaWG aloneOpenVLAN
EncryptionAmneziaWGAmneziaWG
IdentityStatic keysSSO/IdP + device identity
Access controlNone (all-to-all)ACLs as code, posture-aware
NAT traversalManualAutomatic, relay fallback
Audit logging—Flow logs + session recording
DeploymentPer-tunnel config filesOne login, fleet-wide

AmneziaWG was the hard part. We finished the job.