Solutions

Enterprise networking without the enterprise project

The same mesh that powers homelabs runs your organization — with SSO, SCIM, audit export, network-as-code, and a support team that answers.

IdP connected on Monday, VPN decommissioned this quarter

The enterprise requirements — SSO, SCIM, audit export, network-as-code — are checkboxes, not integration projects. Point it at your IdP, push the client, and start migrating sites. The rollout is measured in weeks because the hard parts are organizational, never technical.

  • ✓SAML/OIDC with any major IdP, SCIM included
  • ✓Terraform + GitOps for every policy change
  • ✓Migration support from legacy VPN & PAM included
rollout — enterprise timeline
week 1IdP + SCIM · admin training✓DONE
weeks 2–4subnet routers · pilot users✓DONE
quarterlegacy VPN off · PAM consolidation62%ON TRACK

Your data stays where regulation says it must

Regional coordination planes keep control traffic in-jurisdiction, and a self-hosted controller option exists for the strictest regimes. Either way, payload traffic never transits our infrastructure — it flows device-to-device, encrypted end-to-end.

residency — coordination planes
eu-westFrankfurt · GDPRin-regionACTIVE
us-eastVirginiain-regionACTIVE
self-hostedyour DC · your keysair-gappedOPTION

Built for the requirements list

SSO & SCIM

Join any SAML/OIDC IdP; users and groups sync automatically. Deprovisioning revokes access in seconds.

Audit & compliance exports

Connection logs, policy changes, and admin actions — streamed to your SIEM or retained per your schedule.

Network as code

Terraform provider, GitOps workflows, and CI validation for every policy change. Reviewable, revertible, provable.

Session recording

Capture privileged SSH and database sessions for investigation and compliance review.

Data residency options

Regional coordination planes and a self-hosted controller option where regulation demands it.

SLA & support

99.99% target uptime with credits, a dedicated support engineer, and shared escalation channels.

Procurement-ready

  • ✓Security questionnaires answered from a public trust center
  • ✓Standard DPAs and subprocessor lists
  • ✓Annual third-party penetration tests with summaries available under NDA
  • ✓Invoice billing, POs, and vendor onboarding paperwork
  • ✓Migration support from legacy VPN and PAM vendors

Typical rollout

Week 1: IdP + SCIM connected, admin training. Weeks 2–4: site-by-site subnet routers, pilot users. Quarter: legacy VPN decommissioned, PAM consolidation begins. Your mileage will vary — that's what the scoping call is for.

Start the conversation →

Enterprise FAQs

What does pricing look like at org scale?
Seat-based with volume tiers, device-only nodes priced separately and much cheaper. Most enterprises land between the quoted list and a negotiated rate after a scoping call — the calculator on the pricing page gets you in the ballpark.
Can we run the control plane ourselves?
Yes — the self-hosted controller option runs in your data center or cloud account. You keep the coordination keys; we keep shipping you updates. It's the escape hatch regulated industries usually ask about first.
What's the actual SLA?
99.99% target on coordination services with service credits, plus a dedicated support engineer and a shared escalation channel on the enterprise plan. Data-plane outages don't take the network down — devices keep talking even if coordination hiccups.
How does vendor risk review usually go?
Fast, by design: public trust center, standard DPAs, subprocessor lists, SOC 2 report, and pen test summaries under NDA. Most security questionnaires are answered from published material.
We're mid-way through a PAM rollout — replace or coexist?
Coexist, then consolidate. OpenVLAN handles the session layer your PAM tool sits on; most teams keep the vault, retire the bastions, and let sessions ride the mesh with recording intact.

Bring your requirements list

We've seen it. Let's compare notes.