Zero Trust Access Assurance

Know who can reach what, and prove it.

MeshTransit connects your private infrastructure over WireGuard® and tells you exactly who can reach what, why, and since when. Share a resource with a partner without merging networks or renumbering a single address.

  • Every access path explained
  • Hash-chained audit evidence
  • Overlapping address ranges welcome

Why MeshTransit

Connectivity is the starting point. Certainty is the product.

Plenty of tools connect devices. MeshTransit is built to answer what comes next: why a path exists, what a change would open, and whether you can prove it to an auditor.

  1. 01 · Understand

    Every path explains itself

    Pick two devices, a protocol and a port. MeshTransit answers allowed or blocked, names the rule, group, tag or shared resource behind it and the release in force.

    • Policy Explain
    • Access Graph
  2. 02 · Control safely

    See the blast radius before you click

    Adding a rule or revoking a share lists every connection it opens or closes. Workspace guardrails refuse a change that would break a principle, such as Vendor never reaching Production.

    • Impact preview
    • Guardrails
  3. 03 · Share, not merge

    Share access, not networks

    Offer one device to another organisation under a contract both sides approve, with ports, expiry and instant revocation. Their side picks the addresses, so identical ranges never collide.

    • Trust Contracts
    • Address sovereignty
  4. 04 · Prove

    Evidence, not trust

    Every rule, share, member and device change is sealed into a hash-chained audit stream. Export it and let an auditor verify the chain with an open tool, without asking us.

    • Sealed audit trail
    • Verifiable export

Policy Explain

Ask why. Get the rule, the release and the approver.

No more reading rule files to guess. Every answer names the exact chain of group, tag, rule or shared resource behind a connection, and what removing it would close.

Why canlan-laptopreachdb-prod:5432?
Allowedrelease 42
  1. user group Engineering
  2. rule Engineering → tag postgres · tcp/5432
  3. approved by Minh, 3 Oct
Revoking the rule closes 14 connectionssealed · 0x9f3a…

Built differently

Not another flat network with a nicer dashboard.

Each pillar rests on an architecture decision made from the first line of code. They are hard to add later to a product designed around one network per company.

The common approachMeshTransit
One flat network and one global rule file per companyMany isolated Networks per Workspace, each with its own addresses, DNS, rules and admins
Every device keeps one address everywhere; sharing a device exposes that addressOverlapping ranges are allowed; a shared device gets an alias inside the receiver’s own address space
Rules take effect straight from the editorRules compile into immutable releases you can simulate, approve and trace in the audit chain
Sharing is a toggle on a deviceSharing is a contract with terms, expiry and an approver on each side, revoked at once
Logs say what an admin clickedSealed evidence answers who could reach what, through which rule, and since when

Product

Everything an admin needs, in one Console.

People, devices, rules and shares are managed in one place, and every change reaches devices as one consistent release.

  • Visibility

    Access Graph

    A live map of every device, resource and share in a Network, with each edge showing the protocol and port it allows. Click an edge to see why.

  • Policy

    Groups and tags

    Rules by user group, device group and tag. Membership changes reach devices at once, with no new release needed.

  • Devices

    Device lifecycle

    Devices belong to a person or to the Workspace. Suspend, hand over, move or revoke one, and it leaves every map within seconds.

  • People

    Member lifecycle

    Invite by email. Suspend someone to cut access instantly, or remove them and decide device by device what happens.

  • Roles

    Separation of duties

    Owner, admin, network admin, IT admin, security admin, billing admin and auditor. Nobody grants more than they hold.

  • Platform

    Cloud or self-hosted, built for HA

    Stateless replicas, PostgreSQL as the only authority and Redis for hints only. Run it with us or on your own Kubernetes with the Helm chart.

Who it is for

Built for teams whose access has to hold up to scrutiny.

  • MSPs and infrastructure operators

    One isolated Network per customer, overlapping ranges included, and proof for each customer that nobody else reaches their systems.

  • Vendors and partners

    Give an outsourcer, auditor or support engineer time-boxed access to one system through a Trust Contract, and revoke it in one click.

  • Teams preparing for audits

    Answer “who can reach production?” with sealed, exportable evidence instead of screenshots and spreadsheets.

  • Mergers and joint ventures

    Connect two organisations that both use 10.0.0.0/8 without renumbering either side.

What is next

From explaining access to proving it is enforced.

The next releases close the loop: what you intended, what each device received, and what it actually enforces.

  • In development

    Policy distribution status

    For every device, the release it should run versus the release it has received, with alerts for devices that lag.

  • In development

    Time machine

    Ask “at 10:00 last Tuesday, who could reach the database, and through which rule or share?” and get an answer you can export.

  • In development

    Enforcement proof from every device

    The client reports a hash of the rules it actually enforces, so you can tell intended, delivered and enforced apart.

  • In development

    Least-privilege suggestions

    Opt-in, header-only flow data shows rules nobody uses and ports wider than needed, with a suggested tighter rule.

  • In development

    Self-service sign-up

    Sign in for the first time and get your own Workspace, with abuse limits built in.

  • In development

    More clients

    The Linux client ships first. Windows, macOS and mobile clients are in development.

Questions teams ask first

How is MeshTransit different from other mesh VPNs?

Connecting devices is the starting point, not the product. MeshTransit answers the questions that come after: why can this device reach that one, what would a rule change open, who could reach the database last week. It also shares one device with another organisation without merging networks or renumbering, and revocation takes effect at once.

Can I share a server with another company without network peering?

Yes. You offer one device under a Trust Contract, both sides approve, and their devices reach only that device through an alias in their own address range. Identical address ranges on both sides are fine.

What happens when someone leaves the team?

Suspend them to cut access at once, or remove them and choose for each device whether it moves to the Workspace, goes to a colleague or is revoked. Their sessions, roles and enrollment keys end, and the audit trail keeps the history.

Can an auditor check the evidence without trusting you?

Yes. Audit exports carry the seal of every event and its link to the previous one. An open verification tool recomputes the chain from the exported fields alone and flags any edit, gap or reordering.

Which platforms are supported?

The first release ships a Linux client for Ubuntu 24.04 and 26.04 on amd64 and arm64. Windows, macOS and mobile clients are in development.

Can I host it myself?

Yes. The self-hosted edition runs one Workspace with many Networks on your own Kubernetes, with PostgreSQL and Redis, packaged as a Helm chart.

Stop guessing who can reach production.

Explain every path, share without merging, and keep the evidence.