Zero Trust Access Assurance
Know who can reach what, and prove it.
MeshTransit connects your private infrastructure over WireGuard® and tells you exactly who can reach what, why, and since when. Share a resource with a partner without merging networks or renumbering a single address.
- Every access path explained
- Hash-chained audit evidence
- Overlapping address ranges welcome
Why MeshTransit
Connectivity is the starting point. Certainty is the product.
Plenty of tools connect devices. MeshTransit is built to answer what comes next: why a path exists, what a change would open, and whether you can prove it to an auditor.
- 01 · Understand
Every path explains itself
Pick two devices, a protocol and a port. MeshTransit answers allowed or blocked, names the rule, group, tag or shared resource behind it and the release in force.
- Policy Explain
- Access Graph
- 02 · Control safely
See the blast radius before you click
Adding a rule or revoking a share lists every connection it opens or closes. Workspace guardrails refuse a change that would break a principle, such as Vendor never reaching Production.
- Impact preview
- Guardrails
- 03 · Share, not merge
Share access, not networks
Offer one device to another organisation under a contract both sides approve, with ports, expiry and instant revocation. Their side picks the addresses, so identical ranges never collide.
- Trust Contracts
- Address sovereignty
- 04 · Prove
Evidence, not trust
Every rule, share, member and device change is sealed into a hash-chained audit stream. Export it and let an auditor verify the chain with an open tool, without asking us.
- Sealed audit trail
- Verifiable export
Policy Explain
Ask why. Get the rule, the release and the approver.
No more reading rule files to guess. Every answer names the exact chain of group, tag, rule or shared resource behind a connection, and what removing it would close.
- user group Engineering
- rule Engineering → tag postgres · tcp/5432
- approved by Minh, 3 Oct
Built differently
Not another flat network with a nicer dashboard.
Each pillar rests on an architecture decision made from the first line of code. They are hard to add later to a product designed around one network per company.
Product
Everything an admin needs, in one Console.
People, devices, rules and shares are managed in one place, and every change reaches devices as one consistent release.
- Visibility
Access Graph
A live map of every device, resource and share in a Network, with each edge showing the protocol and port it allows. Click an edge to see why.
- Policy
Groups and tags
Rules by user group, device group and tag. Membership changes reach devices at once, with no new release needed.
- Devices
Device lifecycle
Devices belong to a person or to the Workspace. Suspend, hand over, move or revoke one, and it leaves every map within seconds.
- People
Member lifecycle
Invite by email. Suspend someone to cut access instantly, or remove them and decide device by device what happens.
- Roles
Separation of duties
Owner, admin, network admin, IT admin, security admin, billing admin and auditor. Nobody grants more than they hold.
- Platform
Cloud or self-hosted, built for HA
Stateless replicas, PostgreSQL as the only authority and Redis for hints only. Run it with us or on your own Kubernetes with the Helm chart.
Who it is for
Built for teams whose access has to hold up to scrutiny.
MSPs and infrastructure operators
One isolated Network per customer, overlapping ranges included, and proof for each customer that nobody else reaches their systems.
Vendors and partners
Give an outsourcer, auditor or support engineer time-boxed access to one system through a Trust Contract, and revoke it in one click.
Teams preparing for audits
Answer “who can reach production?” with sealed, exportable evidence instead of screenshots and spreadsheets.
Mergers and joint ventures
Connect two organisations that both use 10.0.0.0/8 without renumbering either side.
What is next
From explaining access to proving it is enforced.
The next releases close the loop: what you intended, what each device received, and what it actually enforces.
- In development
Policy distribution status
For every device, the release it should run versus the release it has received, with alerts for devices that lag.
- In development
Time machine
Ask “at 10:00 last Tuesday, who could reach the database, and through which rule or share?” and get an answer you can export.
- In development
Enforcement proof from every device
The client reports a hash of the rules it actually enforces, so you can tell intended, delivered and enforced apart.
- In development
Least-privilege suggestions
Opt-in, header-only flow data shows rules nobody uses and ports wider than needed, with a suggested tighter rule.
- In development
Self-service sign-up
Sign in for the first time and get your own Workspace, with abuse limits built in.
- In development
More clients
The Linux client ships first. Windows, macOS and mobile clients are in development.
Questions teams ask first
How is MeshTransit different from other mesh VPNs?
Connecting devices is the starting point, not the product. MeshTransit answers the questions that come after: why can this device reach that one, what would a rule change open, who could reach the database last week. It also shares one device with another organisation without merging networks or renumbering, and revocation takes effect at once.
Can I share a server with another company without network peering?
Yes. You offer one device under a Trust Contract, both sides approve, and their devices reach only that device through an alias in their own address range. Identical address ranges on both sides are fine.
What happens when someone leaves the team?
Suspend them to cut access at once, or remove them and choose for each device whether it moves to the Workspace, goes to a colleague or is revoked. Their sessions, roles and enrollment keys end, and the audit trail keeps the history.
Can an auditor check the evidence without trusting you?
Yes. Audit exports carry the seal of every event and its link to the previous one. An open verification tool recomputes the chain from the exported fields alone and flags any edit, gap or reordering.
Which platforms are supported?
The first release ships a Linux client for Ubuntu 24.04 and 26.04 on amd64 and arm64. Windows, macOS and mobile clients are in development.
Can I host it myself?
Yes. The self-hosted edition runs one Workspace with many Networks on your own Kubernetes, with PostgreSQL and Redis, packaged as a Helm chart.
Stop guessing who can reach production.
Explain every path, share without merging, and keep the evidence.