Neutralize the Chaos.

Control at the edge of your network.

One device inspects, routes and encrypts everything that passes.

What happens to your traffic

Segmentation stops lateral movement. Internal applications stop facing the internet. The SLA is held by a team you can call.

INTERNET Untrusted Web, mail App access Branch tunnel Scans, exploits IXOLATE SG Single control point INSPECT IDS/IPS, DNS, reputation ROUTE Multi-WAN, OSPF/BGP TUNNEL IPsec, WireGuard YOUR NETWORK Segmented, not flat SERVERS VLAN 10 Office & tunnel only OFFICE VLAN 20 Egress inspected IOT & GUEST VLAN 30 No path to servers BRANCH No public IP INTERNET Untrusted Web, mail App access Branch tunnel Scans, exploits IXOLATE SG Single control point INSPECT IDS/IPS, DNS, reputation ROUTE Multi-WAN, OSPF/BGP TUNNEL IPsec, WireGuard YOUR NETWORK Segmented, not flat SERVERS VLAN 10 Office & tunnel only OFFICE VLAN 20 Egress inspected IOT & GUEST VLAN 30 No path to servers BRANCH No public IP
Colour means one thing across this whole site
RoutedEncryptedInspectedDenied
ISPs & WISPs, SMB & enterprise, government & state firms, campus & schools, NGOs, MSPs & integrators

What changes in the first week

Not a feature list. Four changes you can verify yourself once the device is running.

Internal apps leave the internet

Access arrives through an encrypted tunnel. Ports that used to face the public are closed, RDP and admin panels included.

Lateral movement stops at the VLAN edge

Cameras, IoT and guest networks have no path to servers. One compromised device no longer drags the rest with it.

A link drops, sessions stay up

Multi-WAN moves traffic to the backup link. The HA pair takes over with a state table already in sync.

Every change leaves a trail

Rule changes and updates are recorded on the device with time, actor and result. Ready to collect at audit time.

The responsibility line

Networks rarely fail because of the box you bought. They fail because nobody knows who moves. We write that down before anything is signed.

You own
  • Business policy: who may reach what
  • The hardware, except on our appliance model
  • WAN links and the relationship with your ISP
  • The final call on any risky change
We own
  • Gateway software, configuration and hardening
  • Security updates and major version moves
  • Incident investigation within your tier hours
  • Network documentation that still matches reality

The line moves during the assessment. An ISP with hundreds of CPEs does not carry the same split as a single campus.

Available now

Three things you can contract today. Three more are being built, and we say so plainly.

  • Support & SLA contract

    Two tiers. Service hours, response targets and coverage in writing. Major version moves stay on our side.

    See the tiers →
  • Business license

    Opens the business edition update path. Bound to the hardware. Offline activation, no device phoning out.

    How it works →
  • Deployment & migration

    One-time. Segmentation design, migration off the old box, failover tested, handover documentation.

    See the scope →
Being built
  • Appliance

    A ready unit, configured before it ships.

    Waitlist →
  • Managed NOC

    We operate it: monitoring, changes, incidents, monthly reporting.

    Talk it through →
  • Security Operations

    Central logs, detection and threat intelligence on top of deployed gateways.

    Talk it through →

Four steps, no surprises

  1. 01

    Assessment

    Free. We map topology, sites, load and compliance obligations. The output is a written read, not a quote.

  2. 02

    Design & quote

    Segmentation, redundancy, the tier that fits. Numbers appear here, once the scope is real.

  3. 03

    Deployment

    Staged migration. Agreed change windows. A rollback plan before any button is pressed.

  4. 04

    Kept running

    Updates, monitoring per tier, incident investigation. Major version moves get scheduled, never sprung on you.

Why there is no price list

A clinic with twenty users and an ISP with three hundred CPEs can run the same device. The cost of that device stopping is nowhere near the same, and neither is the coverage we have to carry. The assessment is free and the number follows once the scope is real. If it turns out you do not need us yet, that is a valid answer too.

Start from the network you have now

Send the topology as it is. A sketch on paper is enough. You get a written read and a next step.