Self-hosted Zero Trust VPN.

Connect everything. Trust nothing.

$curl -fsSL https://get.tunnex.io | sh

Linux runs the full stack. macOS runs a portable control plane and uses a separate Linux gateway.

Tunnex access plane: humans, workloads, and AI agents reaching named destinations through one policy boundary Three principals on the left (human, workload, and AI agent) connect through a single central policy core to five destinations on the right: servers, databases, Kubernetes, internal APIs, and an MCP server. One principal and one destination are highlighted at a time.HUMANWORKLOADAI AGENTSERVERSDATABASESKUBERNETESINTERNAL APISMCP SERVER
SSO-verified people, device-bound tunnels
Granular server access with ephemeral credentials
Tunnex compiles your policy into WireGuard peers and gateway state, so people, sites and services connect directly. The control plane hands out config and never carries a packet.
With Tunnex: direct encrypted tunnels between people, sites and services Two locations on the left — an office and a home — connect over peer-to-peer WireGuard tunnels straight to a cloud environment and a datacenter on the right. A site-to-site tunnel links the cloud and the datacenter. The self-hosted Tunnex control plane in the middle distributes configuration and policy to all four over dotted lines, and never carries traffic.peer-to-peerWireGuard® tunnelpeer-to-peerWireGuard® tunnelconfig & policysite-to-siteWireGuard® tunnelOFFICEHOMECLOUDDATACENTERAliceEngineeringBobSupportWeb serverDatabaseCRMWeb serverControl plane · self-hosted
One command per host
A gateway enrolls itself and pulls its config. No keys typed by hand, no per-site firewall edit.
Policy compiles to the wire
Rules become peer allow-lists and nftables state deterministically: default-deny unless a rule says otherwise.
No single point in the path
The control plane distributes config and policy. Traffic goes peer to peer; if the plane is down, existing tunnels keep running.
Connect Everything.
Trust Nothing.

Connected

CONNECTION STATS0.00 B/s
1.89 KB/s peak0.00 B/s
BYTES IN
92.00 B
BYTES OUT
180.00 B
DURATION
0:24
LAST HANDSHAKE
25s ago
TUNNEL IP
10.99.0.3/32
THE DESKTOP CLIENT

A client that only claims what the wire proves.

Reports live WireGuard handshakes directly. When disconnected, state counters read clear em-dash — instead of fake zeros.
Kernel-level kill-switch
pf on macOS, WFP on Windows. Holds closed even if the process exits unexpectedly.
Split tunnel or all traffic
Toggle routing modes in Settings. Re-issues device configuration deterministically.
Revocation-aware teardown
Admin revocation immediately tears down the tunnel and releases pool slots.
Clear diagnostic logs
Verbatim error traces, timestamps, and log exports for fast debugging.
SIMULATE
Illustrative telemetry with placeholder values. A revocation tears the tunnel down from the server side: the client does not get to disagree.
QUESTIONS

The ones worth asking any VPN vendor.

Ask ours the same way. If an answer here is vaguer than you need, write to sales@tunnex.io.
Is the hosted service ever in my traffic path?+
No. Our hosted service holds billing and license records only. The control plane, the gateways, and the clients all run on infrastructure you own. Packets never route through anything we operate, and there is no key escrow.
What happens if tunnex.io goes down?+
Your VPN keeps running. License keys verify offline against a public key that ships in the binary, so there is no phone-home and no license server in your critical path. Air-gapped deployments are fully supported.
Can I connect from behind CGNAT?+
Gateways currently require public reachability or a port forward. We do not run a relay fleet today. Relay fleet support and NAT traversal features are on the product roadmap.
Do WireGuard and OpenVPN have separate policy rules?+
No. An OpenVPN device is a subject in the same compiled artifact as a WireGuard peer. Two protocols, one Zero Trust engine without separate rule stacks.
Does device posture mean hardware attestation?+
No. Posture is client-reported OS version and disk encryption status. A device flips its own gate on its next report, and unknown states are reported as unknown rather than compliant.
What happens when the trial or a license expires?+
A grace period with warnings is provided. If a licence later lapses, plan-gated capabilities return to Community entitlements, but existing gateways and your VPN keep running. Licence state never touches the data plane.
Do I need a different build for a paid plan?+
No. Tunnex is one binary. Community needs no key; a signed licence key activates the selected plan in the deployment you already run.
How does Tunnex govern AI agents and MCP servers?+
Tunnex issues non-human agent principals with time-boxed, port-scoped access to MCP (Model Context Protocol) servers. Under prompt injection, network-level default-deny bounds the blast radius, preventing compromised AI agents from pivoting to unauthorized internal infrastructure.
Are the desktop clients signed?+
Not yet. Gatekeeper and SmartScreen will prompt on first open until code-signing lands. Code-signed and notarized desktop releases are currently on the roadmap.
PROVEN ON THE WIRE

Cross-cloud, on real infrastructure.

Site-to-site between AWS Sydney and Azure West US, un-NAT'd, under enforcing policy. Capabilities ship after they are demonstrated end to end: the record states which ones were.
WIREGUARD SITE-TO-SITE138 MS · UN-NAT'DROUTES RECONCILED BY THE AGENTS
ILLUSTRATIVE · AGENT PRINCIPALS ARE ROADMAP

Up and running in minutes.

Install the server, authenticate with your identity provider, and connect your first device in minutes.