See what shipped this month

Secure Your Network with a Zero-Trust Mesh

Baseguard connects your devices directly, peer to peer, encrypted end to end. No VPN configs, no exposed ports, no latency tax. Your infrastructure finds itself, from anywhere.

E2E EncryptedWireGuard® ProtocolISO 27001
console.baseguard.net
Nodes
Devices connected to your organization's private network.
Search nodes
Tags
New Node
NodeAddressLast SeenVersion
prod-api-01Expiry Disabledprod100.64.0.21Online0.2.8 · ubuntu 24.04
prod-db-primaryExpiry Disabledprod100.64.0.22Online0.2.8 · ubuntu 24.04
k8s-worker-03k8s100.64.0.31Online0.2.8 · debian 12
ci-runner-02ci100.64.0.41Jul 30, 17:520.2.8 · ubuntu 24.04
edge-gw-fraExpiry Disablededge100.64.0.51Online0.2.8 · alpine 3.20
monitoring-01infra100.64.0.61Online0.2.8 · ubuntu 24.04
staging-api-01staging100.64.0.71Jul 29, 09:140.2.7 · ubuntu 22.04
prod-api-01Online
Expiry Disabledprod
Actions
IPv4100.64.0.21
Public IP34.89.112.4
Domainprod-api-01.7089b838.baseg…
Created Byops@acme.inc
Node Info
ID5KBMXDl8ztjOYztqHFRssm
Hostnameprod-api-01.internal
Nameprod-api-01
Last SeenOnline
Created AtFeb 14, 2026 14:05
Client Version0.2.8
Operating Systemubuntu 24.04
Key ExpiresSep 10, 2026 10:13

Trusted by engineering teams at

VBTVLMediaTechnartsBaran TechnologyKokteylAppSamuraiNetdirektTapsilatOMG FinanceMatbaagoVBTVLMediaTechnartsBaran TechnologyKokteylAppSamuraiNetdirektTapsilatOMG FinanceMatbaago

One platform, from first handshake to full audit trail

CONNECT
Mesh VPN
Direct peer-to-peer WireGuard® tunnels between every device
Relay Fallback
Encrypted relays only when a direct path is impossible
Exit Nodes
Route internet traffic through any node you trust
SECURE
Access Control
Default-deny policies by user, group, tag or service
SSO & MFA
Plug into your existing identity provider
Key Rotation
Short-lived keys, rotated automatically
RESOLVE
Private DNS
Every device gets a stable name, queries never leave your network
Split DNS
Internal stays internal, external goes out
Service Discovery
Find services by name, not by IP spreadsheet
OBSERVE
Audit Logs
Every connection, every policy decision, searchable
Live Topology
See paths, latency and health in real time
Export & SIEM
Stream events to the tools you already run
SSO withApple · Google · Microsoft · any OIDC provider
Deploy onCloud · On-Premise · Air-gapped

Baseguard. One Secure Network for Your Whole Team

A zero-trust networking platform that connects your people, servers and devices, securely, at wire speed, without the operational overhead.

Get Started Free
MESH VPN

Direct, Encrypted, Peer-to-Peer

Devices discover each other automatically and connect point to point over the WireGuard® protocol. Traffic never passes through our servers, there is no bandwidth bottleneck to pay for.

More About the Mesh

New devices join the mesh and find every peer without any configuration.

We replaced our legacy VPN in an afternoon. Latency dropped by 80%
Erdem Yurdanur · Founder, Kokteyl
console.baseguard.net
Nodes
Devices connected to your organization's private network.
Search nodes
Tags
New Node
NodeAddressLast SeenVersion
prod-api-01Expiry Disabledprod100.64.0.21Online0.2.8 · ubuntu 24.04
prod-db-primaryExpiry Disabledprod100.64.0.22Online0.2.8 · ubuntu 24.04
k8s-worker-03k8s100.64.0.31Online0.2.8 · debian 12
ci-runner-02ci100.64.0.41Jul 30, 17:520.2.8 · ubuntu 24.04
edge-gw-fraExpiry Disablededge100.64.0.51Online0.2.8 · alpine 3.20
monitoring-01infra100.64.0.61Online0.2.8 · ubuntu 24.04
staging-api-01staging100.64.0.71Jul 29, 09:140.2.7 · ubuntu 22.04
prod-api-01Online
Expiry Disabledprod
Actions
IPv4100.64.0.21
Public IP34.89.112.4
Domainprod-api-01.7089b838.baseg…
Created Byops@acme.inc
Node Info
ID5KBMXDl8ztjOYztqHFRssm
Hostnameprod-api-01.internal
Nameprod-api-01
Last SeenOnline
Created AtFeb 14, 2026 14:05
Client Version0.2.8
Operating Systemubuntu 24.04
Key ExpiresSep 10, 2026 10:13
ACCESS CONTROL

Zero-Trust Rules, Human-Readable

Group users and servers by tags, write policies in plain JSON, and let Baseguard enforce them on every packet. No access without an explicit rule.

More About Access Control

Nothing talks to anything until a rule says so. Least privilege, by construction.

We are not managing the network any more. We just get on with our own work.
Ertugrul Eraslan · Co-Founder, Baran Technology
console.baseguard.net
Access Control
Control which nodes can reach each other with tag-based rules.
Network RulesPreviewTags
Search rules
Tags
Create Rule
NameSource TagsDestination TagsProtocolPorts
allow-sre-prodsreprodTCP22
ci-to-registryciregistryTCP5000
DefaultAllAllALLAll
Configure network access rules
Define secure communication rules between nodes by configuring tags, protocols, and ports.
Name
rule name
Source Tags
dev
Destination Tags
staging
Protocol
TCP
Ports
22, 443
CancelCreate Rule
PRIVATE DNS

Every Device Gets a Name

Baseguard runs DNS inside your mesh. Machines get stable, memorable names the moment they join, and queries about your infrastructure never leave your network.

More About Private DNS

prod-db.base just works, no zone files, no registrar, no tickets.

console.baseguard.net
DNS
Configure name resolution, search domains, and custom records for your network.
NameserversSearch DomainsRecords
Search records
Tags
Add Record
DomainTypeTargetTTL (seconds)Tags
*.corp.internalA10.0.0.1300All
api.corp.internalA100.64.0.21300prod
grafana.corp.internalA100.64.0.61300infra
registry.corp.internalA100.64.0.41300ci
AUDIT LOGS

Every Connection, Accounted For

Connections, policy decisions, node joins, config changes, everything lands in a searchable, exportable audit stream built for compliance teams.

More About Audit Logs

Query any timeframe, any node, any rule, answers in seconds.

console.baseguard.net
Audit Log
Review administrative activity across your organization.
Search logs
Jul 24 – Jul 31, 2026
Action
ActorActionResourceCreated At
ops@acme.incCreate Network ACLallow-sre-prod09:12
ecem@acme.incUpdate Nodeedge-gw-fra09:04
ozgur@acme.incCreate API Keyapi-key-ci08:57
ci@acme.incVerify Node Authci-runner-0208:41
DEPLOY ANYWHERE

From Zero to Mesh in Minutes

One-line installers for every platform, MDM-friendly packages, and a control plane you can use as SaaS or run yourself, even air-gapped.

Get the Installers

Linux, macOS, Windows, iOS, Android, Docker, Kubernetes, Raspberry Pi.

root@pi:~ #

Built for the way you run infrastructure

0
VPN configs to maintain
<1ms
Added latency on direct paths
Connect your team to internal resources from anywhere. Coffee shop, airport, home office, it doesn't matter.
Book a Demo

Simple pricing. No surprises.

Start free, scale as you grow. Every plan includes the core security features.

Free

$0forever

For personal projects and small teams.

Up to 5 users
100 machines
  • End-to-end encrypted mesh
  • Tag-based access policies
  • Private DNS and open API
Get Started Free

Team

Most popular
$10per user / month

For teams that need scale and a full audit trail.

Unlimited users
100 machines + 10 per user
  • Everything in Free, plus:
  • Enterprise SSO and MFA
  • Full audit logging and SLA
Contact Sales

Enterprise

Customannual agreements

For advanced security and compliance needs.

Unlimited users
Custom machine limits
  • Everything in Team, plus:
  • Self-hosted deployment
  • SIEM integration and priority SLA
Contact Sales

Frequently asked questions

Can't find what you're looking for? Talk to support. A human answers.

Baseguard is a zero-trust mesh networking platform. It connects your devices, servers and people directly to each other over encrypted, peer-to-peer WireGuard® tunnels, replacing traditional VPNs, bastion hosts and firewall sprawl with one identity-aware network.

Baseguard for Enterprise

Solutions built on enterprise-grade security, privacy and compliance, deployed your way.

SSO & SCIM provisioning
Custom ACL policy reviews
On-premise control plane
Advanced data retention
Dedicated relay regions
Audit log export & SIEM
99.99% uptime SLA
Private support channel
Air-gapped deployments
Security questionnaire support