Features
Everything you need. Nothing you don't.
One platform to connect, secure and observe your private network. Here is what's inside.
CONNECT
A mesh VPN that configures itself
Baseguard builds direct, encrypted tunnels between your devices over the WireGuard® protocol. There is no central concentrator to route through, no subnets to plan and no config files to distribute, devices discover each other and connect peer to peer.
Peer-to-peer connections
Traffic flows directly between devices at wire speed. No bandwidth bottleneck, no added latency from a middlebox.
End-to-end encryption
Every packet is encrypted with modern cryptography before it leaves the device. Nothing on the path can read it, including us.
NAT traversal
Home networks, office firewalls, CGNAT, hotel Wi-Fi, direct paths are negotiated through almost anything, automatically.
Relay fallback
When a direct path is truly impossible, encrypted relays keep the connection alive. Relays forward traffic they cannot decrypt.
Split tunneling
Only traffic for your private network goes through the mesh. Everything else uses the normal internet path, so browsing stays fast.
Exit nodes
Route your internet traffic through any machine you trust, useful on untrusted networks or for location-specific access.
SECURE
Zero-trust access, enforced on every packet
Access in Baseguard follows identity, not IP addresses. Group users and machines with tags, write human-readable rules, and let the network enforce least privilege by default, nothing talks to anything until a rule says so.
Tag-based access policies
Label machines by role (prod, staging, ci) and write rules against tags instead of fragile IP ranges.
SSO with your identity provider
Sign in with Apple, Google or Microsoft on every plan; enterprise SSO and MFA integration on Team and above.
Auth keys
Pre-authenticated keys enroll servers, containers and CI runners without a browser login, ideal for automation.
Device approval
Require an admin to approve every new device before it can join the network.
Node auth period
Set how long a device's authentication stays valid. Short-lived credentials, re-verified on your schedule.
Separation of administrative duties
Split network administration across roles so no single account holds every permission.
RESOLVE
Private DNS that just works
Every device gets a stable, memorable name the moment it joins your network. Queries about your infrastructure are answered inside the mesh, so your internal hostnames never leak to public resolvers.
Short DNS host names
Reach any machine by name, no IP spreadsheets, no zone files, no tickets to the network team.
Search domains
Configure search domains so short names resolve the way your team expects, across every device.
Custom records
Add your own records for internal services and route names exactly where you want them.
Private resolution
Internal names resolve internally; everything else goes out as usual. Your infrastructure map stays yours.
OBSERVE
Visibility that satisfies your auditors
Every administrative action and connection decision lands in a searchable audit stream. When compliance asks how production is segmented, the answer is one query away.
Audit logging
Who joined, what changed, which rule allowed a connection, recorded with actor, action, resource and time.
Access intelligence
Understand how your network is actually used: which paths are active, which rules matter, what never connects.
SIEM integration
Stream events to Splunk, Datadog, Elastic or any tool that speaks JSON, on Enterprise plans.
BUILD
Made to be automated
Baseguard fits the way engineering teams already work: an open API for everything the console does, pre-auth keys for fleets, SSH access across the mesh and clients for every platform you run.
Open API
Manage nodes, rules, keys and DNS programmatically. Wire Baseguard into CI/CD, IaC and internal tooling.
SSH access
Reach any machine in the mesh over SSH using its private name, no bastion hosts, no port forwarding.
Every platform
Native clients for Linux, macOS, Windows, iOS and Android, plus a real desktop GUI on Linux.
Self-hosted option
Run the control plane on your own infrastructure when regulation or policy demands it, available on Enterprise.
See it on your own network
Free for up to 5 users and 100 machines. Setup takes minutes.