See what shipped this month

Features

Everything you need. Nothing you don't.

One platform to connect, secure and observe your private network. Here is what's inside.

CONNECT

A mesh VPN that configures itself

Baseguard builds direct, encrypted tunnels between your devices over the WireGuard® protocol. There is no central concentrator to route through, no subnets to plan and no config files to distribute, devices discover each other and connect peer to peer.

Peer-to-peer connections

Traffic flows directly between devices at wire speed. No bandwidth bottleneck, no added latency from a middlebox.

End-to-end encryption

Every packet is encrypted with modern cryptography before it leaves the device. Nothing on the path can read it, including us.

NAT traversal

Home networks, office firewalls, CGNAT, hotel Wi-Fi, direct paths are negotiated through almost anything, automatically.

Relay fallback

When a direct path is truly impossible, encrypted relays keep the connection alive. Relays forward traffic they cannot decrypt.

Split tunneling

Only traffic for your private network goes through the mesh. Everything else uses the normal internet path, so browsing stays fast.

Exit nodes

Route your internet traffic through any machine you trust, useful on untrusted networks or for location-specific access.

SECURE

Zero-trust access, enforced on every packet

Access in Baseguard follows identity, not IP addresses. Group users and machines with tags, write human-readable rules, and let the network enforce least privilege by default, nothing talks to anything until a rule says so.

Tag-based access policies

Label machines by role (prod, staging, ci) and write rules against tags instead of fragile IP ranges.

SSO with your identity provider

Sign in with Apple, Google or Microsoft on every plan; enterprise SSO and MFA integration on Team and above.

Auth keys

Pre-authenticated keys enroll servers, containers and CI runners without a browser login, ideal for automation.

Device approval

Require an admin to approve every new device before it can join the network.

Node auth period

Set how long a device's authentication stays valid. Short-lived credentials, re-verified on your schedule.

Separation of administrative duties

Split network administration across roles so no single account holds every permission.

RESOLVE

Private DNS that just works

Every device gets a stable, memorable name the moment it joins your network. Queries about your infrastructure are answered inside the mesh, so your internal hostnames never leak to public resolvers.

Short DNS host names

Reach any machine by name, no IP spreadsheets, no zone files, no tickets to the network team.

Search domains

Configure search domains so short names resolve the way your team expects, across every device.

Custom records

Add your own records for internal services and route names exactly where you want them.

Private resolution

Internal names resolve internally; everything else goes out as usual. Your infrastructure map stays yours.

OBSERVE

Visibility that satisfies your auditors

Every administrative action and connection decision lands in a searchable audit stream. When compliance asks how production is segmented, the answer is one query away.

Audit logging

Who joined, what changed, which rule allowed a connection, recorded with actor, action, resource and time.

Access intelligence

Understand how your network is actually used: which paths are active, which rules matter, what never connects.

SIEM integration

Stream events to Splunk, Datadog, Elastic or any tool that speaks JSON, on Enterprise plans.

BUILD

Made to be automated

Baseguard fits the way engineering teams already work: an open API for everything the console does, pre-auth keys for fleets, SSH access across the mesh and clients for every platform you run.

Open API

Manage nodes, rules, keys and DNS programmatically. Wire Baseguard into CI/CD, IaC and internal tooling.

SSH access

Reach any machine in the mesh over SSH using its private name, no bastion hosts, no port forwarding.

Every platform

Native clients for Linux, macOS, Windows, iOS and Android, plus a real desktop GUI on Linux.

Self-hosted option

Run the control plane on your own infrastructure when regulation or policy demands it, available on Enterprise.

See it on your own network

Free for up to 5 users and 100 machines. Setup takes minutes.