UpdatesExplore the release notes

BASEGUARD FEATURES

Your private network.
Put to work.

Reach the machines you need, decide what they can access, and get on with the work you came to do.

Terminal
~ ssh build-01.acme.internal
Connected to build-01 · 100.64.0.12
developer@build-01:~$
Last login: today from 100.64.0.8
❯

Mesh VPN

Work on your office machine. From home.

Your laptop, cloud servers and office machines connect over encrypted WireGuard tunnels. Keep using SSH, your database client and your browser.

Explore Mesh VPN
Network Rules · example
ALLOW ONLY WHAT THIS DEVICE NEEDS
Source tagdev
TCP · 443
Destination tagstaging
staging · port 443 is reachable
No access to production from this rule

Example with Default ACL removed and no broader allow rules.

Access Control

Let developers into staging. Keep production separate.

Tag your machines and allow specific services between them. See which devices can connect, and on which ports.

Explore Access Control
grafana.corp.internal
Team dashboardPrivate
APIHealthy
DatabaseConnected
WorkersReady

Private DNS

Open your dashboard by name.

Give internal services a name your team can remember. Add custom records or keep using your existing internal nameservers.

Explore Private DNS
Audit Logs · rule history
RESOURCE: DEV-TO-STAGING
Rule updatedTCP port changed to 443by Alex Morgan
Rule createddev → stagingby Sam Chen

Actor, time and the submitted change, kept together.

Audit Logs

Find out who changed that rule.

Search administrative changes by action, resource and time. Open an entry to see the actor and submitted request.

Explore Audit Logs
CI runner · build job
~ baseguard login --auth-key "$BG_AUTH_KEY"
baseguard connect
# Access the registry through your ci rule
docker pull registry.corp.internal/app:latest
# Ephemeral node is removed on disconnect

API & Automation

Give your pipeline private access.

Enroll a runner with an auth key, reach your private registry and remove the ephemeral node when it disconnects.

Explore API & Automation

TRY IT ON YOUR OWN NETWORK

Connect your first two machines.

Install Baseguard, join the same organization, and put it to work.