Private by design. Clear about limits.
A secure connection needs both encryption and accountable access.
Encrypted device traffic
Device traffic uses WireGuard encryption. Relays forward encrypted packets and do not terminate the device-to-device WireGuard tunnel. The control service handles device public keys, workspace membership, addresses, routes and policy metadata.
Identity and authorization
Personal console accounts use email verification, password sign-in and optional two-factor authentication. Sensitive actions require recent authentication. Owners, administrators and auditors have different permissions. Device approval and tenant-scoped access policies control network access.
Short-lived authorization
Agents must refresh authorization with the control service. If authorization cannot be renewed before its lease expires, forwarding stops. A service outage can therefore interrupt connectivity after the lease expires.
What the early-access service is not
No availability SLA, independent security certification or enterprise compliance claim is made. Self-configured enterprise OpenID Connect, production billing and mobile clients are not generally available.
Before putting it into production
Review your host firewall and access rules, protect agent state and account recovery methods, and maintain a separate administrative recovery path. This early-access deployment should not be your only way to reach a critical system.