Zero-trust access without a VPN appliance
A classic VPN puts a user on the network and trusts them with everything behind it. The Pilae network works the other way. Each person reaches only the apps their group allows, from a device that has signed in with their work account. There is no flat network to wander through.
The mesh is Pilaeās own private network, which connects your devices and servers in encrypted tunnels. We run it for you, write the access policies from your group structure, and keep the clients and the policy in step with your directory.
Why your apps have no public address
Many self-hosting incidents start with an app exposed to the internet that nobody meant to expose: an admin panel, a database port, a forgotten test instance. With Pilae, every app answers only on the mesh, and host firewalls close every other port. A new app is private until you decide otherwise.
Some apps must be public, such as a booking page or a client portal. Those go through one hardened gate on port 443, with TLS, rate limits and only the routes you approve. The security page sets out the controls around it.
One network for premises and cloud
Machines on your premises and in Pilae Cloud join the same mesh. A hybrid estate gets one network, one policy and one audit trail in the console. The coordination service that lets machines find each other is covered by our data processing agreement. For isolated environments it runs inside your perimeter instead.
Access that follows your directory
Staff join the mesh with their Keycloak or Microsoft Entra ID account. Our identity service connects it during onboarding. When someone leaves and their account is disabled, their access to the mesh and to every app ends with it. To plan your network, book a scoping call.