Private network for self-hosted apps: zero-trust access by identity

Your apps answer only on a private, encrypted mesh. People reach them by identity, not by address, and the internet sees one hardened gate on port 443.

Start with one workloadBook a 30-minute briefing

Mesh
Pilae private network, encrypted tunnels
Public entry
One hardened gate on port 443
Access
By identity and group, through your SSO
Default
Every new app is private

Apps nobody on the internet can find

An app with a public address is found by automated scanners soon after it goes online. On the Pilae network, your apps have no public address at all. Only the people and machines you allow can reach them.

Private by default

Each app answers only on the mesh. A new app stays private until you decide it needs a public entry.

One hardened gate

The only public entry point is a single gate on port 443, with TLS, rate limits and only the routes you approve.

Access by identity

People join the mesh with their Keycloak or Entra ID account. Groups in your directory decide which apps each person reaches.

Encrypted end to end

Traffic between devices and apps travels in encrypted tunnels. The coordination service never sees its content.

Sites joined as one

Machines on your premises and in Pilae Cloud sit on the same mesh, so a hybrid estate has one network and one policy.

Every connection on record

Peers, policies and policy changes are visible in the console and recorded in the audit trail.

Zero-trust access without a VPN appliance

A classic VPN puts a user on the network and trusts them with everything behind it. The Pilae network works the other way. Each person reaches only the apps their group allows, from a device that has signed in with their work account. There is no flat network to wander through.

The mesh is Pilae’s own private network, which connects your devices and servers in encrypted tunnels. We run it for you, write the access policies from your group structure, and keep the clients and the policy in step with your directory.

Why your apps have no public address

Many self-hosting incidents start with an app exposed to the internet that nobody meant to expose: an admin panel, a database port, a forgotten test instance. With Pilae, every app answers only on the mesh, and host firewalls close every other port. A new app is private until you decide otherwise.

Some apps must be public, such as a booking page or a client portal. Those go through one hardened gate on port 443, with TLS, rate limits and only the routes you approve. The security page sets out the controls around it.

One network for premises and cloud

Machines on your premises and in Pilae Cloud join the same mesh. A hybrid estate gets one network, one policy and one audit trail in the console. The coordination service that lets machines find each other is covered by our data processing agreement. For isolated environments it runs inside your perimeter instead.

Access that follows your directory

Staff join the mesh with their Keycloak or Microsoft Entra ID account. Our identity service connects it during onboarding. When someone leaves and their account is disabled, their access to the mesh and to every app ends with it. To plan your network, book a scoping call.

How your network is set up

  1. Map access

    We agree with your team which groups reach which apps, and which apps, if any, need a public entry.

  2. Build the mesh

    Your machines join the mesh, host firewalls close every public port, and access policies are written from the map.

  3. Connect identity

    The mesh is linked to your identity provider, so staff join with their usual account and lose access when it is disabled.

  4. Open the gate

    Apps that must be public, such as a customer portal, are published through the gate on port 443 and nowhere else.

What your contract includes

Default posture
Every app private to the mesh. Public exposure only for the apps you name, through the gate on port 443.
Access policies
Written from your group structure, and changed only on your request, with each change recorded.
Identity
Mesh sign-in through your Keycloak or Entra ID, set up during onboarding.
Coordination
Covered by your data processing agreement, or run inside your perimeter for air-gapped deployments.
Client devices
Pilae network clients for Windows, macOS, Linux, iOS and Android, with rollout guidance for your IT team.

The apps behind it

Questions

Can the public internet reach my apps?

No. Apps answer only on the private mesh. The only public entry point is one hardened gate on port 443, and you decide which apps it exposes, if any.

How does the private network work?

Pilae connects your devices and servers in a private mesh of encrypted tunnels. It keeps your apps off the public internet and grants access by identity, through your SSO.

How do my staff reach a private app?

They install the Pilae network client, sign in with their work account through your identity provider, and open the app as usual. The groups they belong to decide which apps they can reach.

Can the coordination service see my data?

No. Traffic travels in tunnels encrypted between the two ends. The coordination service exchanges keys and peer addresses so devices can find each other, and never carries the content of the traffic.

Does the private network work for air-gapped deployments?

Yes. For an air-gapped or fully isolated deployment, the coordination service runs inside your perimeter, and nothing depends on a connection to Pilae Cloud.

Related

Take your apps off the public internet.

Thirty minutes with an engineer to map who needs which app and what, if anything, must stay public.