A safer model than the traditional VPN
Direct, identity-verified connections instead of a central gateway
Traditional VPN
- Users land on a flat network with broad access
- All traffic funnels through a central concentrator
- Public gateways are a constant target for attackers
- Access lives in VPN accounts, so offboarding is slow
With Defined
- Least-privilege access enforced by an identity-based firewall
- Direct peer-to-peer tunnels with no central bottleneck
- No inbound ports and no public endpoints to expose
- Access follows your identity provider, so offboarding is instant
Built-in security for modern infrastructure
Authenticate users through OIDC and connect them directly to the systems they need
Authenticate with your provider
Use your existing SSO provider such as Okta, Google, or Azure AD to log in and manage access across your infrastructure.
No VPN required
Skip traditional VPN headaches. We create secure tunnels only when users authenticate, reducing overhead and complexity.
Allow access from anywhere
Connect to internal tools and servers securely, without opening inbound firewall ports or exposing public endpoints.
Granular access control
Enforce granular access with tags and roles, ensuring users only reach what they’re allowed to.
Connectivity failover
When direct connections fail, relays maintain encrypted connectivity automatically, ensuring consistent remote access.
Built-in firewall
Segment and isolate internal environments, protecting critical systems from unauthorized access or network threats.
How Defined stacks up
See how Defined compares to the tools teams most often replace
Frequently asked questions
Secure remote access lets people connect to private servers, dashboards, and internal services from anywhere without exposing those systems to the public internet. With Defined Networking, every connection is mutually authenticated with certificates, end-to-end encrypted, and limited to the specific hosts a user is authorized to reach.
A traditional VPN routes traffic through a central concentrator and typically drops users onto a flat network where they can reach everything. Defined creates direct, peer-to-peer encrypted tunnels only between the hosts you explicitly allow, with no central bottleneck and identity-based firewall rules enforcing least privilege.
No. Hosts establish outbound connections and use UDP hole punching to connect directly, so there are no inbound firewall ports to open and no public endpoints to expose. This works even for machines behind NAT or CGNAT, and relays maintain connectivity when a direct path is not available.
Yes. Users authenticate through your existing OIDC provider, such as Okta, Google, or Azure AD, so access follows your existing identity and onboarding or offboarding workflows.
Yes. Because Defined provides network-layer connectivity, any TCP or UDP service works over it, including SSH, RDP, internal web dashboards, and databases, even when the target machine is behind NAT with no public IP.
Yes. Defined replaces a traditional remote-access VPN with a zero trust mesh. Instead of routing everyone through a central VPN gateway, it creates direct, end-to-end encrypted connections that are authorized by identity, with no concentrator to size or maintain.
Yes. Every connection is authenticated by identity and authorized by a built-in host firewall, so users reach only the specific services they are allowed to. That least-privilege, identity-based model is the core of zero trust network access (ZTNA).
Yes. You can connect up to 100 hosts for free with no credit card required, which is enough for most teams to roll out secure remote access before scaling up.
Encryption that works
Fast, secure overlay networking with unlimited scalability. Up to 100 hosts free, no credit card required.