Product · Deployment

Cloud, Self-hosted, and Hybrid.

Choose the deployment model that matches your control, compliance, and operational requirements. Every model runs the same zero-trust architecture — you choose which planes to own.

Deployment models

Three models. One architecture.

The same separated planes, site-side enforcement, and key isolation run in every model. The difference is who operates each plane.

SAAS

Cloud

Managed control plane and global PoP mesh. The fastest path to production for teams that want access, not infrastructure.

+Managed NSD — no install, no ops
+Global PoPs — low-latency relay mesh
+Pay-as-you-go — scale without procurement
+Automatic upgrades and certificate rotation
fastest time to production
SELF-HOSTED

Self-hosted

Run NSD on your own infrastructure with full sovereignty over config, keys, and audit data. Air-gap and offline activation supported.

+Full data residency — nothing leaves your boundary
+Air-gap and offline license activation
+BYO observability — Prometheus-compatible metrics
+You own upgrades, HA design, and backup
for regulated workloads and sovereign control
HYBRID

Hybrid

Managed control plane with self-hosted gateways and site nodes — keep data and enforcement boundaries where you need them while cutting control-plane maintenance.

+Managed NSD — your gateways, your nodes
+Per-region data residency policies
+Stage migration — move planes independently
+Global enterprise with local enforcement
for global organizations with local requirements
Decision guide

Use Cloud when speed matters, Self-hosted when control matters, and Hybrid when both need to coexist.

CLOUD

Choose Cloud when...

You want to evaluate quickly, run a small to medium fleet, or don't want to operate infrastructure. Managed upgrades, no ops burden, and pay-as-you-go.

+Trial and evaluation
+Small to medium teams
+No dedicated infrastructure ops
SELF-HOSTED

Choose Self-hosted when...

You need full data residency, are operating in a regulated sector, or have an air-gap requirement. You take on the ops burden in exchange for complete control.

+Data residency mandates
+Air-gapped or regulated environments
+Compliance with strict data locality
HYBRID

Choose Hybrid when...

You want the managed control plane for availability but need enforcement to happen inside your perimeter — or when you have multiple regions with different data requirements.

+Multi-region with local enforcement
+Phased migration from self-hosted
+Control-plane SLA without compromising data-plane sovereignty
What stays the same

The architecture does not change. The operator does.

KEYS

Keys stay on-node, always

WireGuard private keys are generated on each device and node, stored locally, and never transmitted — regardless of deployment model.

ENFORCEMENT

Site-side ACL is final

NSN applies access control next to your workloads. Even if the control plane is unavailable, existing sessions are governed by the last-known policy at the site.

AUDIT

Per-flow structured records

Every authorized flow produces a structured audit record: identity, device, destination, matched policy, bytes. The schema is the same in every deployment model.

CRYPTO

WireGuard + mTLS 1.3

Data-plane tunnels use WireGuard. The control channel between every component is mutually authenticated TLS 1.3 with short-lived certificates.

Get started

Pick a model and deploy in minutes.

Cloud needs no setup. Self-hosted ships as a single binary. Hybrid starts with the managed control plane and grows from there.