Native device identities
Every VPN device has its own registered public key, status and configuration lifecycle. The private key never needs to leave the client.
Xensec is intentionally focused on the pieces required to run a private, native VPN service well.
Every VPN device has its own registered public key, status and configuration lifecycle. The private key never needs to leave the client.
The control plane selects eligible infrastructure, allocates tunnel state and sends peer jobs to authenticated VPN node agents.
Locations reflect server heartbeat, provisioning state, capacity, load and manual maintenance state rather than a hard-coded list.
Password authentication, authenticator-based 2FA, recovery codes, passkeys and scoped customer/ACP sessions protect access.
Use managed shared Xensec nodes or a customer-assigned dedicated VPN node while keeping the same client and account experience.
Customer activity and VPN connection history are surfaced in the portal without exposing internal node secrets or WireGuard private material.
See the current product tiers and choose the infrastructure that fits.