Your private network
running in 30 seconds
One private, encrypted network across your laptops, servers, and cloud machines — they reach each other like they're in the same room. No firewall holes, no exposed ports, no legacy VPN. Just one command per device.
Up and running in three steps
Create a network and a one-time code in the dashboard, then run one command on each device. That's the whole setup.
Create
Name a network in the dashboard. It gets its own private address space and keys — room for about a thousand devices.
your own keys · ~1,000 devices
Enroll
Generate a one-time code for a single device. It expires fast, so a leaked code is worthless.
one-time code · expires fast
Join
Run one command on the device. It generates its own keys and joins — with nothing opened to the internet.
$ exanets up <token>
Secure by design, simple by default
Direct connections, real privacy, and one-command setup — plus everything you need to run it for real.
Feels like one local network
Devices talk straight to each other, as if on the same switch — wherever they are. The coordinator only introduces them; it never carries your traffic.
even across the internet
Private to your devices
Each device holds its own keys, and they never leave it. Traffic is sealed by the sender and opened only by its destination — no one in between can read it.
keys never leave your devices
Nothing exposed online
No public IP, no open port, nothing listening on the internet — so there's no front door for an attacker to find or force.
no open ports to the internet
Revoke a device in seconds
Remove a device from the dashboard and every peer stops trusting it within about 30 seconds. No chasing down machines.
in about 30 seconds
Runs on every device
One small binary per machine. macOS and Linux today; iOS, Android, and Windows soon.
one binary · more platforms soon
A network per team, fully isolated
Every network is walled off from the rest. People see only the networks they belong to, and that boundary is enforced in the database — not just hidden in the UI.
private to each team
Reach anything, like it's local
Once devices share a network, they reach each other by name — as if they were sitting in the same room.
- Internal services, on localhost
- Reach SSH, databases, dashboards, and Git by name — as if they were running on your own machine.
- Home lab meets cloud
- Stitch your laptop, a home server, and a few cloud VMs into one flat, private network.
- Team access without a gateway
- Give teammates access to internal tools without a VPN gateway or exposing anything to the public internet.
- Devices behind NAT
- Reach machines behind home and office NAT — no port-forwarding, no static IPs, and no relay sitting in the middle of your traffic.
The ease of a mesh, without a relay in the middle
Quick to set up, with direct device-to-device connections and per-device keys that never leave the device. And unlike other meshes, no relay ever carries your traffic.
Connects your devices directly
EXANetsYesLegacy VPNNoHosted meshYesTraffic never relayed through a provider
EXANetsYesLegacy VPNNoHosted meshNoPer-device keys stay on the device
EXANetsYesLegacy VPNNoHosted meshYesNothing exposed to the internet
EXANetsYesLegacy VPNNoHosted meshYesDedicated, isolated network per team
EXANetsYesLegacy VPNPartialHosted meshPartialTime to add a device
EXANets~30sLegacy VPNhoursHosted mesh~minutes
Ready to build your private network?
Free while in early access. No credit card required.