The Modern, Open Source, Self-Hosted Zero Trust Network Access Platform
Modern Zero Trust Network Access
Replace your Business VPNs and Traditional Remote Access Tools with a Modern, FOSS, Self-Hosted, Unified ZTNA Solution
A Unified Zero Trust Architecture
A Unified Architecture for both Humans and Workloads to Access Private/Internal Resources behind NAT Scattered Across Multiple Clouds and Environments as well as Protected Public Resources such as SaaS APIs and Databases
Secret-less Access to APIs, SSH and Databases
Provide Dynamic Secret-less Access to HTTP-based Resources without sharing API Keys, PostgreSQL and MySQL Databases without sharing Passwords, SSH Servers without Managing Keys and Certificates
Application-layer Aware Access Control
Access Control at the Application-layer (L7) (e.g. HTTP paths and methods, Kubernetes namespaces and verbs, PostgreSQL queries, etc...) using Identity-aware Proxies (IAPs) via Context-aware Policy-as-Code via CEL and OPA
Zero-Config Client-based ZTNA
Private access using VPN-like Zero-Config Client-based ZTNA over WireGuard/QUIC Tunnels with Automatic, Centralized Private DNS
Unified, Scalable BeyondCorp Architecture
Public client-less BeyondCorp access for both Human via their Browsers and Workload Users via Standard OAuth2 Authentication Flow
Built for Scalability and Availability
A Scalable Platform Built on top of Kubernetes for Automatic Horizontal Scalability and Availability
Centralized, Declarative and Programmable Management
Designed to be Administered like Kubernetes via DevOps/GitOps-friendly Centralized and Declarative Way. The Cluster is furthermore fully Programmable over gRPC.
Integrate your OIDC/SAML SSO Providers
Seamlessly integrate any OpenID Connect or SAML 2.0 SSO Provider as well as GitHub OAuth2.
OpenTelemetry-Ready Visibility
OpenTelemetry-ready Layer-7 Aware, Real-Time Visibility and Auditing to Your Log Management and SIEM Providers
Eliminate VPN Problems
Eliminate Traditional VPN Problems: Use a Single Stable Route instead of Injecting Countless Routes into Your Users' Clients. Effortless Dual-Stack Networking Regardless of the Support at the Upstream. Seamless, Unified, Automatic Private DNS.
© 2025 octelium.comOctelium Labs, LLCAll rights reserved
Octelium and Octelium logo are trademarks of Octelium Labs, LLC.
WireGuard is a registered trademark of Jason A. Donenfeld