Connect distributed nodes into one private network
Your servers live in different places (cloud / on-prem / office / homelab). Make them behave like one private network with shared subnets and controlled routing.
Programmable private networks for organizations and teams — set up your network, connect nodes to subnets, control routes and egress, and manage secure access.
Connect Helguard to Claude, Claude Code, Cursor, Codex, GitHub Copilot, and any MCP-compatible client — query nodes and subnets, manage members, and register infrastructure through natural language.
OAuth 2.1 with PKCE and Dynamic Client Registration — sign in through your browser, nothing to configure for personal use.
Scoped, revocable organization tokens for CI/automation and static integrations.
Works with Claude, Claude Code, Cursor, Codex, GitHub Copilot, OpenCode, and more.
Safety-scoped by design — read-heavy access plus lightweight admin actions, no destructive operations.
$ claude mcp add --transport http helguard https://api.helguard.net/mcp — $ claude — > /mcp — Signed in to Helguard (browser) — > "List subnets with unhealthy nodes" — Subnet: production (12 nodes), 1 node offline — Subnet: staging (4 nodes), all healthy
Common ways teams use Helguard in real environments.
Your servers live in different places (cloud / on-prem / office / homelab). Make them behave like one private network with shared subnets and controlled routing.
Give your team secure access to internal dashboards and services without exposing them to the public internet.
Use a node within a subnet as a public gateway, so users can route internet traffic through a defined and controlled exit point.
Bring existing networks (VPC/LAN) into reach by publishing routes—without redesigning your infrastructure.
A lightweight CLI for operational tasks—check status, start/stop/reload the agent, and validate connectivity during setup and troubleshooting.
$ helguardctl status — helguard-agent — State: RUNNING — Organization: Helguard Labs — Node: Services - Server 1 — Backend: Connected (Last Ping 54s ago) — Uptime: 5h12m22s — Version: 1.0.0 — Private Networks: Workspace (workspace-nti8t) ACTIVE, Operations (operations-7k16) ACTIVE — Firewall: IP Forwarding Enabled
Core building blocks included in the current MVP.
Organizations, members, and roles (Owner/Admin/Member) built-in.
Connect multiple nodes in a private subnet and manage connectivity.
Bring nodes online without opening extra inbound ports.
Publish routes to reach existing networks (VPC/LAN) and other Helguard networks.
Controlled internet routing through a designated gateway node.
Native apps for macOS and Windows with seamless connectivity and management.
Prevent traffic leaks when strict mode is enabled.
Account sign-in protected with MFA (TOTP) and secure sessions.
MVP scope shown — additional capabilities will be added over time.
A controlled demo environment with a preconfigured Labs organization to evaluate Helguard.
Explore preconfigured demo services (Keycloak, Gitea, Excalidraw)
Access is granted by adding you to the Helguard Labs organization
Create your own organization and connect your nodes/subnets
Labs organization is admin-managed for security
Access is provided via request. Admin actions in the Labs organization are restricted.