Private Network Platform

Private network access and routing controls for modern teams

Programmable private networks for organizations and teams — set up your network, connect nodes to subnets, control routes and egress, and manage secure access.

  • Zero-config onboarding
  • Subnets (CIDR)
  • Routes & Egress
  • Access Control

Scenarios

Common ways teams use Helguard in real environments.

Connect distributed nodes into one private network

Your servers live in different places (cloud / on-prem / office / homelab). Make them behave like one private network with shared subnets and controlled routing.

Web Panel
Helguard multi-node private network view

Secure remote access to internal services

Give your team secure access to internal dashboards and services without exposing them to the public internet.

Client App
Helguard secure service access screen

Public gateway for controlled internet access

Use a node within a subnet as a public gateway, so users can route internet traffic through a defined and controlled exit point.

Client App
Helguard public gateway configuration screen

Reach existing private networks (site/hybrid connectivity)

Bring existing networks (VPC/LAN) into reach by publishing routes—without redesigning your infrastructure.

Web Panel
Helguard route advertisement screen

Operational control (helguardctl)

A lightweight CLI for operational tasks—check status, start/stop/reload the agent, and validate connectivity during setup and troubleshooting.

CLI
$ helguardctl status
helguard-agent
--------------------
State:             RUNNING
Organization:      Helguard Labs
Node:              Services - Server 1
Backend:           Connected (Last Ping 54s ago)
Uptime:            5h12m22s
Version:           1.0.0

Private Networks:
  - Workspace       (workspace-nti8t)   ACTIVE
  - Operations      (operations-7k16)   ACTIVE

Firewall:
  IP Forwarding: Enabled

MVP Capabilities

Core building blocks included in the current MVP.

Multi-organization model

Organizations, members, and roles (Owner/Admin/Member) built-in.

Subnets (CIDR)

Connect multiple nodes in a private subnet and manage connectivity.

Agent-based onboarding

Bring nodes online without opening extra inbound ports.

Advertising routes

Publish routes to reach existing networks (VPC/LAN) and other Helguard networks.

Public Gateway (Egress)

Controlled internet routing through a designated gateway node.

Client apps

Native apps for macOS and Windows with seamless connectivity and management.

Tunnel Lock (Kill Switch)

Prevent traffic leaks when strict mode is enabled.

Secure Authentication

Account sign-in protected with MFA (TOTP) and secure sessions.

MVP scope shown — additional capabilities will be added over time.

Helguard Labs

A controlled demo environment with a preconfigured Labs organization to evaluate Helguard.

Explore preconfigured demo services (Keycloak, Gitea, Excalidraw)

Access is granted by adding you to the Helguard Labs organization

Create your own organization and connect your nodes/subnets

Labs organization is admin-managed for security

Access is provided via request. Admin actions in the Labs organization are restricted.

Helguard Labs dashboard