Zero trust at wire speed.

Firezone connects your team directly to the servers and apps they need. Nothing is exposed to the internet, and you can set it up in minutes.

Backed by Y Combinator and trusted by thousands of organizations

corrdyn logosquare1 logowolfram logoteracloud logodouble11 logo
corrdyn logosquare1 logowolfram logoteracloud logodouble11 logo

5+ Gbps from a laptop

Firezone’s data plane is written in Rust and tuned for each operating system. Devices connect straight to the nearest Gateway.

How the architecture works
Throughput by platform, as testedCommodity hardwareTuned hardware
Linux
5+ Gbps, 10+ Gbps on tuned hardware
macOS
5+ Gbps
Windows
5+ Gbps
iOS
2+ Gbps
Android
2+ Gbps

Throughput varies with round-trip latency, packet loss, hardware, network capacity, and workload.

Secure without the hassle

Your network stays hidden. Access follows your identity provider. And only company devices can connect.

Invisible to the internet

Gateways only make outbound connections. They never listen for traffic from the internet, so there are no open ports to find and nothing to attack. You don’t touch your firewall at all. If a direct path isn’t possible, traffic goes through the nearest of 34 relay clusters, so it stays fast on any network.

you@laptop: ~

$ nmap -Pn -p- gateway.corp.example
Starting Nmap 7.95
Nmap scan report for gateway.corp.example
All 65535 scanned ports are in ignored states.
Not shown: 65535 filtered tcp ports (no-response)

Nmap done: 1 IP address (1 host up)
  1. Oktadana@corp.example deactivated
  2. FirezoneIdentity deleted
  3. FirezoneSigned out of 3 Clients
  4. FirezoneTunnels to 12 Resources closed

People who leave lose access

Firezone syncs users and groups from Okta, Entra ID, and Google Workspace. Deactivate someone there and they’re signed out of every device. There’s no second list to clean up.

Subject
CN=dev.firezone.device-trust
SAN
firezone://serial/C02XG2JHJG5J
Issuer
Intune SCEP CA
Private key
Stored in TPM, never exported

Signature verified over mutual TLS

Only your devices get in

Your MDM gives each laptop a certificate whose key can’t leave the machine. Turn it on and a stolen password on a personal laptop gets nowhere.

Every connection gets checked

Before a packet gets through, Firezone checks who you are, which device you’re on, and whether it’s healthy. Intune, Defender, SentinelOne, and others report the device’s health.

Start with ready-made checks like disk encryption and an up-to-date OS. When you need something specific, write the rule in JSON.

connection.log

dana@corp.example → postgres.internal:5432
  ✓ identityOkta, member of Engineering
  ✓ devicecertificate attested by TPM
  ✓ posturedisk encrypted, OS current, 0 threats
  ● tunnelup, direct, no relay

policy.json

{ "and": [
  { "field": "intune.is_encrypted",
    "op": "is", "value": true },
  { "field": "intune.last_sync_at",
    "op": "within_last", "value": "PT24H" },
  { "field": "sentinelone.active_threats",
    "op": "eq", "value": 0, "rows": "all" }
] }

Know who accessed what

Firezone logs every sign-in, admin change, API call, and network flow, on every plan. Each flow shows who connected, from which device, to what, and how much data moved. Both ends of the tunnel report it, so faked numbers stand out.

Pull logs from the API, or on Business and Enterprise, stream them to your SIEM.

you@laptop: ~

$ curl -s "$FZ_API/logs?type=flow" \
    -H "Authorization: Bearer $FZ_TOKEN" | jq '.data[0]'
{
  "log_id": "f4e8a2c61b09d735e2a48b17",
  "initiator_actor_email": "riley@corp.example",  "initiator_device_os_name": "macOS",
  "initiator_device_serial": "C02XG2JHJG5J",
  "policy_id": "3e9b7c1a-52d4-4f8e-a0c6-81d2f5b9e470",
  "resource_name": "postgres.internal",  "inner_dst_port": 5432,
  "tx_bytes": 48213,
  "rx_bytes": 9120344}

Simple to roll out

A Gateway is a small Linux binary. Run it next to your resources with a token and you’re done. Most teams are set up in under ten minutes.

# docker-compose.yml
services:
  firezone-gateway:
    image: ghcr.io/firezone/gateway:1
    environment:
      FIREZONE_TOKEN: <token>
    # Networking options are in the Docker guide
Deploy your first Gateway

Clients for every device your team uses

10 s
to fail over to a healthy Gateway in the same Site
Fresh keys
on every sign-in, and they never leave device memory

Teams that switched

“At Strong Compute, we have been using Firezone for over 3 years and it is still the most stable and best VPN solution we tested for remote access.”
Cian ByrneFounding Engineer, Strong Compute
“When producing live broadcasts for Fortune 500 companies security is of the utmost importance. We therefore selected Firezone for its robust WireGuard-based architecture. The flexible policy system and simple & clean user experience make Firezone the best fitting product for us in the market after trying several other solutions like Tailscale, OpenVPN, and Nebula.”
Robert BuismanCEO, NOMOBO
“Firezone's easy-to-setup, sleek, and simple interface makes management effortless. It perfectly met our zero-trust security needs without the complexity found in other products we tested.”
Mark SimTechnical Account Manager, Beakon
“After comparing Tailscale, we ultimately chose Firezone to secure access to our data warehouses. Firezone's ease of configuration and robust policy-based access system made it the clear choice for our needs.”
James WinegarCEO, Corrdyn

Works with what you already use

Connect your identity provider, MDM, endpoint security, and SIEM. Manage the rest as code with Terraform or the REST API.

See all integrations

Open source, so you can check our work

How can you trust a zero trust product if you cannot read its code? Firezone is built in the open on GitHub, from the Clients and Gateways to the control plane.

Read the source on GitHub
ROSS Index - Fastest Growing Open-Source Startups in Q2 2022 | Runa Capital
GitHub stars on firezone/firezoneAs of Oct 2026
02,5005,0007,50010,0002021202220232024202520269,108 stars

GitHub stars on firezone/firezone by month
MonthStars
May 20201
Jun 20201
Jul 20202
Aug 20202
Sep 20202
Oct 20202
Nov 20202
Dec 20202
Jan 20212
Feb 20212
Mar 20212
Apr 20212
May 20212
Jun 20213
Jul 20213
Aug 20213
Sep 2021398
Oct 2021653
Nov 2021721
Dec 2021882
Jan 2022983
Feb 20221,084
Mar 20221,342
Apr 20221,464
May 20221,871
Jun 20222,146
Jul 20222,326
Aug 20222,517
Sep 20222,664
Oct 20222,838
Nov 20223,042
Dec 20223,206
Jan 20233,374
Feb 20233,510
Mar 20233,653
Apr 20233,814
May 20233,969
Jun 20234,135
Jul 20234,294
Aug 20234,532
Sep 20235,004
Oct 20235,149
Nov 20235,291
Dec 20235,438
Jan 20245,586
Feb 20245,708
Mar 20245,847
Apr 20245,934
May 20246,030
Jun 20246,113
Jul 20246,250
Aug 20246,403
Sep 20246,486
Oct 20246,580
Nov 20246,648
Dec 20246,717
Jan 20256,798
Feb 20256,861
Mar 20256,933
Apr 20257,008
May 20257,103
Jun 20257,202
Jul 20257,294
Aug 20257,357
Sep 20257,675
Oct 20258,078
Nov 20258,155
Dec 20258,228
Jan 20268,291
Feb 20268,353
Mar 20268,477
Apr 20268,533
May 20268,585
Jun 20268,681
Jul 20268,955
Aug 20269,029
Sep 20269,103
Oct 20269,108