Give your team fast, direct access to the servers and apps they need, and give attackers nothing to find. Setup takes minutes.
Most VPNs choke the moment you ask them to move real data. Firezone’s data plane is written in Rust, built on WireGuard®, and tuned for each operating system, so devices connect straight to the nearest Gateway and the link, not the software, sets the limit.
How the architecture worksThroughput varies with round-trip latency, packet loss, hardware, network capacity, and workload.
Packets travel in batches instead of one at a time, so your device spends its time moving data, not shuffling it.
Your operating system and network card take over the repetitive jobs whenever they can, which frees the CPU for everything else.
New connections are usually ready in 200 ms or less. If a direct path is blocked, traffic hops through one of 34 relay clusters that keep up at line rate for most workloads.
Attackers can’t attack what they can’t see. Firezone hides your network, ties access to your identity provider, and turns away every device you don’t own.
Gateways only make outbound connections. They never listen for traffic from the internet, so there are no open ports to find and nothing to attack. You don’t touch your firewall at all. If a direct path isn’t possible, traffic goes through the nearest of 34 relay clusters, so it stays fast on any network.
you@laptop: ~
$ nmap -Pn -p- gateway.corp.example
Starting Nmap 7.95
Nmap scan report for gateway.corp.example
All 65535 scanned ports are in ignored states.
Not shown: 65535 filtered tcp ports (no-response)
Nmap done: 1 IP address (1 host up)Firezone syncs users and groups from Okta, Entra ID, and Google Workspace. Deactivate someone there and they’re signed out of every device. There’s no second list to clean up.
Signature verified over mutual TLS
Your MDM gives each laptop a certificate whose key can’t leave the machine. Turn it on and a stolen password on a personal laptop gets nowhere.
Passing one login check once isn’t enough. Before a single packet gets through, Firezone asks who you are, which device you’re on, and whether it’s healthy. Intune, Defender, SentinelOne, and others report the answers.
Start with ready-made checks like disk encryption and an up-to-date OS. When you need something specific, write the rule in JSON.
connection.log
dana@corp.example → postgres.internal:5432
✓ identityOkta, member of Engineering
✓ devicecertificate attested by TPM
✓ posturedisk encrypted, OS current, 0 threats
● tunnelWireGuard® tunnel up, direct, no relaypolicy.json
{ "and": [
{ "field": "intune.is_encrypted",
"op": "is", "value": true },
{ "field": "intune.last_sync_at",
"op": "within_last", "value": "PT24H" },
{ "field": "sentinelone.active_threats",
"op": "eq", "value": 0, "rows": "all" }
] }When something looks off, you want answers, not guesses. Firezone logs every sign-in, admin change, API call, and network flow, on every plan. Each flow shows who connected, from which device, to what, and how much data moved. Both ends of the tunnel report it, so faked numbers stand out.
Pull logs from the API, or on Business and Enterprise, stream them to your SIEM.
you@laptop: ~
$ curl -s "$FZ_API/logs?type=flow" \
-H "Authorization: Bearer $FZ_TOKEN" | jq '.data[0]'
{
"log_id": "f4e8a2c61b09d735e2a48b17",
"initiator_actor_email": "riley@corp.example", "initiator_device_os_name": "macOS",
"initiator_device_serial": "C02XG2JHJG5J",
"policy_id": "3e9b7c1a-52d4-4f8e-a0c6-81d2f5b9e470",
"resource_name": "postgres.internal", "inner_dst_port": 5432,
"tx_bytes": 48213,
"rx_bytes": 9120344}connections secured, and counting
Each one an authenticated, encrypted WireGuard® tunnel before a single packet moved.
Thousands
of organizations trust Firezone
to keep them secure.
A Gateway is a small Linux binary that ends your WireGuard® tunnels. Run it next to your resources with a token and you’re done. Most teams are set up in under ten minutes.
# docker-compose.yml
services:
firezone-gateway:
image: ghcr.io/firezone/gateway:1
environment:
FIREZONE_TOKEN: <token>
# Networking options are in the Docker guideThe ideas are the same, only the names change. Here is what everything is called on the Firezone side.
Run side by side
Deploy a Gateway next to your resources. Your old VPN keeps working.
Recreate access
Add Resources and Policies for the same people and servers.
Move people over
Install the Client, sign in, and switch off the old tunnel.
“At Strong Compute, we have been using Firezone for over 3 years and it is still the most stable and best VPN solution we tested for remote access.”
Cian ByrneFounding Engineer, Strong Compute“When producing live broadcasts for Fortune 500 companies security is of the utmost importance. We therefore selected Firezone for its robust WireGuard-based architecture. The flexible policy system and simple & clean user experience make Firezone the best fitting product for us in the market after trying several other solutions like Tailscale, OpenVPN, and Nebula.”
Robert BuismanCEO, NOMOBO“Firezone's easy-to-setup, sleek, and simple interface makes management effortless. It perfectly met our zero-trust security needs without the complexity found in other products we tested.”
Mark SimTechnical Account Manager, Beakon“After comparing Tailscale, we ultimately chose Firezone to secure access to our data warehouses. Firezone's ease of configuration and robust policy-based access system made it the clear choice for our needs.”
James WinegarCEO, CorrdynNo rip and replace. Plug in your identity provider, MDM, endpoint security, and SIEM, then manage the rest as code with Terraform or the REST API.
See all integrationsHow can you trust a zero trust product if you cannot read its code? Firezone is built in the open on GitHub, from the Clients and Gateways to the control plane.
Read the source on GitHub| Month | Stars |
|---|---|
| May 2020 | 1 |
| Jun 2020 | 1 |
| Jul 2020 | 2 |
| Aug 2020 | 2 |
| Sep 2020 | 2 |
| Oct 2020 | 2 |
| Nov 2020 | 2 |
| Dec 2020 | 2 |
| Jan 2021 | 2 |
| Feb 2021 | 2 |
| Mar 2021 | 2 |
| Apr 2021 | 2 |
| May 2021 | 2 |
| Jun 2021 | 3 |
| Jul 2021 | 3 |
| Aug 2021 | 3 |
| Sep 2021 | 398 |
| Oct 2021 | 653 |
| Nov 2021 | 721 |
| Dec 2021 | 882 |
| Jan 2022 | 983 |
| Feb 2022 | 1,084 |
| Mar 2022 | 1,342 |
| Apr 2022 | 1,464 |
| May 2022 | 1,871 |
| Jun 2022 | 2,146 |
| Jul 2022 | 2,326 |
| Aug 2022 | 2,517 |
| Sep 2022 | 2,664 |
| Oct 2022 | 2,838 |
| Nov 2022 | 3,042 |
| Dec 2022 | 3,206 |
| Jan 2023 | 3,374 |
| Feb 2023 | 3,510 |
| Mar 2023 | 3,653 |
| Apr 2023 | 3,814 |
| May 2023 | 3,969 |
| Jun 2023 | 4,135 |
| Jul 2023 | 4,294 |
| Aug 2023 | 4,532 |
| Sep 2023 | 5,004 |
| Oct 2023 | 5,149 |
| Nov 2023 | 5,291 |
| Dec 2023 | 5,438 |
| Jan 2024 | 5,586 |
| Feb 2024 | 5,708 |
| Mar 2024 | 5,847 |
| Apr 2024 | 5,934 |
| May 2024 | 6,030 |
| Jun 2024 | 6,113 |
| Jul 2024 | 6,250 |
| Aug 2024 | 6,403 |
| Sep 2024 | 6,486 |
| Oct 2024 | 6,580 |
| Nov 2024 | 6,648 |
| Dec 2024 | 6,717 |
| Jan 2025 | 6,798 |
| Feb 2025 | 6,861 |
| Mar 2025 | 6,933 |
| Apr 2025 | 7,008 |
| May 2025 | 7,103 |
| Jun 2025 | 7,202 |
| Jul 2025 | 7,294 |
| Aug 2025 | 7,357 |
| Sep 2025 | 7,675 |
| Oct 2025 | 8,078 |
| Nov 2025 | 8,155 |
| Dec 2025 | 8,228 |
| Jan 2026 | 8,291 |
| Feb 2026 | 8,353 |
| Mar 2026 | 8,477 |
| Apr 2026 | 8,533 |
| May 2026 | 8,585 |
| Jun 2026 | 8,681 |
| Jul 2026 | 8,955 |
| Aug 2026 | 9,029 |
| Sep 2026 | 9,103 |
| Oct 2026 | 9,108 |