Pick a plan that best suits your needs. No credit card required to sign up.
MonthlyAnnualSave 17%
Starter
Free
Secure remote access for individuals and small groups.
No credit card required.
Up to 6 users
Access your homelab or VPC from anywhere
Native clients for Windows, Linux, macOS, iOS, Android
Authenticate via email or OpenID Connect (OIDC)
Load balancing and automatic failover
No firewall configuration required
Community Support
Team
$5$4.16 per user/month
Zero trust network access for teams and organizations
Save 17% by switching to annual
Everything in Starter
plus
Up to 500 users
Resource access logs
Port and protocol traffic restrictions
Conditional access policies
Customize your account slug
Priority email support
Enterprise
30-day trial
Contact us
Compliance-ready security for large organizations
Everything in Starter and Team
plus
Unlimited users
Directory sync for Google, Entra ID, and Okta
Dedicated Slack support channel
Uptime SLAs
Access to our SOC2 and pentest reports
Roadmap acceleration
White-glove onboarding
Annual invoicing
Trusted by organizations like
Compare plans
Starter
Team
Enterprise
Users
Includes both admins and end-users of your Firezone account
6
500
Unlimited
Service Accounts
Machine accounts used to access Resources without a user present
10
100
Unlimited
Sites
Sites are a collection of Gateways and Resources that share the same network connectivity context. Typically a subnet or VPC.
10
100
Unlimited
Admins
Users with account-wide access to deploy Gateways, manage billing, and edit users, Sites, or other configuration
1
10
Unlimited
Policies
Policies control access to Resources (e.g. Group “A” may access Resource “B”)
Unlimited
Unlimited
Unlimited
Resources
Anything you wish to manage access to (e.g. database, VPC, home network, web server, SaaS application)
Unlimited
Unlimited
Unlimited
Connected Clients
Any device or machine that the Firezone Client connects from
3 per user
5 per user
Unlimited
Networking Features
NAT hole punching
Connect to Resources without opening inbound firewall ports
Native Firezone Clients
Native client apps for all major platforms
Split tunneling
Route traffic to Resources through Firezone leaving other traffic unaffected
IPv4 and IPv6 Resources
Connect to Resources over IPv4 or IPv6
Automatic NAT64
Connect to IPv6-only Resources from IPv4-only networks and vice-versa
DNS-based routing
Route traffic through Firezone based on DNS matching rules
Gateway load-balancing
Spread traffic across multiple Gateways within a Site
Automatic Gateway failover
Clients automatically switch from unhealthy Gateways to healthy ones
Full-tunnel routing
Route all traffic from select Clients through Firezone
—
Authentication & Authorization
Resource-level access policies
Control access to Resources based on user identity and group
Email (OTP) authentication
Authenticate users with a one-time code sent to their email
OpenID Connect authentication
Authenticate users with any OIDC-compatible provider
Conditional access policies
Allow access based on source IP, authentication method, time of day, or country.
—
Custom account slug
Customize the sign-in URL for your account. E.g. https://app.firezone.dev/your-organization
—
Google Workspace directory sync
Automatically sync users and groups from Google Workspace to Firezone
—
—
Microsoft Entra ID directory sync
Automatically sync users and groups from Microsoft Entra ID to Firezone
—
—
Okta directory sync
Automatically sync users and groups from Okta to Firezone
—
—
Security Features
Session-based key rotation
Rotate WireGuard encryption keys each time a user signs in
Client verification
Require Clients to be marked as verified in the admin portal before they can access Resources
GeoIP Mapping
Show where your users are connecting from
Resource access logs
See who accessed which Resource and when
—
Traffic restrictions
Restrict access to specific ports and protocols
—
Firezone service compliance reports
Independent audit reports of Firezone's service for compliance with industry standards
—
—
SOC 2
Firezone service pentest reports
Penetration testing for security vulnerabilities in Firezone's service conducted by a third party firm
—
—
40 hours
Support & Customer success
Community Forums
Community Discord
Priority Email
—
Dedicated Slack
—
—
Roadmap acceleration
Shape the product roadmap with customized features and integrations
—
—
White-glove onboarding
Get personalized deployment support and training for your team
—
—
Uptime SLA
Guaranteed uptime for your Firezone service
—
—
99.9%
Billing & payment
Payment by credit card
Pay for your subscription using a credit card
—
Payment by ACH transfer
Pay for your subscription using an ACH transfer
—
Payment by wire transfer
Pay for your subscription using a wire transfer
—
—
Annual invoicing
Pay for your subscription annually
—
—
FAQ
No. Firezone is a business VPN replacement, not a consumer VPN. It's a zero trust access platform that connects your organization's workforce to private resources like servers, databases, and internal apps. It isn't designed to anonymize your browsing or let you change your apparent location.
All of the source code for the entire Firezone product is available at our GitHub repository, and you're free to self-host Firezone for your organization without restriction. However, we don't offer documentation or support for self-hosting Firezone at this time.
No. As long they're set up to access different resources, you can run Firezone alongside your existing remote access solutions, and switch over whenever you're ready. There's no need for any downtime or unnecessary disruptions.
Yes. The Starter plan is free to use without limitation. No credit card is required to get started. The Enterprise plan includes a free pilot period to evaluate whether Firezone is a good fit for your organization. Contact sales to request a demo.
Yes.
For the Team plan, you can add or remove seats at any time. When adding seats, you'll be charged a prorated amount for the remainder of the billing cycle. When removing seats, the change will take effect at the end of the billing cycle.
For the Enterprise plan, contact your account manager to request a seat increase. You'll then be billed for the prorated amount for the remainder of the billing cycle.
Changes are effective immediately. You will be charged a prorated increase that reflects the additional seat count for the remainder of the billing cycle.
For example, if you are on a yearly Team plan and at month 6 you add 5 seats, the prorated charge is 5 * 50 * 0.5 = $125 and is billed when you make the change.
Seat decreases are applied only at the end of your current billing cycle (monthly or yearly). If you remove 5 seats, those seats remain paid through the end of the cycle and can be reassigned to other users.
We do not process refunds for seat-count decreases. Instead, the removed seats function as account credit until your billing cycle renews.
Network traffic is always end-to-end encrypted, and by default, routes directly to Gateways running on your infrastructure. In rare circumstances, encrypted traffic can pass through our global relay network if a direct connection cannot be established. Firezone can never decrypt the contents of your traffic.
For Starter and Team plans, you can downgrade by going to your Account settings in your Firezone admin portal. For Enterprise plans, contact your account manager for subscription updates. Ifyou'd like to completely delete your account, contact support.
The Team plan is billed monthly on the same day you start service until canceled. Enterprise plans are billed annually.
The annual discount is already included in the yearly Team price. To use annual billing, select annual when upgrading to Team in your Firezone admin portal.
The Starter plan is free and does not require a credit card to get started. Team and Enterprise plans can be paid via credit card, ACH, or wire transfer.
Yes. Not-for-profit organizations and educational institutions are eligible for a 50% discount. Contact sales to request the discount.