sys.status: online
secure remote access for field devices

A secure URL for every device.

Give every field device a cryptographic identity and a private or public URL — without opening a port.

  • no inbound ports
  • mutual TLS
  • zero-knowledge relay
  • one static binary
Outbound only
No firewall holes or exposed device ports.
Per-device identity
Each agent connects with its own certificate.
Payload private
The relay routes passthrough traffic without decrypting it.
SEC.01 DEPLOY SEQUENCE
How it works

Online in three steps

Works behind NAT, CGNAT, and strict firewalls — no inbound ports, no runtime to install, one static binary.

01 — Register

Register the device

Add a device in the console and choose how its services are exposed.

02 — Install

Run the agent

Download a preconfigured agent or mint an enrollment token, run one installer, and the device connects itself.

03 — Reach

Reach it anywhere

The device dials out to the relay; you reach it by hostname. It opens no inbound ports.

InternetusersRelayzero-knowledgeDeviceoutbound onlyTLS / SNImTLS (dials out)
SEC.02 SYSTEM PROPERTIES
Built for fleets, not demos

Boring where it counts. Sharp where it matters.

Per-device PKI

Every device holds its own CA-issued certificate. The private key is generated on the device and never leaves it.

Zero-knowledge passthrough

Passthrough traffic is never decrypted at the relay. We route by TLS SNI without reading a single byte of your payload.

Hostname routing

Many devices share one address, demultiplexed by hostname — no port-per-device sprawl.

Fast revocation

Revoke a device and its live tunnels drop in seconds — the relay re-checks certificate status continuously.

Isolated organizations

Every resource belongs to an organization, and the boundary is enforced and adversarially tested in CI.

Gateway fan-out

One agent can expose anything on the device network — cameras, PLCs, gateways — each service behind its own route.

Edge access rules

Attach IP allowlists, basic auth, or mutual-TLS to a route as edge access rules.

Account security

Console accounts get role-based access, optional TOTP two-factor, and an append-only audit trail.

Simple infrastructure

The relay avoids extra queueing layers and keeps the operating model straightforward.

SEC.03 OPERATOR DOCS
Your traffic is yours

The relay never reads your bytes

Passthrough traffic is never decrypted at the relay. We route by TLS SNI without reading a single byte of your payload.

Read the security model
SEC.04 RESOURCE TIERS
Init sequence

Bring your first device online

Free tier, no card required.