Everything in one mesh platform
From NAT traversal and split tunneling to SSO, posture checks, and Terraform — Kimox ships the connectivity and security primitives platform teams expect without appliance sprawl.
Network connectivity
Encrypted mesh paths across clouds, NAT traversal, and DNS — without opening firewall ports.
Direct peer tunnels
Nodes negotiate encrypted paths to each other first. Relay hops activate only when NAT or firewall geometry blocks a direct route.
Learn moreAutomatic NAT traversal
UDP hole punching, STUN discovery, and coordinated relay fallback — no inbound port forwarding on your edge routers.
Learn moreMulti-cloud mesh
AWS, GCP, Azure, and bare metal join the same overlay. Stable identities replace brittle CIDR spreadsheets.
Learn moreMagicDNS
Every node gets a predictable hostname on the mesh. Internal services resolve without maintaining a separate DNS zone file.
Learn moreSplit tunneling
Route only corporate prefixes through Kimox. Personal browsing stays local so remote engineers keep full bandwidth.
Learn moreExit nodes
Designate trusted gateways when all traffic must egress through a known IP — useful for vendor allowlists and geo compliance.
Learn moreAccess control
Identity-based policies that follow workloads — not IP subnets that break on every deploy.
Tag-based ACLs
Authorize traffic by identity tags, not IP subnets. Policies survive migrations, autoscaling, and cluster rebuilds.
Learn moreMFA enforcement
Require step-up authentication for sensitive tags. Integrates with your existing IdP without custom middleware.
Learn moreContinuous authorization
Sessions re-evaluate group membership and posture signals. Revoked access tears down active tunnels within seconds.
Learn moreDevice posture
Verify device health before a tunnel comes up — block risky endpoints at the edge.
Device posture checks
Block connections from outdated OS builds, missing disk encryption, or absent EDR agents before a tunnel comes up.
Learn moreMonitoring & logging
Immutable connection events for debugging, compliance, and incident response.
Connection audit logs
Every handshake, policy denial, and relay fallback is logged with actor, device, and destination metadata.
Learn moreUser management
Provision and deprovision mesh access from the identity tools your team already runs.
SSO and SCIM
Provision users and groups from your identity provider. Offboarding in Okta-style tools removes mesh access automatically.
Learn moreAccess request workflows
Engineers request time-bound grants to production tags. Managers approve in Slack or the admin console.
Learn morePolicy & compliance
Draft, preview, and roll out mesh policy with audit trails built for regulated teams.
Central policy console
Draft ACL changes, preview blast radius, and roll out to staging tags before promoting to production.
Learn moreCompliance exports
Generate SOC 2 and HIPAA-friendly reports from immutable audit streams — no scraping syslog servers.
Learn morePhased rollout controls
Pin policies to specific groups or regions. Expand mesh membership incrementally without a big-bang cutover.
Learn moreIntegrations
Declare mesh infrastructure in code and wire Kimox into your existing toolchain.
Terraform provider
Declare nodes, ACLs, and DNS records in HCL. Mesh changes go through the same PR review as the rest of your infra.
Learn moreGitOps-friendly API
Export effective policy as YAML, diff against main, and apply via CI. No click-ops required for production changes.
Learn moreKubernetes operator
Helm chart and operator annotate pods for mesh membership. Sidecar or host-network modes fit your cluster constraints.
Learn moreClients & deployment
Native agents and bootstrap paths for laptops, servers, and CI runners.
Native clients
Lightweight agents for macOS, Windows, Linux, iOS, and Android. Same auth flow everywhere your team works.
Learn moreOne-line bootstrap
curl | sh for servers, MDM packages for laptops, and prebuilt container images for CI runners — live in minutes.
Learn moreFirst-class CLI
Inspect peers, tail connection events, and debug ACL denials from your terminal. Scriptable output for automation.
Learn moreReady to simplify your network?
Start free with up to 3 users. Scale when your team does.
Get started free