event/2026Kimox Connect 2026 — register for our virtual networking summit Reserve your spot

features.platform

Everything in one mesh platform

From NAT traversal and split tunneling to SSO, posture checks, and Terraform — Kimox ships the connectivity and security primitives platform teams expect without appliance sprawl.

Network connectivity

Encrypted mesh paths across clouds, NAT traversal, and DNS — without opening firewall ports.

Direct peer tunnels

Nodes negotiate encrypted paths to each other first. Relay hops activate only when NAT or firewall geometry blocks a direct route.

Learn more

Automatic NAT traversal

UDP hole punching, STUN discovery, and coordinated relay fallback — no inbound port forwarding on your edge routers.

Learn more

Multi-cloud mesh

AWS, GCP, Azure, and bare metal join the same overlay. Stable identities replace brittle CIDR spreadsheets.

Learn more

MagicDNS

Every node gets a predictable hostname on the mesh. Internal services resolve without maintaining a separate DNS zone file.

Learn more

Split tunneling

Route only corporate prefixes through Kimox. Personal browsing stays local so remote engineers keep full bandwidth.

Learn more

Exit nodes

Designate trusted gateways when all traffic must egress through a known IP — useful for vendor allowlists and geo compliance.

Learn more

Access control

Identity-based policies that follow workloads — not IP subnets that break on every deploy.

Tag-based ACLs

Authorize traffic by identity tags, not IP subnets. Policies survive migrations, autoscaling, and cluster rebuilds.

Learn more

MFA enforcement

Require step-up authentication for sensitive tags. Integrates with your existing IdP without custom middleware.

Learn more

Continuous authorization

Sessions re-evaluate group membership and posture signals. Revoked access tears down active tunnels within seconds.

Learn more

Device posture

Verify device health before a tunnel comes up — block risky endpoints at the edge.

Device posture checks

Block connections from outdated OS builds, missing disk encryption, or absent EDR agents before a tunnel comes up.

Learn more

Monitoring & logging

Immutable connection events for debugging, compliance, and incident response.

Connection audit logs

Every handshake, policy denial, and relay fallback is logged with actor, device, and destination metadata.

Learn more

User management

Provision and deprovision mesh access from the identity tools your team already runs.

SSO and SCIM

Provision users and groups from your identity provider. Offboarding in Okta-style tools removes mesh access automatically.

Learn more

Access request workflows

Engineers request time-bound grants to production tags. Managers approve in Slack or the admin console.

Learn more

Policy & compliance

Draft, preview, and roll out mesh policy with audit trails built for regulated teams.

Central policy console

Draft ACL changes, preview blast radius, and roll out to staging tags before promoting to production.

Learn more

Compliance exports

Generate SOC 2 and HIPAA-friendly reports from immutable audit streams — no scraping syslog servers.

Learn more

Phased rollout controls

Pin policies to specific groups or regions. Expand mesh membership incrementally without a big-bang cutover.

Learn more

Integrations

Declare mesh infrastructure in code and wire Kimox into your existing toolchain.

Terraform provider

Declare nodes, ACLs, and DNS records in HCL. Mesh changes go through the same PR review as the rest of your infra.

Learn more

GitOps-friendly API

Export effective policy as YAML, diff against main, and apply via CI. No click-ops required for production changes.

Learn more

Kubernetes operator

Helm chart and operator annotate pods for mesh membership. Sidecar or host-network modes fit your cluster constraints.

Learn more

Clients & deployment

Native agents and bootstrap paths for laptops, servers, and CI runners.

Native clients

Lightweight agents for macOS, Windows, Linux, iOS, and Android. Same auth flow everywhere your team works.

Learn more

One-line bootstrap

curl | sh for servers, MDM packages for laptops, and prebuilt container images for CI runners — live in minutes.

Learn more

First-class CLI

Inspect peers, tail connection events, and debug ACL denials from your terminal. Scriptable output for automation.

Learn more
deploy.mesh

Ready to simplify your network?

Start free with up to 3 users. Scale when your team does.

Get started free