CitiumSoftwareby Cloudfragments
Sovereign edge tunnel · Design-partner pilot open

ZenoTunnel

No open ports. No peeking.

ZenoTunnel publishes services from your Kubernetes cluster or server through European edges. Your side dials out, so you open no inbound ports. The edge routes your traffic but never decrypts it: TLS ends inside your infrastructure.

0
Inbound ports
~5 MB
Edge memory
TLS 1.3
Post-quantum by default
EU
Infrastructure only
How it works

Three steps. Zero inbound ports.

One small connector on your side, a DNS record, and your own TLS. Nothing listens on your network.

1. Install the connector

Add it to your Kubernetes cluster with Helm, or run it on any Linux host. It opens one outbound, post-quantum TLS connection to our EU edges.

2. Point your hostname at us

Add a DNS record for your hostname. We verify that the domain is yours and route it to your tunnel. No load balancer, NAT rules or firewall holes.

3. Your WAF, in your cluster

Visitors' TLS travels down the tunnel still encrypted. It ends in ZenoIngress or the proxy you already run, where your own WAF and policies inspect it.

Private by design

We route your traffic. We can't read it.

Every TLS connection starts with a short, unencrypted greeting that names the website the visitor wants: the server name, or SNI. The ZenoTunnel edge reads that one field, picks your tunnel and passes the rest along exactly as it arrived, still encrypted. The keys that unlock the traffic live only in your infrastructure.

Certificates issued on your side

The connector answers the ACME challenge through the tunnel, so the private key never leaves your cluster.

Gateway API native

Publish with an HTTPRoute and keep TLS and WAF policy in Git, next to the rest of your cluster configuration.

Leaving is a DNS change

Your keys and rules already live with you. There is nothing to migrate out of our edge.

Verifiable audit log

ZenoTunnel keeps a tamper-evident audit log that you can verify yourself.

Built on ZenoIngress

The edge and the reverse tunnel run on the ZenoIngress engine: memory-safe Rust with a footprint of about 5 MB.

EU infrastructure only

EU and Swiss infrastructure and an EU legal entity. No US hyperscaler sits in the data path.

Developers

A few commands, then it stays out of your way.

The zt CLI handles domains, tunnels and hostnames. Run more connector replicas for more capacity; each edge sends a visitor to the least-loaded one.

# 1. Verify your domain
$ zt domains add example.eu
$ zt domains verify example.eu --wait 10m

# 2. Create a tunnel and install the connector
$ zt tunnels create prod-k8s
$ helm install zt zenotunnel/connector \
    --namespace zenotunnel --create-namespace \
    --set enrolment.token="$ZT_TOKEN"

# 3. Publish. Passthrough is the default.
$ zt hostnames publish app.example.eu --tunnel prod-k8s
Two ways to buy

Managed in the EU, or entirely yours

Use the managed service, or license the whole stack and run it yourself.

ZenoTunnel EU

Managed service

We run the edges and the control plane on EU infrastructure. You install the connector and publish. The design-partner pilot has 8 slots: free for 8 weeks, best effort.

ZenoTunnel Platform

Platform licence

License the complete stack (control plane, edges and connectors) and run it in your own data centres, sovereign cloud or air-gapped network. No dependency on us as an operator. From €32,000 per year; evaluation licence on request.

Publish without opening a port

Join the design-partner pilot or talk to us about a platform licence for your own infrastructure.