v1.0 Now Available

Stop Trusting IPs.
Start Trusting Identities.

Zylock is the self-hosted VPN replacement that knows who is connecting, not just what. Single binary. WireGuard speed. SOC2-ready visibility.

✓ Linux Server ✓ Windows Client ✓ OIDC Ready
🛡️

Identity-First Security

Replace shared keys with OIDC/SSO (Google, Okta, Azure). Approve users via admin dashboard before they connect.

WireGuard Speed

Modern kernel-space cryptography. High throughput, low latency, and resistant to network scanning.

👁️

Audit & Compliance

Immutable append-only logs. Know exactly who accessed what, when they logged in, and when they were revoked.

Traditional VPN vs. Zylock

The "Bouncer" for your private network.

❌ Legacy VPN

  • "Here is a key, you are now trusted forever."
  • Logs show IP addresses, not names.
  • Revocation is manual and difficult.

✅ The Zylock Way

  • User logs in via SSO (MFA enforced by IDP).
  • Device authenticates via mTLS certificates.
  • Admin can kill sessions instantly.

Choose Your Architecture

Why teams are moving away from both SaaS rental and legacy hardware.

Your Choice
Zylock
Modern Self-Hosted
SaaS ZTNA
Vendor Cloud
Legacy VPN
The "Castle" Model
Control Plane Location 🏠 Your Server
100% Data Ownership
☁️ Vendor Cloud
Metadata leaks externally
🏢 On-Prem
Requires heavy appliances
Authentication ✅ OIDC / SSO ✅ OIDC / SSO ❌ LDAP / Shared Keys
Installation Single Binary Agent + Cloud Acct Complex Appliance
Audit Visibility User + Device + IP User + IP IP Only (Blind)
Protocol ⚡ WireGuard ⚡ WireGuard / Proprietary 🐌 IPsec / OpenVPN

Thinking about DIY Open Source? Raw WireGuard is fast, but managing keys and config files for a whole team is a nightmare. Zylock gives you the UI and SSO you're missing.

Active Development

The Trajectory

We are building a system engineers trust even when it's quiet.
Here is what ships next.

Q1 2026

Governance & Granularity

  • Resource-Level Policies: Define access rules per service/network (Prod vs. Staging).
  • RBAC: Scoped permissions for Admins, Operators, and Viewers.
Q2 2026

Operational Resilience

  • Break-Glass Mode: Time-limited, auditable overrides for emergency outages.
  • Device Trust Signals: Gate access based on OS version and disk encryption status.

"Zylock avoids features that increase complexity without strategic payoff. No AI gimmicks. No alert fatigue."