Perimeter0

Self-hosted Zero Trust
Network Access

WireGuard-powered peer-to-peer tunnels, access policies, and MagicDNS — all running on your infrastructure.

Everything you need to secure your network

WireGuard-Encrypted Tunnels

Every peer-to-peer connection is secured with WireGuard — the fastest, most auditable VPN protocol available.

Zero-Trust Access Policies

Define fine-grained ACL rules to control exactly which peers can reach which resources, with default-deny enforcement.

Self-Hosted & On-Prem

Run the management plane, signal server, and relay entirely on your own infrastructure — no third-party cloud required.

MagicDNS

Automatically assign stable DNS names to every enrolled device so you never need to remember IP addresses again.

Subnet Routing

Expose entire on-prem subnets through a single agent, giving remote peers seamless access to internal services.

Audit Log

Every administrative action is recorded with timestamp and actor so you always have a complete trail.

How it works

  1. 1

    Install the agent

    One binary, zero dependencies. Runs on Linux, macOS, and Windows.

  2. 2

    Login & enrol

    Authenticate with your identity provider — the device is enrolled automatically.

  3. 3

    Access your network

    Peers connect directly via WireGuard tunnels. No traffic leaves through the relay unless needed.

Ready to get started?

Deploy in minutes on your own infrastructure.

Get Started Free