Early access

One private network across all your sites

BoreasTUN SD-WAN joins your offices, data centres, cloud environments and branch routers into a single private network. You decide once what is allowed to talk to what — and every location follows, automatically.

Closed until you open it
Nothing can reach anything by default. You grant access deliberately, and only what you grant is possible.
Always takes the better line
Where a site has more than one internet connection, traffic moves to the healthier one on its own — before people start noticing a bad call.
Your existing logins
Administrators sign in with the company accounts you already use, so joiners and leavers are handled where you handle them today.
Encrypted end to endRuns on hardware you already ownEvery change recorded

How it works

Four steps. After the first two, the network largely looks after itself.

1. Add a site
Install the agent and give it a one-time invitation. It introduces itself and gets its own identity.
2. Write the rules
Say which sites and networks may reach which. Plain statements, kept in one place.
3. Publish
Every site receives the same sealed copy of the rules and checks it is genuine before applying it.
4. It stays put
Sites reapply the rules after a reboot, and a change that turns out badly is rolled back on its own.

What you can do with it

Link branch offices privately
Reach cloud networks as if local
Keep two internet lines useful
Cut off a lost device instantly
Give contractors narrow access
Connect a site in minutes
See who changed what, and when
Prove what the rules were

Built for the places you already run

No proprietary appliance to buy. It runs on the servers, firewalls and routers most networks already have.

Linux servers
In your data centre or at a hosting provider, on Intel or ARM.
pfSense firewalls
Adds site-to-site connectivity to the firewall already at the edge of your office.
Small routers
Compact OpenWrt hardware is enough for a branch, a workshop or a home office.
Cloud networks
Bring a cloud environment onto the same private network as your offices.

Organisations with several offices

One network across every location, without a separate tunnel to hand-configure for each pair of sites.

Teams spread across clouds

Treat cloud and on-premises networks as one, with the same rules applying to both.

Anyone who has to show their work

Every rule change and every device is recorded, so an auditor's questions have answers.

How this relates to the uWAN apps

Two different jobs, sharing the same encryption underneath.

The uWAN apps
For one person and their devices. You install the app, sign in, pick a location and your traffic is private. Nothing to administer.
BoreasTUN SD-WAN
For whole sites. Your IT team runs it, sets the rules centrally, and every location follows them — people at those sites do not install anything.

Where the product is today

BoreasTUN SD-WAN is in early access. It runs today across Linux, pfSense and OpenWrt hardware in our pilot network, and we are working with a small number of organisations to prove it in real deployments before a general release.

If that sounds like a fit — or if you would rather wait for the general release and hear about it when it lands — get in touch and we will be straight with you about what is ready and what is not.

Interested in connecting your sites?

Tell us how many locations you have and what you need to reach. We will tell you whether we can help today.

BoreasTUN Logo
uWAN