Dedicated servers with static IPs. WireGuard encryption. Zero open ports. Cloud managed or self-hosted.
How It Works
Choose a region or install on your own infrastructure. Your dedicated server is ready in 30 seconds.
Create device tokens from the dashboard. Each team member gets a unique token to connect securely.
Install the client, paste the token, done. All traffic encrypted through your dedicated server.
Pick a server size, deploy in any location. Add more servers anytime.
10-day free trial · No charge until trial ends
| Plan | Starter | POPULAR Team | Business | Scale |
|---|---|---|---|---|
| Price | $9/mo | $19/mo | $39/mo | $59/mo |
| Devices per server | 15 devices | 50 devices | 100 devices | 250 devices |
| WireGuard encryption | ||||
| TLS transport | ||||
| Auto key rotation | ||||
| Mesh networking | — | |||
| Subnet routing | — | |||
| Dedicated static IP | ||||
| Priority support | — | — | ||
Unlimited devices, custom SLA, dedicated support.
All servers include: WireGuard encryption, TLS transport, connection failover, auto key rotation, minimal logging.
Comparison
Different tools for different needs. Here's how we compare.
| Feature | NexGuard | Tailscale | WireGuard |
|---|---|---|---|
| Dedicated server | Auto deploy (30s) | Manual (exit node) | Manual setup |
| Static public IP | ✓ Included | ✓ Via VPS exit node | ✓ Via VPS |
| Setup time | 30 seconds | ~5 minutes | 30+ minutes |
| Open ports needed | 0 | 0 | 1 UDP |
| Firewall compatible | ✓ Port 443 | △ DERP relay | ✗ Needs UDP |
| Connection failover | ✓ | △ Limited | ✗ Manual iptables |
| Key rotation | ✓ 24h automatic | ✓ 180d | ✗ Manual |
| Mesh networking | ✓ | ✓ Core feature | ✗ |
| Web dashboard | ✓ | ✓ | ✗ |
| Self-host option | ✓ Free tier | ✗ Headscale only | ✓ Native |
| Team pricing | From $5/mo per server | $6/user/mo | Free (DIY) |
| Max devices | 10,000+ | 100 (business) | Unlimited (manual) |
| Architecture | No coordination server | Metadata on their infra | Self-managed |
Your team needs dedicated network infrastructure with zero open ports, TLS transport, and managed servers. Compatible with corporate firewalls and NAT environments.
You need peer-to-peer mesh networking with great NAT traversal and mobile apps. Best for internal device-to-device connectivity.
You have the expertise to configure servers, manage keys, and write firewall rules manually. Maximum control, maximum effort.
Quick Start
Cloud managed or self-hosted — same client, same encryption.
Download
Client app for your team. Self-host the server for free or let us manage it.