Built by the team behind OpenVPN

The ZTNA adminwho never reads docs and never sleeps.

Deploy zero-trust network access by typing what you want.

Deploy a gateway in US-East.

Ask. We’ll answer. No dashboards, no CLI, no certifications.

How it works

Three steps.
No IT team required.

01

Sign up & link your cloud

One-time Google sign-in. Connect your GCP project with a single click.

02

Say “deploy a gateway”

Chat with the AI. It provisions a secure gateway in your own cloud in under 3 minutes.

03

Admin shares the config, the team connects

Admin shares the connection config. Admin picks WireGuard or OpenVPN at workspace creation — both at kernel-grade performance. Team members connect with any standard client. Traffic flows through your gateway.

Why Cipherscale

Enterprise zero trust,
without the enterprise tax.

Traditional ZTNA is built for enterprises with dedicated security teams, six-figure budgets, and weeks to spare. Cipherscale is built for everyone else.

Cipherscale
Traditional ZTNA
Deploy time
Under 5 minutes, from a chat
Weeks of setup, consultants, training
Management
Natural-language AI chat
Dashboards, CLIs, six-figure contracts
Data control
Gateway runs in YOUR cloud
Traffic flows through the vendor’s cloud
Routing
Internet + your VPC by default, other private networks stay local
Often all-or-nothing tunnel policies
Pricing
Free today. Paid tiers as the product matures.
Enterprise-only, annual commits

Built for your stage.

Startups (1–10 seats)

Get zero trust for free.

Five seats on the free tier. Connect your whole team in an afternoon.

Growing teams (10–100 seats)

Self-serve as you scale.

Admin picks WireGuard or OpenVPN at workspace creation. WireGuard for stateless simplicity; OpenVPN with DCO for connection-oriented load distribution — both at kernel-grade performance. Each member gets their connection config — QR code or download for WireGuard workspaces; download or OpenVPN Connect deep-link for OpenVPN workspaces. Admin manages gateway lifecycle from chat.

Where we’re heading

Building incrementally. On our roadmap:

Dual-protocol workspaces — admin picks WireGuard or OpenVPN with DCO at workspace creation; WireGuard for stateless simplicity, OpenVPN for connection-oriented load distribution; both at kernel-grade performance

Multi-cloud gateways (GCP and DigitalOcean today; AWS and Azure planned)

Production-tier launch — public commercial release

Visitor AI Q&A — pre-auth chat for prospects

Private app access and governed SaaS access (zero-trust pillars)

Enterprise features — SAML/SSO, audit logging, fine-grained policy engine

The zero-trust model

Every user, every device, every session — verified before the tunnel opens.

  • Identity-based access Your team signs in with Google; we verify every session.
  • Your infrastructure, your keys The gateway runs in your cloud. Your data never touches ours.
  • No trust perimeter — never Every connection is authenticated and encrypted. No “inside” vs “outside” shortcuts.

About

Built by the people who built OpenVPN.

Cipherscale is built by the team behind OpenVPN — the VPN trusted by 20 million+ users. We spent two decades making secure networking work for companies of every size, and we kept hearing the same thing from smaller teams: “We want zero trust, but we can’t afford a six-month deployment and a dedicated security hire.” Cipherscale is our answer. The engineering you’d expect from OpenVPN, delivered through a chat.