Built for people and small teams

Your network.
Your rules.

Securely connect trusted devices, private services and user-owned exits. Your devices hold the keys; you decide who gets in and where traffic leaves.

Available today · Secure mesh / Device access / Owned exits / Failover

01Device-held keysPrivate keys are generated and remain on the device
02User-owned exitsRoute through a home, office or server you control
03Encrypted meshRelays carry WireGuard ciphertext and never hold private keys

YOUR DEVICES, SERVICES AND PLACES

One trusted network that belongs to you.

Not a rented stranger’s IP. A secure path for approved devices back to your home, office and services you operate.

HOME
CAFÉHOME NAS

Reach your home NAS anywhere

Keep file services off the public internet. Once approved, your laptop reaches private addresses as if it were at home.

SMALL BUSINESS
LAPTOPOFFICE

Give office access to the right people

Grant access per person and device without a shared long-lived password. Revoke a device when someone leaves.

TRAVEL
PHONEOWN EXIT

Travel through an exit you own

Send IPv4, IPv6 and DNS through a home, office or cloud host you control, with fail-closed protection if the path breaks.

FROM IDENTITY TO NETWORK ACCESS

Verify once. Bind the device. Connect quietly.

Today this uses email verification and a one-time enrollment code. We do not present that as finished enterprise SSO; OIDC and Passkey are next.

  1. 01
    Verify identity

    An email code verifies the applicant; the control plane issues a short-lived, single-use enrollment code.

  2. 02
    Bind the device

    The client generates its key locally. Enrollment is bound to that device key; the private key is never uploaded.

  3. 03
    Connect by policy

    Approved devices prefer direct paths, falling back only to a RELAY authorized inside the same Tenant.

CLEAR, VISIBLE BOUNDARIES

Network privacy without vague promises.

01IPv4, IPv6 and DNS follow the selected exit, with fail-closed leak protection.

02Clients prompt you to review location services, browser permissions, WebRTC, Wi-Fi and Bluetooth scanning.

03We never silently change system permissions or claim to hide account history, time zone or every browser fingerprint.

SECURITY LEDGER

Shipped and pending, stated separately.

Shipped

Mandatory hybrid post-quantum security

TLS 1.3 permits only X25519MLKEM768. Every device pair derives a WireGuard PSK from an ML-KEM-768 shared secret. ML-KEM encapsulation is authenticated with ML-DSA-65; invalid signatures, key mismatches, and missing or invalid post-quantum sessions fail closed.

Shipped

Tenant relay forwards ciphertext only

A Tenant can authorize its own RELAY. It requires membership credentials and device-key proof and forwards WireGuard packets only.

Partial

Platform signing and external audit

Apple App Store, Android direct-release, macOS Developer ID and Windows Authenticode distribution are live. macOS notarization, Google Play distribution and an independent security audit are still unfinished.

CLIENTS

One mesh. Every device.

Current client releases use different distribution channels by platform. Review each signing status and installation limitation first.

01

macOS

Developer ID signed · Apple notarization unavailable

13+ · Intel / Apple Silicon · v0.2.43

Install only after reviewing the signed package and SHA-256 checksum. SHA-256

02

Windows

Authenticode signed · Microsoft timestamped

Windows 10 / 11 · v0.2.43

Both archives are signed by Future Alpha LLC through Azure Artifact Signing and carry Microsoft RFC 3161 timestamps. Verify SHA-256 before installation. SHA-256

03

Android

Direct release · RatelMesh-signed APK

Android 8.0+ · v0.2.39

Non-debuggable v0.2.39 APK signed with the RatelMesh release certificate for Android 8.0 and newer. It is not distributed through Google Play; verify SHA-256 before installation. SHA-256

05

iOS / iPadOS

App Store · v0.2.39

iOS 16+ · v0.2.39

Install the published iOS and iPadOS release from the RatelMesh listing on the Apple App Store.

Apple platform distributioniOS and iPadOS v0.2.39 are published through the Apple App Store and can run as an iPad-designed app on compatible Apple silicon Macs. The separate macOS v0.2.43 menu-bar package is Developer ID signed but not Apple notarized. v0.2.43 SHA-256 · v0.2.39 SHA-256 · RELEASE NOTES

FAQ

The practical questions first.

What post-quantum design does RatelMesh use?

WireGuard still uses Curve25519. RatelMesh adds an ML-KEM-768-derived preshared key and restricts TLS to X25519MLKEM768. This is downgrade-resistant hybrid post-quantum security.

Do I enter an enrollment code every time?

No. The one-use enrollment code is used only when the device first registers. Device credentials remain stored locally.

What can an exit device see?

The exit network can observe destination IPs, timing and volume. HTTPS content remains encrypted between your browser and the website. Use only an exit you trust.

Does it guarantee every service will work?

No. Services may also use account region, device location, billing information and their own policies. RatelMesh does not override service terms.

Can a small team pilot it now?

Yes, for a bounded pilot with a family, creative team or small office. Broad production rollout should wait for the remaining signing, external audit and commercial support.