Enclave Networks is a Zero Trust Network Access (ZTNA) platform that creates encrypted, peer-to-peer overlay networks over the public Internet using a software-defined architecture. The platform establishes private connectivity between endpoints—including computers, servers, cloud instances, containers, mobile devices, and IoT systems—across on-premises, hybrid, cloud, SaaS, and distributed environments without requiring VPN servers, firewall modifications, NAT configuration, routing table changes, public IP exposure, or network reconfiguration. Devices enroll through certificate-based signing keys and participate in a mesh network with assigned virtual IP addresses from the 100.64.0.0/10 subnet, communicating via outbound-only UDP tunnels with TCP fallback at OSI Layer 2 (encapsulating Ethernet frames) or Layer 3, enabling universal protocol support for both north-south and east-west traffic including non-routed protocols such as NetBIOS and multicast. Cryptographic operations employ Ed25519 signatures, Curve25519 key exchange, and AES-256-GCM or ChaCha20-Poly1305 tunnel encryption with perfect forward secrecy. Authentication is performed before connection establishment through integration with enterprise identity providers including Microsoft Entra ID, Azure AD, Okta, Duo, JumpCloud, Google, GitHub, and any OpenID Connect-compatible service, supporting multi-factor authentication and on-premises Active Directory verification.
Access is governed by centrally managed, policy-driven controls that verify identity, context, and device posture before establishing connectivity, implementing session-based, least-privilege access in accordance with NIST SP 800-207 principles. Policies use tags, enrollment keys, and ACL definitions to automate connectivity rules with optional protocol and port restrictions, incorporating features such as micro-segmentation, Active Hours for time-based restrictions, Auto Expiry for automatic access termination, dynamic provisioning and teardown of network links, and just-in-time connectivity. The platform includes a high-performance UDP socket stack optimized for line-speed throughput, low CPU usage, and high concurrency using asynchronous I/O; policy decisions are cached on endpoints to maintain connectivity during temporary trust broker outages. A Linux-based software gateway extends connectivity to agentless devices and subnets, supporting NAT via iptables/nftables, UFW integration, and DNS stub resolution, with multiple gateway deployments supporting Balanced, Ordered, and Geographic priority modes. Additional capabilities include DNS resolution and filtering, secure web gateway functionality, ephemeral enrollment keys for temporary containers, CLI with JSON output, API-driven automated provisioning, Terraform provider infrastructure-as-code support, a Go module for API access, Network Flow Metadata with IPFIX export, and extensibility through plug-ins. Enclave Networks is offered as a cloud-based SaaS solution hosted in Microsoft Azure UK-South with optional on-premises or co-managed deployment, managed through a web portal with real-time access revocation, monitoring, analytics, and automated security response, and includes mobile applications for Android and iOS. The infrastructure complies with ISO/IEC 27001, ISO 27017, SOC 1-3, PCI DSS Level 1, HIPAA, GDPR, and NIST standards.