A self-hosted remote access platform combining WireGuard VPN with identity management and multi-factor authentication.

Defguard is a self-hosted secure remote access platform. It integrates WireGuard VPN, identity and access management, and multi-factor authentication into a single system to manage access to private networks and infrastructure. The software is deployed as a server and includes dedicated clients for Linux, macOS, Windows, Android, and iOS.
Users utilize Defguard to establish secure tunnels to their internal resources while enforcing strict authentication policies. It replaces the need for multiple disconnected tools by combining a VPN server with an internal OpenID Connect provider and a network access control system. The platform supports both kernel and userspace WireGuard implementations, allowing for flexible deployment across different operating system environments.
The system uses a component-based architecture to minimize the attack surface and ensure network segmentation. It divides responsibilities between a Core management plane for identity, authentication, and policy, an Edge public-facing entry point, and a Gateway that enforces network access policies for protected resources. This structure allows organizations to maintain full control over their data and infrastructure without relying on external dependencies or third-party cloud services. The platform is designed for transparency, providing published software bills of materials and architecture decision records to support security audits.
Defguard is a security-focused solution for organizations requiring a zero-trust approach to VPN access and identity management.
A cross platform GUI client for managing rule based network tunnels and proxy configurations via Tauri.
Creates private WireGuard networks to connect devices across clouds, VPCs, and on-premises networks without modifying firewall rules.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.