Make your network invisible.
Keep your business connected.
CloakNet is a zero trust networking platform that closes every inbound port and connects your sites, devices, APIs and AI workloads over identity-based, end-to-end encrypted overlays — built on proven open zero trust technology.
If attackers can't reach it, they can't attack it
Traditional VPNs and firewalls publish attack surface: open listeners, routable subnets, trusted networks. CloakNet inverts the model — nothing listens, nothing is routable, and every session is authenticated and authorized before a single packet of your data moves.
Dark by default
Services sit behind outbound-only connections. No open inbound ports, no public IP dependency, nothing for scanners to find.
Identity, not IP addresses
Access is granted to cryptographically verified identities per service — not to network ranges. Least privilege becomes the default posture.
Programmable overlay
Built on open zero trust overlay technology, so connectivity can be embedded in apps, gateways and routers — and automated end to end.
One fabric, four hard problems solved
Site to Site
Retire brittle IPsec meshes. Connect data centers, branches and clouds with app-level, zero trust links.
Learn moreOT & IoT
Cloak PLCs, sensors and edge gateways. Remote access without exposing industrial networks.
Learn moreAPI Security
Take APIs off the public internet entirely. Authenticate before connect — not after.
Learn moreAI Security
Private, policy-controlled paths between users, agents, models and the data they touch.
Learn moreZero trust at the edge, in a metal box
The CloakNet CN350W-4G industrial router puts the fabric wherever your assets live — factory floors, kiosks, vehicles, remote sites. Dual-SIM 4G LTE, five Ethernet ports, RS232/RS485 serial, and WireGuard, OpenVPN, IPsec and m2mCloud tunnels in a −30 °C to 75 °C rated metal casing.
- Dual-SIM automatic failover for always-on links
- Modbus TCP/RTU to MQTT for PLC and sensor data
- Multiple VPN protocols and remote web management

From exposed to invisible in three moves
Deploy endpoints
Drop lightweight CloakNet endpoints next to your apps and sites — as software agents, containers, SDK-embedded clients, or CloakNet routers. They dial out; nothing dials in.
Define services & policy
Name each service and decide exactly which identities may reach it. Policy is enforced in the fabric before connection — deny is the default.
Close the front door
Shut inbound firewall rules and retire the VPN concentrator. Your services are now unreachable from the internet, yet reachable by everyone who should have access.
See CloakNet cloak your network
30 minutes with our engineers. Your topology, our overlay, zero inbound ports.