What is the NetFoundry Platform
The NetFoundry Platform consists of several components and applications:
Console
The web interface. Enroll identities, define services and policies, provision routers, read metrics and events.
Automate the networkAPI
Use the same API that we do to automate provisioning, the network model, metrics, and reporting.
Get the data outData Connector
Stream network events and metrics into your own warehouse, SIEM, or analytics stack instead of reading them in a console.
Publish an HTTP serviceFrontdoor
Reach an HTTP service from a browser with no client software and no firewall changes — publicly or kept private to your identities. Users authenticate through your existing IdP.
Serve your own customersCustomer Connect
Deliver zero trust access to the people who buy from you, each tenant isolated from every other. White-label and vanity domain options for solution providers.
The open source foundationOpenZiti
NetFoundry created and maintains OpenZiti, the Apache 2.0 project everything here is built on. You get the same overlay, the same SDKs, and the same cryptography, with NetFoundry running and supporting it.
Let us run it for you, or run it yourself
The overlay, the SDKs, and the security model are identical either way. What differs is who operates the infrastructure — and in both cases the network configuration and the policies that govern access stay yours.
NetFoundry Cloud
A hybrid SaaS model: NetFoundry manages the infrastructure, and you own the network configuration and policies. Your network is dedicated to you rather than shared with other customers.
- One-click controllers and routers on AWS, Azure, GCP, and OCI
- Your own controller, data plane, and PKI
- Managed version upgrades, including for routers you host yourself
- Automated configuration backups
- Infrastructure inventory, allocated IPs, and component health in the console
- SCIM identity provisioning from Entra ID or Okta
- IPsec bridging for existing site-to-site VPNs
- An uptime SLA on the network NetFoundry operates
NetFoundry Self-Hosted
The same stack and the same contractual guarantees, deployed into an environment you own — on-prem, air-gapped, or your own cloud accounts.
- You deploy and run the controllers and routers on infrastructure you own
- No dependency on a NetFoundry-operated control plane
- Fits sovereign, air-gapped, and otherwise restricted environments
- You choose the platform, the sizing, and the upgrade schedule
- Production installers, bundled and packaged for supportability
- Logs, OS metrics, Ziti metrics, and stream integration included
- Optional remote access that you grant and revoke, so NetFoundry can troubleshoot or run an upgrade from inside the isolated network
Choose NetFoundry Cloud when
- You want a production network in minutes rather than a build project
- Your engineers should be building applications, not operating an overlay
- You are scaling across regions and would rather not run distributed routers
- You want to stay current without planning upgrade cycles
- You need an uptime guarantee on the network itself, with financial remedies
Choose NetFoundry Self-Hosted when
- Regulation or internal policy rules out a cloud-hosted control plane
- The environment is air-gapped, sovereign, or otherwise isolated
- You need to control exactly where every component runs
- You have staff to operate it and still want the vendor guarantees
Support and compliance
Apache 2.0 disclaims warranty and liability, which is the correct posture for a licence and an insufficient one for a procurement process. A NetFoundry subscription adds the contractual surface around the same software: 24×7 support from the engineers who write it, an uptime SLA with service credits on networks NetFoundry operates, and data processing agreements.
On compliance, what NetFoundry provides differs by framework — an audit report, a contractual commitment, and architectural guidance are not the same thing:
- AuditedIndependent audit reports NetFoundry can provide.
- SOC 2 Type II
- Contractual and eligibleSupported through contract terms and platform configuration.
- HIPAA eligibilityGDPRCCPAData processing agreements
- Guidance and alignmentNetFoundry provides guidance and controls that map to these; the attestation is yours.
- FIPSPCI DSSNIST 800-207NIST 800-171IEC 62443NERC CIPNIS2DORACJIS
Visibility
Telemetry comes out of the Ziti fabric itself, so the numbers describe the overlay rather than a proxy for it.
Metrics
Traffic volume by dialing endpoint, hosting endpoint, service, and edge router, over preset or custom time ranges and filterable by endpoint attribute. Reference.
Fabric and controller latency
Router-to-router link latency and router-to-controller control-channel latency, as mean, max, and P99, with a link diagram and time series. Latency timeouts surface failing paths and overloaded routers.
Traffic analysis
For ZTNA deployments using ingress and egress gateways, the actual source IPs, destination IPs, and ports crossing the funnel — so a segmentation design can be derived from observed flows rather than guessed at.
Events and audit logging
Management events record who changed what and when, alongside network activity. Reference.
Metering and alarms
Usage metered by application and by team, with alarm and event configuration so a threshold reaches you rather than waiting to be noticed.
Export
Data Connector streams events and metrics into your own warehouse, SIEM, or analytics platform.