Firewall changes stall
Every customer network is different, and opening a new inbound port creates another approval and maintenance burden.
Remote access tunnel / managed pilot
Give support and operations teams a controlled route to approved on-premise APIs, admin tools and TCP services through one outbound agent—without creating a flat VPN network.
Tunnel core available for technical evaluation. Managed access controls are in development.
The support gap
Every customer network is different, and opening a new inbound port creates another approval and maintenance burden.
A technician may need one web interface or SSH service—not membership of the customer’s wider private network.
A routine diagnosis becomes a truck roll when the right engineer cannot reach the right service at the right moment.
One path, three decisions
The tunnel is outbound-only and built around approved services. The public edge routes to what the agent declared—not to a destination supplied by the caller.
A small agent inside the private network opens and maintains an authenticated TLS WebSocket connection to the DataDemon edge.
Each approved capability has one service name, one type, one fixed local destination, and defined time or resource limits.
HTTP requests, WebSocket sessions and TCP connections receive independent bounded streams, so one failure does not end unrelated work.
127.0.0.1:8080
No
127.0.0.1:9000
No
127.0.0.1:22
No
Built around the service call
The strongest fit is a repeatable support or cloud-to-site workflow across a deployed fleet—not one developer sharing localhost.
Reach an approved administration interface on a kiosk, commercial printer, laboratory instrument, gateway or controller.
Remote equipment supportLet a SaaS application call a fixed API inside a customer network without asking the customer to expose it publicly.
Cloud-to-customer connectivityConnect central operations to a local service at a shop, office or remote site through one managed agent.
Remote site accessCarry explicitly configured SSH, database or proprietary TCP traffic without letting callers select arbitrary internal destinations.
Capability-bound TCPEngineering evidence, correctly labelled
The latest four-agent local qualification exercised 128 concurrent streams over an unshaped Docker LAN. It validates correctness and local transport behaviour—not real-world WAN performance or production readiness.
See the managed-pilot boundaryLocal, unshaped LAN laboratory result · 0.132–0.138 ms observed RTT · broadband, inter-region, adverse-network, endurance, restart and real-WAN gates remain incomplete.
A transparent pilot boundary
We are looking for design partners with a real deployed-equipment or customer-premises access problem. This is not an invitation to move production traffic today.
Design-partner profile
The first managed pilot should solve a recurring operational problem where a successful remote diagnosis can avoid delay, escalation or a physical visit.
Questions from security and operations
No inbound port is required at the agent site. The agent initiates an authenticated outbound TLS WebSocket connection to the public edge. The customer network must still permit that outbound connection.
A VPN commonly joins users or devices at the network layer. The tunnel is designed to route traffic to named services with fixed local destinations. It is a smaller access surface, not a claim to replace every VPN use case.
No. Public input cannot select a local host, port, filesystem root or capability ID. The edge can route only to a service already declared and accepted for that authenticated agent session.
The current tunnel core supports HTTP, streaming responses, Server-Sent Events, long polling, explicitly enabled WebSocket services and raw TCP. Fixed SSH and MySQL compatibility have been tested over TCP.
The tunnel uses TLS on its transport boundaries, but “end-to-end encrypted” would depend on the exact public edge, tunnel and local-origin configuration. We will document those boundaries precisely for each managed pilot rather than make a blanket claim.
Not yet. The tunnel engine is available for technical evaluation. Identity, tenant isolation, approvals, durable audit, billing, automated domains, high availability, operational controls and real-WAN qualification remain work for a managed pilot.
One real workflow beats a long feature list
Start with the device count, the local service and the cost of today’s workaround.
Tell us about your equipment