Remote access tunnel / managed pilot

Reach services behind customer firewalls. Keep the ports closed.

Give support and operations teams a controlled route to approved on-premise APIs, admin tools and TCP services through one outbound agent—without creating a flat VPN network.

Tunnel core available for technical evaluation. Managed access controls are in development.

Remote site
Outbound connection only
Service surface
Fixed, named destinations
Protocols
HTTP · WebSocket · TCP

The support gap

Your product is on site. Your expertise is not.

Firewall changes stall

Every customer network is different, and opening a new inbound port creates another approval and maintenance burden.

VPNs expose too much

A technician may need one web interface or SSH service—not membership of the customer’s wider private network.

Site visits compound

A routine diagnosis becomes a truck roll when the right engineer cannot reach the right service at the right moment.

One path, three decisions

Remote access without handing over the network.

The tunnel is outbound-only and built around approved services. The public edge routes to what the agent declared—not to a destination supplied by the caller.

  1. 01

    The agent calls out

    A small agent inside the private network opens and maintains an authenticated TLS WebSocket connection to the DataDemon edge.

  2. 02

    Named services register

    Each approved capability has one service name, one type, one fixed local destination, and defined time or resource limits.

  3. 03

    Requests stay contained

    HTTP requests, WebSocket sessions and TCP connections receive independent bounded streams, so one failure does not end unrelated work.

Capability table customer-site-042
admin-ui HTTP + WebSocket 127.0.0.1:8080 No
device-api HTTP 127.0.0.1:9000 No
ssh TCP 127.0.0.1:22 No

Built around the service call

For teams supporting systems in networks they do not control.

The strongest fit is a repeatable support or cloud-to-site workflow across a deployed fleet—not one developer sharing localhost.

Installed equipment

Reach an approved administration interface on a kiosk, commercial printer, laboratory instrument, gateway or controller.

Remote equipment support

On-premise software

Let a SaaS application call a fixed API inside a customer network without asking the customer to expose it publicly.

Cloud-to-customer connectivity

Branch operations

Connect central operations to a local service at a shop, office or remote site through one managed agent.

Remote site access

Fixed technical access

Carry explicitly configured SSH, database or proprietary TCP traffic without letting callers select arbitrary internal destinations.

Capability-bound TCP

Engineering evidence, correctly labelled

The transport works. The internet-facing product still has gates to clear.

The latest four-agent local qualification exercised 128 concurrent streams over an unshaped Docker LAN. It validates correctness and local transport behaviour—not real-world WAN performance or production readiness.

See the managed-pilot boundary
928 / 928
requests completed
232 GiB
transferred in the matrix
0
integrity failures or unexpected resets
128
concurrent streams at peak workload

Local, unshaped LAN laboratory result · 0.132–0.138 ms observed RTT · broadband, inter-region, adverse-network, endurance, restart and real-WAN gates remain incomplete.

A transparent pilot boundary

Evaluate the tunnel now. Shape the managed access layer with us.

We are looking for design partners with a real deployed-equipment or customer-premises access problem. This is not an invitation to move production traffic today.

Implemented transport

Available for technical evaluation

  • Outbound agent connection and reconnection
  • Fixed HTTP, WebSocket and raw TCP services
  • Multiple services over one carrier
  • Bounded buffering, concurrency and flow control
  • Independent cancellation and stream failure
  • Health, metrics and protected session inventory
Managed pilot gates

Required before paid internet-facing use

  • Customer authentication and tenant-aware authorisation
  • Per-agent credentials, approvals and durable audit
  • Automated DNS, TLS and custom domains
  • Entitlements, billing and credential rotation
  • High availability, alerting, backups and incident operations
  • WAN, endurance, restart and fault-injection qualification

Design-partner profile

A strong fit has expensive incidents and a narrowly defined service.

The first managed pilot should solve a recurring operational problem where a successful remote diagnosis can avoid delay, escalation or a physical visit.

Worth a conversation if you have…

  • 50–2,000 deployed devices, gateways or customer sites
  • A Linux host able to run the private-side agent
  • A fixed HTTP API, admin interface, SSH or TCP service
  • A support team losing time to network access or site visits
  • Customers that reject inbound firewall changes

Probably not the right fit if you need…

  • A free tunnel for occasional localhost sharing
  • A general private network for personal devices
  • Immediate production rollout or an SLA
  • Full IoT fleet management, OTA updates or device telemetry

Questions from security and operations

Before you put an agent in a customer network.

Does the DataDemon tunnel require an inbound firewall rule?

No inbound port is required at the agent site. The agent initiates an authenticated outbound TLS WebSocket connection to the public edge. The customer network must still permit that outbound connection.

How is this different from a VPN?

A VPN commonly joins users or devices at the network layer. The tunnel is designed to route traffic to named services with fixed local destinations. It is a smaller access surface, not a claim to replace every VPN use case.

Can a caller choose another internal IP or port?

No. Public input cannot select a local host, port, filesystem root or capability ID. The edge can route only to a service already declared and accepted for that authenticated agent session.

Which protocols are supported?

The current tunnel core supports HTTP, streaming responses, Server-Sent Events, long polling, explicitly enabled WebSocket services and raw TCP. Fixed SSH and MySQL compatibility have been tested over TCP.

Is the connection end-to-end encrypted?

The tunnel uses TLS on its transport boundaries, but “end-to-end encrypted” would depend on the exact public edge, tunnel and local-origin configuration. We will document those boundaries precisely for each managed pilot rather than make a blanket claim.

Is this ready for paid production use?

Not yet. The tunnel engine is available for technical evaluation. Identity, tenant isolation, approvals, durable audit, billing, automated domains, high availability, operational controls and real-WAN qualification remain work for a managed pilot.

One real workflow beats a long feature list

Tell us what is deployed, where it lives, and what your team needs to reach.

Start with the device count, the local service and the cost of today’s workaround.

Tell us about your equipment