Planck VPN for Business

VPN infrastructure that belongs to your organization, not a crowd

We build private VPN infrastructure around dedicated static IP addresses reserved for a single client: you. Your team connects through gateways provisioned for your organization alone, running WireGuard and OpenVPN, with per-user keys you can revoke the moment someone leaves. Every packet that exits carries an address that no other company has ever used through us.

The Product

What you get

Three things distinguish this service from a subscription VPN: addresses that are yours, gateways that are yours, and control over exactly who can connect.

Dedicated static egress IPs

Each engagement includes static IPv4 addresses assigned to your organization and to nobody else. They never rotate, they are never shared with another tenant, and they carry no reputation baggage from strangers. You can place them on allowlists at your SaaS providers, your banks, and your customers, and cite them in firewall rules and security documentation, because traffic from those addresses can only originate from your authenticated users.

Private gateways per organization

Your traffic terminates on gateway instances provisioned for your account, not on shared multi-tenant servers. That isolation means predictable performance under load, a clean security boundary between you and every other client, and the freedom to tune routing, MTU, and firewall policy to your environment. Gateways run hardened Linux builds with minimal services exposed and receive scheduled security updates.

Centralized team and key management

Every user receives a unique keypair. There are no shared credentials to leak and no group passwords to rotate after an offboarding. Administrators add users, assign them to access groups, and revoke keys from a single management interface. Revocation propagates to all gateways immediately, terminating active sessions for that key without disrupting anyone else. Connection events are available for export to your SIEM.

Use Cases

Where a dedicated egress identity pays off

Most teams arrive here because something broke: a fraud filter flagged them, an allowlist request stalled, or a contractor kept access two weeks too long. These are the problems this service exists to remove.

01

IP allowlisting for SaaS admin panels, internal tools, and customer environments

Restricting administrative interfaces to known source addresses is one of the cheapest, most effective access controls available. It fails only when your addresses keep changing. With dedicated egress IPs, you can lock down the systems that matter and never touch the allowlist again until you choose to. Stolen credentials alone stop being enough to reach an admin login page, because the attacker is not connecting from your address space.

  • SaaS and cloud provider admin consoles
  • Internal dashboards, CI systems, and staging environments
  • Customer production environments that require registered source IPs
  • Databases and management planes exposed only to your ranges
02

Secure remote workforce with a stable corporate egress identity

Your engineers work from home networks, hotel Wi-Fi, and airport lounges. The tunnel encrypts everything between the device and your gateway, so hostile local networks see only ciphertext. Just as important, every connection to your internal systems and vendors arrives from the same corporate addresses regardless of where the employee sits. Conditional access policies, geo-sensitive fraud checks, and anomaly detection tools all behave consistently because your organization presents one stable identity to the internet.

03

Predictable integration traffic for API partners and payment providers

Payment processors, banks, and many enterprise API partners filter inbound requests by source IP and require you to register your addresses before go-live. If your outbound traffic originates from ephemeral cloud infrastructure, every migration or autoscaling event risks breaking a production integration. Routing that traffic through your dedicated gateways gives partners fixed, documented addresses to register once. You can rebuild your infrastructure behind the tunnel as often as you like without a single re-registration email.

04

Controlled contractor and vendor access with per-user keys

Third parties need access to specific systems for a defined period, and nothing more. Issue each contractor an individual key, scope their routes with a split tunnel policy so only agreed subnets traverse the VPN, and log every session they open. When the engagement ends, revoke the key and the access ends with it. There is no shared account to rotate, no lingering credential in a vendor's password vault, and a clean connection record if you ever need to reconstruct who reached what.

Under the Hood

Technical specifications

The service is built on open, audited protocols with modern cryptography. Nothing proprietary sits in the data path.

Area Specification
Protocols WireGuard as the default. OpenVPN over UDP and TCP for environments with restrictive middleboxes or legacy client requirements. Both can run in parallel on the same gateway set.
Encryption ChaCha20-Poly1305 authenticated encryption with Curve25519 key exchange for WireGuard. AES-256-GCM with TLS for OpenVPN control and data channels.
Key management A unique keypair per user and per device. Keys are added, rotated, and revoked centrally. Revocation takes effect across all gateways without service interruption for other users.
Tunneling Full tunnel or split tunnel, set per policy and per group. Route only defined corporate subnets, or carry all traffic through your dedicated egress addresses.
DNS Private resolvers inside the tunnel. Queries never leave the encrypted path, which prevents DNS leaks and lets you resolve internal zones that public DNS cannot see.
Platforms Windows, macOS, Linux, iOS, and Android clients, plus router and gateway deployments for whole-site connectivity where individual clients are impractical.
Availability Redundant gateways per region with automatic failover. Clients reconnect to a standby gateway without user action, and your egress addresses are preserved through the transition.
Deployment Options

Run it where your architecture demands

The same key management, the same protocols, and the same dedicated addressing model apply in every deployment shape. You choose where the gateways live.

Cloud-hosted gateways

We provision gateways in the cloud regions you choose, placing egress close to your workforce and your critical integrations to keep latency low. Multi-region deployments give traveling staff a nearby entry point while preserving a consistent set of corporate egress addresses. Capacity scales with headcount, and we handle patching, monitoring, and failover as part of the service.

On-premises gateway appliances

For organizations with data residency obligations or a strict perimeter model, we deploy gateway appliances inside your own network, behind your firewall and under your physical control. Remote users terminate their tunnels directly on your premises, and traffic to internal systems never transits third-party infrastructure. We supply the hardened build, the configuration, and the operational runbook; your team retains custody.

Site-to-site tunnels

Persistent encrypted tunnels link your offices, data centers, and cloud VPCs into one routed private network. Branch sites reach headquarters resources without exposing services to the internet, and cloud environments in different providers exchange traffic over WireGuard rather than public endpoints. Routing is defined per site, so each location sees exactly the subnets it should and nothing else.

Onboarding

From first call to full rollout

A typical deployment moves through four stages. Small teams are often live within days; larger rollouts follow the same path with a phased client migration.

Requirements call and IP plan

We map your use cases, user count, regions, and the systems that will consume your allowlisted addresses. You receive a written plan covering gateway placement, address assignments, tunnel policy, and DNS design before anything is provisioned.

Gateway provisioning

We stand up your gateways in the agreed regions or ship the on-premises build, assign your dedicated addresses, configure redundancy and private DNS, and validate failover behavior before any user connects.

Client rollout

Each user receives a configuration profile tied to their own keypair, with install guides for every platform in scope. We support pilot groups first, then the wider team, and remain on call while your allowlists are updated to the new addresses.

Handover and ongoing support

You receive full documentation, admin training for the management interface, and a defined support channel. We continue to monitor gateway health, apply security updates, and respond to operational requests for the life of the service.

FAQ

Questions we hear from evaluating teams

Can we bring our own IP ranges?

Yes, where the hosting region supports announcing customer prefixes. If your organization holds its own address space, we can arrange for your prefix to be announced from your dedicated gateways so egress traffic carries addresses you own outright. If you do not hold your own ranges, we assign addresses reserved exclusively for you, document the assignment in the service agreement, and keep them stable for the duration of the engagement.

How fast is key revocation?

Revoking a key in the management interface propagates to every gateway in your deployment within moments, and we commit to full effect within five minutes. Active sessions for the revoked key are terminated, not merely blocked from reconnecting. No gateway restart is involved, so other users stay connected throughout.

Do you log our traffic?

We keep the connection metadata required to operate the service: authentication events, connect and disconnect timestamps, the assigned tunnel address, and transfer volumes per session. This is what makes troubleshooting, capacity planning, and your own audit requests possible. We do not inspect packet contents, we do not record browsing activity or DNS query histories tied to individuals, and we do not sell or share any operational data. The exact scope and retention period of logs is written into your service agreement, so there is no ambiguity about what exists and for how long.

Can this coexist with our existing VPN?

Yes. Many clients run our service alongside an existing remote access VPN during migration, or permanently for a specific purpose such as partner integration egress. Split tunnel policies let us scope exactly which destinations route through the dedicated gateways, so the two systems do not compete for routes. We review your current routing and client software during the requirements call to rule out conflicts before deployment.

What happens if a gateway fails?

Each deployment includes redundant gateways with automatic failover. When a gateway becomes unhealthy, clients re-establish their tunnels to a standby without user intervention, typically within seconds for WireGuard. Your dedicated egress addresses move with the failover, so allowlists and partner registrations continue to work. Gateway health is monitored continuously and we investigate every failover event.

How is this different from a consumer VPN?

A consumer VPN routes thousands of unrelated users through shared exit addresses. Those addresses accumulate abuse reports, appear on block lists, and trip fraud and bot detection, which is why consumer VPN traffic is often refused outright. They also offer no organizational control: no admin console, no per-user keys, no revocation, no policy. This service is the opposite arrangement. The addresses are used by your organization alone, the gateways are provisioned for you, access is managed by your administrators, and the configuration is engineered around your specific allowlisting, routing, and compliance requirements.

Get Started

Reserve infrastructure that answers only to you

Tell us about your team, your regions, and the systems you need to reach. We will come back with a concrete deployment plan and your dedicated address assignments.