Connect every cloud.Enforce every policy.Deploy zero agents.
The multi-cloud networking fabric built for teams who have outgrown tunnel VPNs but are not signing a six-figure enterprise contract to solve it. Lower your networking TCO, keep your packet content in your own infrastructure, and stop maintaining separate ops for every cloud.
example fabric2 regions · 4 txgws · 6 lgws · 8 spokes · any-to-any
multi-region · multi-cloud · any-to-any flows · zero agents in your workload vpcs
01why it matters
Four outcomes your leadership team already cares about
The short version, up front. The architectural receipts come later on this page — scroll when you're ready.
total cost
Spend mid-market money. Get enterprise capability.
Incumbent enterprise MCNF platforms were priced for the Fortune 500. Telaron isn't. You get the same multi-cloud fabric capability without the six-figure annual contract, the per-spoke gateway VM bill, or the CSP transit data-processing tax (TGW, Virtual WAN, NCC).
No gateway VMs in your workload VPCs
No cross-charging transit fees (TGW / Virtual WAN / NCC)
Community tier free, Pro per-gateway
operational load
Run less. Ship more.
One control plane across every cloud you use. No Kubernetes required. No agents to roll out to every workload. Your team manages intent in Terraform, Pulumi, or the REST API; the fabric handles the plumbing — consistently, across AWS, GCP, Azure, and on-premises.
Terraform, Pulumi, or REST API — you pick
GitOps-native, no K8s required
One runbook for every cloud
security & compliance
Stronger posture. Simpler story.
Your packet content stays in your infrastructure — this is an architectural property, not a policy promise. Microsegment by service or application, not just VPC boundary, using CSP-native tags discovered across AWS, Azure, and GCP. Every packet arrives at the LGW with full metadata context — so policy follows identity, not IP.
Add clouds when the business asks, not two quarters later.
Unified eBGP routing. CSP-native spoke integration — GWLB endpoints, VPC peering, ILB next-hop. A new region or a new CSP is a config change, not a reorg. Your network stops being the reason a product launch slips.
Any workload type — VM, container, serverless, bare metal
Native integration with every major CSP
Add a spoke in minutes, not weeks
02built for
Four audiences, one fabric
Multi-cloud networking touches a lot of teams. Here is how the same fabric answers each of them.
01
Platform engineering leaders
their pain
Separate networking ops for every cloud, every region, every team.
our answer
One fabric, one control plane, one configuration story across AWS, GCP, Azure, and on-premises — Terraform, Pulumi, or the REST API, your call. Your platform team stops being a cross-cloud integration team.
02
Security & compliance architects
their pain
Multi-cloud makes policy, inspection, and data residency harder to prove.
our answer
Microsegment by service or application — not just VPC — with eBPF plus CSP-native tag discovery across AWS, Azure, and GCP. Keep packet content in your own infrastructure by architecture. Give auditors a one-page story instead of a deposition.
03
CTOs & finance leaders
their pain
Multi-cloud networking bills scale faster than the business does.
our answer
Replace a six-figure enterprise-networking contract with pricing calibrated to the mid-market. Predictable per-gateway cost. No sales call required to start.
04
Network & SDN teams
their pain
IPSec ceilings, spoke VM sprawl, and Kubernetes-everything.
our answer
WireGuard throughput. eBPF policy. Familiar BGP primitives. Runs on VMs, containers, or bare metal — bring your own workloads, however they're packaged.
03see it in action
A whole multi-cloud fabric as one config change
No console clicks. No ticket-driven network changes. Describe your fabric once — in the IaC tool your team already uses — and apply. Adding a cloud is adding a few lines.
Config-driven, not ClickOps — Terraform, Pulumi (Go / TS / Python), or the REST API
Same resource shapes across AWS, GCP, Azure, and on-premises
Native GitHub Actions & GitLab CI via OIDC workload identity — no long-lived tokens in your pipelines
GitOps-native — policy changes are commits, not console tickets
Plan, preview, and rollback every change like any other infrastructure
terraform apply
main.tf
terraform · pulumi · rest — same fabric, pick your tool
04how we deliver
Eight architectural decisions that make the above possible.
The outcomes above aren't adjectives — they're properties of how Telaron is built. If you want the receipts, here they are.
01
2.5 Gbps
per vcpu core
2× throughput per core
Multi-tunnel WireGuard with ChaCha20-Poly1305 and CPU affinity. Legacy IPSec-based MCNF fabrics typically top out around 1.25 Gbps per core on the same hardware. Same infrastructure, double the encrypted throughput — and none of the ESP MTU headaches.
02
0
agents in your workload vpcs
Nothing inside your apps
Your workload spoke VPCs stay untouched — not an agent, not a VM, not a sidecar. The fabric runs in a separate SaaS-orchestrated edge tier (LGW per spoke group, TXGW for cross-cloud transit) deployed into your own central VPCs. Workload spokes attach via native CSP constructs — GWLB endpoints, VPC peering, ILB next-hop.
03
8.8×
vs socket processing
eBPF-native from day zero
XDP and TC hooks deliver ~8.8× throughput over socket-based processing while keeping the kernel networking stack intact. No DPDK NIC takeover, no fragile userspace packet paths.
04
Any
workload type
No Kubernetes required
Infrastructure-grade, not pod-grade. VPC and subnet level with bare-metal-compatible gateways. Your workloads run however they run — VMs, containers, serverless, bare metal.
05
Native
per csp
CSP-native spoke integration
AWS: GWLBe + VPC peering. GCP: VPC peering with ILB next-hop via custom route export. Azure: Gateway LB chaining + VNet peering. Telaron complements the CSPs where it makes sense, and replaces their cross-charging transit layers (AWS TGW, Azure Virtual WAN, GCP NCC) where it makes sense — no per-GB transit tax.
06
100%
iac coverage
Policy as code, always
First-class Terraform provider. Pulumi SDK (Go, TypeScript, Python). Full REST API for anything in between. GitOps reconciliation on every change. No ClickOps traps, no console-only configuration, no day-two manual-tweak debt.
07
Zero
packet content exposure
Data sovereignty by architecture
The SaaS control plane handles configuration metadata and telemetry only — never customer packet content. An architectural property, not a policy promise. Documentable for compliance.
08
~10×
lower tco
Order-of-magnitude lower cost
Eliminate per-spoke gateway VM compute, CSP transit data-processing fees (AWS TGW, Azure Virtual WAN, GCP NCC), and six-figure enterprise-networking licensing. Community tier is free. Pro and Enterprise tiers priced for the mid-market.
05at a glance
How Telaron compares
Three rows, three vendors. The rest is on the full matrix — receipts, not adjectives.
capability
Telaron
Aviatrix
Cisco MCD
Encryption & throughput
WireGuard ChaCha20, ~2.5 Gbps/core
IPSec ESP, ~1.25 Gbps/core
IPSec (NGFW), per-core ceiling
Spoke compute
None in workload VPCs; edge tier in customer-owned central VPCs
all tiers include the apache-2.0 gateway data plane · switch or cancel anytime
07roadmap
What we're building next
The v1 platform ships now. These are the near-term and horizon deliveries building on it — directional, not date-bound. Detail-level feature lists live in the docs.
near-term · next 6 months
Shipping into v1
GitOps CI via OIDC workload identity
Native GitHub Actions & GitLab CI integration through our own OIDC IdP. Short-lived tokens minted per-run — no long-lived secrets in your pipeline.
Unified policy plane
Read policy from Cisco Multicloud Defense and Palo Alto Panorama into one normalised view. Keep your source of truth; let Telaron enforce it at the fabric edge.
SOC 2 Type II attestation
Closing out the attestation cycle. Report available under NDA for regulated customers on the Enterprise tier.
horizon · directional
Where we are heading
L7 deep packet inspection
Protocol-aware policy evaluated at the eBPF fast path. HTTP / gRPC / TLS SNI awareness without a proxy detour or userspace retransmit.
Policy federation — more sources
Expanding beyond Cisco MCD and Panorama. Prisma Cloud, Illumio, CrowdStrike Falcon. Wherever your policy of record lives, we will read it.
ML-assisted anomaly detection
Baseline flow patterns at the LGW, surface drift, stream to your SIEM. Detection-as-a-property of the fabric, not a bolted-on appliance.
roadmap is indicative · ships live at docs.telaron.io · no dates, directions
08 · start shipping
Ready to rebuild your multi-cloud fabric?
Spin up a Community cluster in minutes. Bring your IaC tool of choice, BYO clouds, keep your packet content on your own infrastructure.