Control every cloud.Enforce every policy.Deploy zero agents.
We are building Managed Network-as-a-Service for multi-cloud: one control plane for data-plane and transport-layer policy, above whatever underlay you run. Today it runs on GCP, with gateways in your own network enforcing host-level policy in the kernel and your packet content never leaving your infrastructure. Cross-cloud transit, AWS, and circuits we provision for you — including AWS Interconnect’s free tier — are coming.
the target fabric · gcp runs today · zero agents in your workload vpcs
01why it matters
Four outcomes your leadership team already cares about
The short version, up front. The architecture behind each one comes later on this page — scroll when you're ready.
total cost
Spend mid-market money. Get enterprise capability.
The established platforms in this category are built and priced for the Fortune 500, and they earn it there. Telaron is calibrated for the mid-market: no per-spoke gateway VM bill, and — once cross-cloud transit lands — no CSP transit data-processing tax (TGW, Virtual WAN, NCC) layered underneath.
No gateway VMs in your workload VPCs
No cross-charging transit fees (TGW / Virtual WAN / NCC)coming
Community tier free, Pro per-gateway
operational load
Run less. Ship more.
One control plane across every cloud you use. No Kubernetes required. No agents to roll out to every workload. Your team manages intent in Terraform or the REST API, with Pulumi coming; the fabric handles the plumbing consistently — on GCP today, with AWS in progress and Azure and on-premises planned.
Terraform or REST API — you pick
GitOps-nativecoming
One runbook for every cloudcoming
security & compliance
Stronger posture. Simpler story.
Your packet content stays in your infrastructure — this is an architectural property, not a policy promise. Microsegment by service or application, not just VPC boundary — CSP-native tag discovery is coming. Policy names hosts today; identity drawn from service metadata is coming.
Zero packet-content exposure to the SaaS
Tag-based ABAC microseg via cloud resource discoverycoming
eBPF policy in the kernel, DDoS shedding at XDP
SOC 2 Type II on roadmap
delivery velocity
Add clouds when the business asks, not two quarters later.
Managed NaaS across every cloud is the goal: one control plane above whatever underlay you run. Coming: bringing your own private circuits or having Telaron provision them (including AWS Interconnect’s free tier), unified eBGP routing, and CSP-native spoke integration — together they make a new region or a new CSP a config change, not a reorg.
Underlay-agnostic — WireGuard over any routable path
Underlay provisioned for youcoming
Add a spoke in minutes, not weekscoming
02built for
Four audiences, one fabric
Multi-cloud networking touches a lot of teams. Here is how the same fabric answers each of them.
01
Platform engineering leaders
their pain
Separate networking ops for every cloud, every region, every team.
our answer
One fabric, one control plane, one configuration story — GCP available now, AWS in progress, Azure and on-premises planned. Terraform or the REST API today, Pulumi coming. Your platform team stops being a cross-cloud integration team.
02
Security & compliance architects
their pain
Multi-cloud makes policy, inspection, and data residency harder to prove.
our answer
Microsegment host to host with eBPF in the kernel today; by service or application, with CSP-native tag discovery, is coming. Keep packet content in your own infrastructure by architecture. Give auditors a one-page story instead of a deposition.
03
CTOs & finance leaders
their pain
Multi-cloud networking bills scale faster than the business does.
our answer
Predictable per-gateway cost that tracks the fabric you run, not the traffic you push through it. Free Community tier to prove it out, and no sales call required to start.
04
Network & SDN teams
their pain
IPSec ceilings, spoke VM sprawl, and Kubernetes-everything.
our answer
Kernel WireGuard. eBPF policy. Familiar BGP primitives are coming. Gateways run on VMs today, bare metal is coming, and your workloads need nothing installed, however they're packaged.
03see it in action
A whole multi-cloud fabric as one config change
No console clicks. No ticket-driven network changes. Describe your fabric in the IaC tool your team already uses, and apply it. Adding a cloud will be adding a few lines.
Config-driven, not ClickOps — Terraform or the REST API
Pulumi SDK (Go / TS / Python)coming
Same resource shapes across every cloud — GCP now, AWS in progress, Azure and on-premises planned
Native GitHub Actions & GitLab CI via OIDC workload identity — no long-lived tokens in your pipelinescoming
GitOps-native — policy changes are commits, not ticketscoming
Plan, preview, and rollback every change like any other infrastructurecoming
terraform apply
main.tf
terraform · rest — same fabric, pick your tool · pulumi coming
04how we deliver
Eight architectural decisions that make the above possible.
Here is the architecture behind each outcome above, and which parts of it run today.
01
Kernel
wireguard tunnels
Encrypted in the kernel
Gateways carry traffic over kernel WireGuard with ChaCha20-Poly1305 — no IPsec, and none of its ESP MTU headaches. Multi-tunnel WireGuard with CPU affinity is coming. Throughput figures will be published once they are measured.
02
0
agents in your workload vpcs
Nothing inside your apps
Your workload spoke VPCs stay untouched — not an agent, not a VM, not a sidecar. The fabric runs in a separate edge tier of gateways in your own central VPCs. Orchestrating that tier for you, and attaching workload spokes through native CSP constructs, are coming.
03
XDP + TC
kernel hooks
eBPF-native from day zero
An XDP program sheds abusive traffic at the NIC and a TC program enforces policy after decryption, both in the kernel with the networking stack intact. No DPDK NIC takeover, no fragile userspace packet paths.
04
0
kubernetes clusters needed
No Kubernetes required
Infrastructure-grade, not pod-grade. Gateways run as a service on a VM and work at the VPC and subnet level, so your workloads run however they run. Bare-metal gateways are coming.
05
Any
underlay, any csp
Underlay-agnostic, CSP-native
Telaron is the control plane above the wire — not the wire itself. Gateways reach each other over WireGuard between routable addresses, so any path that carries IP will do. Coming: an orchestrator that provisions the underlay for you, including a managed cloud exchange (Equinix Fabric, Megaport) or AWS Interconnect’s free multi-cloud tier; spoke attachment through CSP-native constructs, GCP first; and replacing the cross-charging transit layers (AWS TGW, Azure Virtual WAN, GCP NCC) with no per-GB transit tax.
06
API
behind every click
Policy as code, always
Everything Command Center does goes through a public REST API, and a Terraform provider covers clusters and spokes. Wider Terraform coverage, a Pulumi SDK and GitOps reconciliation are coming. No ClickOps traps, no console-only configuration.
07
Zero
packet content exposure
Data sovereignty by architecture
The SaaS control plane handles configuration metadata and telemetry only — never customer packet content. An architectural property, not a policy promise. Documentable for compliance.
08
Free
community tier
Priced for the mid-market
Community is free. Pro and Enterprise are priced per gateway for the mid-market. No per-spoke gateway VM compute today; removing CSP transit data-processing fees (AWS TGW, Azure Virtual WAN, GCP NCC) comes with cross-cloud transit.
05at a glance
Where Telaron fits
Three rows, three platforms. The full matrix covers what each one leads on, and where several of them work alongside Telaron rather than against it.
capability
Telaron
Aviatrix
Cisco MCD
Encryption & throughput
WireGuard ChaCha20; throughput not yet published
IPSec ESP, ~1.25 Gbps/core
IPSec (NGFW), per-core ceiling
Spoke compute
None in workload VPCs; edge tier in customer-owned central VPCs
all tiers include the apache-2.0 gateway data plane · switch or cancel anytime
07roadmap
What we're building next
The v1 platform ships now. These are the near-term and horizon deliveries building on it — directional, not date-bound. Detail-level feature lists live in the docs.
near-term · next 6 months
Shipping into v1
GitOps CI via OIDC workload identity
Native GitHub Actions & GitLab CI integration through our own OIDC IdP. Short-lived tokens minted per-run — no long-lived secrets in your pipeline.
Unified policy plane
Read policy from Cisco Multicloud Defense and Palo Alto Panorama into one normalised view. Keep your source of truth; let Telaron enforce it at the fabric edge.
SOC 2 Type II attestation
Closing out the attestation cycle. Report available under NDA for regulated customers on the Enterprise tier.
horizon · directional
Where we are heading
L7 deep packet inspection
Protocol-aware policy evaluated at the eBPF fast path. HTTP / gRPC / TLS SNI awareness without a proxy detour or userspace retransmit.
Policy federation — more sources
Expanding beyond Cisco MCD and Panorama. Prisma Cloud, Illumio, CrowdStrike Falcon. Wherever your policy of record lives, we will read it.
ML-assisted anomaly detection
Baseline flow patterns at the LGW, surface drift, stream to your SIEM. Detection-as-a-property of the fabric, not a bolted-on appliance.
roadmap is indicative · ships live in the docs · no dates, directions
08 · start shipping
Ready to rebuild your multi-cloud fabric?
Ask for a Community account and stand up a cluster on GCP. Script it through the API or Terraform, and keep your packet content on your own infrastructure.