The next-generation VPN, sovereign by design.

TxHub is a sovereign mesh VPN, operated for you in fully isolated regions. Connect every device with the TxHub app over WireGuard, and keep the entire control plane — keys, policy, and identity — held in-region on your behalf.

  • ::WireGuard peer-to-peer
  • ::Native apps
  • ::Configurable SSO
  • ::Sovereign by design
node-map / liveORTHO · λ−40°
◆ ICELAND · REYKJAVÍK
◇ US · VIRGINIA
SECURED
wireguard »»
● reykjavik-1 · isolated2 regions · 0 shared deps
2
sovereign regions
Iceland · United States
0
external deps
Iceland instance
100%
in-country data
Iceland
WireGuard
encryption
peer-to-peer
Digital sovereignty

Two sovereign instances. Zero shared dependencies.

TxHub runs as independently-operated instances, each fully self-contained. Your network lives entirely within one jurisdiction — its control plane, keys, and identity never cross a border.

Iceland · ReykjavíkREGION_IS

Completely isolated to Iceland

Runs on bare-metal in an Icelandic datacenter, operated by TxHub. No cloud services, no SaaS, no third-party control planes. Data and control never leave the country.

Infrastructure
Bare-metal, Icelandic datacenter
External dependencies
None
Data & control plane
Never leaves Iceland
Operated by
Independent Icelandic instance
United States · VirginiaREGION_US

US data residency on AWS

A separate, independently-operated instance running in AWS US-East (Virginia) — for US customers and data-residency requirements, isolated from every other region.

Infrastructure
AWS US-East (Virginia)
Data residency
United States
Control plane
Isolated per region
Operated by
Separate US instance

No cross-region replication. No shared control plane. Sovereignty is the architecture, not a setting.

Capabilities

Everything a modern mesh needs — and nothing it doesn't.

A complete control plane built on proven primitives, with the operational surface trimmed to what matters.

/ WIREGUARD/ MAGICDNS/ ACLs/ OIDC/ DERP/ CROSS-PLATFORM

WireGuard mesh

Encrypted peer-to-peer tunnels between every device, coordinated automatically. No hub to bottleneck your traffic.

Private TxNets

Carve isolated networks — each with its own devices, users, and policy — from a single control plane.

Native apps

First-party TxHub apps for Windows, macOS and Linux. Install, sign in, and you are on your network — no configuration.

ACL policy control

Declarative rules decide exactly who reaches what. Fail-closed by default — access is granted, never assumed.

Device & user management

Approve devices, manage users, and see your entire fleet at a glance from one dashboard.

MagicDNS

Reach every machine by name. Automatic, private DNS resolves across your whole TxNet.

DERP relay

In-region relays keep peers connected through strict NATs and firewalls — with no public cloud in the path (Iceland).

OIDC sign-in

Authenticate with your identity provider. Microsoft Entra ID supported out of the box.

Sovereign by design

TxHub runs the entire control plane in-region — Iceland or US. Nothing phones home, nothing leaves your jurisdiction.

How it works

Install the app. We run the sovereign control plane.

The TxHub app connects to a control plane we operate in your chosen region. Nothing to deploy, nothing to self-host.

  1. 01

    Choose your sovereign region

    Pick where your network lives — fully isolated Iceland or AWS US-East (Virginia). TxHub operates the control plane there for you; nothing to deploy.

  2. 02

    Install the TxHub client

    Install the TxHub app on Windows, macOS or Linux and sign in. One command on servers — the app already knows where your region is.

  3. 03

    Your private mesh is live

    Devices authenticate via OIDC, exchange WireGuard keys, and form an encrypted peer-to-peer mesh — keys, policy, and identity all held in-region by TxHub, managed from the dashboard.

device — txhub up
$txhub up
Opening browser for OIDC sign-in…
✓ Authenticated · you@org
✓ WireGuard keys exchanged
Connected to reykjavik-1 · 11 peers online
$
WireGuard

What is WireGuard?

WireGuard is the modern VPN protocol: a fast, simple way to create encrypted tunnels between devices. It replaces the complexity of IPsec and OpenVPN with a small design built on today's best cryptography.

Every TxHub connection is a WireGuard tunnel. TxHub handles the hard part — exchanging keys, finding a path through firewalls and NAT, and applying your access policy — so devices simply connect.

who holds the keys
  1. 01your device — creates its own key pair — the private key never leaves it
  2. 02control plane — hands out public keys and policy only
  3. 03peers — connect directly, end-to-end encrypted
  4. 04relay (fallback) — forwards ciphertext it cannot read

Modern cryptography

Curve25519 for key exchange, ChaCha20-Poly1305 for encryption, BLAKE2s for hashing. One fixed, current set — no cipher negotiation to downgrade.

Small enough to audit

Around 4,000 lines of code, against hundreds of thousands for older VPN stacks. Less code means less to get wrong, and it has been formally verified.

Built into Linux

Part of the Linux kernel since version 5.6, with fast implementations on Windows, macOS, iOS and Android.

Fast, and it roams

Connections set up in a single round trip and survive switching networks — Wi-Fi to mobile and back without dropping.

WireGuard is a registered trademark of Jason A. Donenfeld.

DNS management

Reach everything by name, not by number.

TxHub runs DNS for your TxNet. Devices get names automatically, you add the zones and records your team needs, and internal domains go to your own nameservers — all managed from the dashboard and pushed to every device.

No hosts files, no separate DNS server to run, and nothing to configure on the devices themselves.

acme · dns
  • laptop.acme.tx.netmachine100.64.0.12
  • nas.acme.tx.netmachine100.64.0.7
  • printer.acme.internalA192.168.1.40
  • wiki.acme.internalmachinenas
  • corp.examplesplit10.0.0.53

Every machine has a name

Each device is published under your TxNet domain the moment it joins — laptop.acme.tx.net — and the name follows it when its address changes.

Your own zones

Add private zones like acme.internal and publish A, AAAA or machine records. A machine record always points at that device, wherever it is.

Split DNS

Send internal domains such as corp.example to your own nameservers, and everything else to the resolvers you choose.

Short names

Search domains let people type printer instead of printer.acme.internal. Devices try your zones in order.

Download

Get the TxHub app.

Install it, sign in, and you're on your TxNet. Always the latest version.

Windows

64-bit installer with the tray app.

macOS

Menu-bar app for Apple Silicon and Intel.

Linux

Debian/Ubuntu and Fedora/RHEL packages.

download .deb$ sudo apt install ./txhub-linux-amd64.deb

Builds aren't code-signed yet, so your OS may ask you to confirm the first launch. SHA256SUMS · all releases & install guides

Sovereignty isn't a setting you toggle. It's where the keys live, where the policy runs, and where your data stays — held in-region, on your behalf.

THE TXHUB PRINCIPLE · SOVEREIGN BY DESIGN

Sovereign networking, operated for you.

Pick your region, connect your first devices, and see the mesh form in minutes.

Prefer to talk first? info@txhub.is