The next-generation VPN, sovereign by design.
TxHub is a sovereign mesh VPN, operated for you in fully isolated regions. Connect every device with the TxHub app over WireGuard, and keep the entire control plane — keys, policy, and identity — held in-region on your behalf.
- ::WireGuard peer-to-peer
- ::Native apps
- ::Configurable SSO
- ::Sovereign by design
Two sovereign instances. Zero shared dependencies.
TxHub runs as independently-operated instances, each fully self-contained. Your network lives entirely within one jurisdiction — its control plane, keys, and identity never cross a border.
Completely isolated to Iceland
Runs on bare-metal in an Icelandic datacenter, operated by TxHub. No cloud services, no SaaS, no third-party control planes. Data and control never leave the country.
- Infrastructure
- Bare-metal, Icelandic datacenter
- External dependencies
- None
- Data & control plane
- Never leaves Iceland
- Operated by
- Independent Icelandic instance
US data residency on AWS
A separate, independently-operated instance running in AWS US-East (Virginia) — for US customers and data-residency requirements, isolated from every other region.
- Infrastructure
- AWS US-East (Virginia)
- Data residency
- United States
- Control plane
- Isolated per region
- Operated by
- Separate US instance
No cross-region replication. No shared control plane. Sovereignty is the architecture, not a setting.
Everything a modern mesh needs — and nothing it doesn't.
A complete control plane built on proven primitives, with the operational surface trimmed to what matters.
WireGuard mesh
Encrypted peer-to-peer tunnels between every device, coordinated automatically. No hub to bottleneck your traffic.
Private TxNets
Carve isolated networks — each with its own devices, users, and policy — from a single control plane.
Native apps
First-party TxHub apps for Windows, macOS and Linux. Install, sign in, and you are on your network — no configuration.
ACL policy control
Declarative rules decide exactly who reaches what. Fail-closed by default — access is granted, never assumed.
Device & user management
Approve devices, manage users, and see your entire fleet at a glance from one dashboard.
MagicDNS
Reach every machine by name. Automatic, private DNS resolves across your whole TxNet.
DERP relay
In-region relays keep peers connected through strict NATs and firewalls — with no public cloud in the path (Iceland).
OIDC sign-in
Authenticate with your identity provider. Microsoft Entra ID supported out of the box.
Sovereign by design
TxHub runs the entire control plane in-region — Iceland or US. Nothing phones home, nothing leaves your jurisdiction.
Install the app. We run the sovereign control plane.
The TxHub app connects to a control plane we operate in your chosen region. Nothing to deploy, nothing to self-host.
- 01
Choose your sovereign region
Pick where your network lives — fully isolated Iceland or AWS US-East (Virginia). TxHub operates the control plane there for you; nothing to deploy.
- 02
Install the TxHub client
Install the TxHub app on Windows, macOS or Linux and sign in. One command on servers — the app already knows where your region is.
- 03
Your private mesh is live
Devices authenticate via OIDC, exchange WireGuard keys, and form an encrypted peer-to-peer mesh — keys, policy, and identity all held in-region by TxHub, managed from the dashboard.
What is WireGuard?
WireGuard is the modern VPN protocol: a fast, simple way to create encrypted tunnels between devices. It replaces the complexity of IPsec and OpenVPN with a small design built on today's best cryptography.
Every TxHub connection is a WireGuard tunnel. TxHub handles the hard part — exchanging keys, finding a path through firewalls and NAT, and applying your access policy — so devices simply connect.
- 01your device — creates its own key pair — the private key never leaves it
- 02control plane — hands out public keys and policy only
- 03peers — connect directly, end-to-end encrypted
- 04relay (fallback) — forwards ciphertext it cannot read
Modern cryptography
Curve25519 for key exchange, ChaCha20-Poly1305 for encryption, BLAKE2s for hashing. One fixed, current set — no cipher negotiation to downgrade.
Small enough to audit
Around 4,000 lines of code, against hundreds of thousands for older VPN stacks. Less code means less to get wrong, and it has been formally verified.
Built into Linux
Part of the Linux kernel since version 5.6, with fast implementations on Windows, macOS, iOS and Android.
Fast, and it roams
Connections set up in a single round trip and survive switching networks — Wi-Fi to mobile and back without dropping.
WireGuard is a registered trademark of Jason A. Donenfeld.
Reach everything by name, not by number.
TxHub runs DNS for your TxNet. Devices get names automatically, you add the zones and records your team needs, and internal domains go to your own nameservers — all managed from the dashboard and pushed to every device.
No hosts files, no separate DNS server to run, and nothing to configure on the devices themselves.
- laptop.acme.tx.netmachine100.64.0.12
- nas.acme.tx.netmachine100.64.0.7
- printer.acme.internalA192.168.1.40
- wiki.acme.internalmachinenas
- corp.examplesplit10.0.0.53
Every machine has a name
Each device is published under your TxNet domain the moment it joins — laptop.acme.tx.net — and the name follows it when its address changes.
Your own zones
Add private zones like acme.internal and publish A, AAAA or machine records. A machine record always points at that device, wherever it is.
Split DNS
Send internal domains such as corp.example to your own nameservers, and everything else to the resolvers you choose.
Short names
Search domains let people type printer instead of printer.acme.internal. Devices try your zones in order.
Get the TxHub app.
Install it, sign in, and you're on your TxNet. Always the latest version.
Linux
Debian/Ubuntu and Fedora/RHEL packages.
Builds aren't code-signed yet, so your OS may ask you to confirm the first launch. SHA256SUMS · all releases & install guides
Sovereignty isn't a setting you toggle. It's where the keys live, where the policy runs, and where your data stays — held in-region, on your behalf.
Sovereign networking, operated for you.
Pick your region, connect your first devices, and see the mesh form in minutes.
Prefer to talk first? info@txhub.is