Alternative to Tailscale / Twingate / ZeroTier (B2B)
Fully Managed NetBird (WireGuard mesh) for businesses. SSO/policies, ops & updates included.
Hosted in Germany or location of your choice.
Case Study Promo: 6 Months Free
We're giving away 6 months of Managed NetBird to 3 companies (value: €1,499.40) – for switchers from Tailscale, Twingate, ZeroTier, or other VPN solutions.
Only for eligible companies.
Trusted by international companies



No subscription. No credit card. Access in <24h via email.
Hosted in Germany • ISO 27001 Datacenter • GDPR compliant
What you get

Full control over peers, policies, and access rules — no DevOps overhead
With traditional VPN providers, costs rise with every new employee and device. Our flatrate stays the same – whether you have 10 or 100 users.
Traditional VPN services punish your growth. We don't. Our managed infrastructure scales with you.
No setup fee (normally €499)
Monthly cost for 50 users (Business tier with SSO & Policies)
Savings vs Tailscale
€650
per month
Annual Savings
€7,801
per year (vs Tailscale)
Break-even
14 Users
Start saving at 14 users
* Business tiers compared (incl. SSO & Policies). Pricing: Tailscale $18, Twingate $10, Perimeter 81 $12 + $40 Gateway.
| Feature | Tailscale / Twingate | WZ-IT Managed NetBird |
|---|---|---|
| Pricing Model | $10–$18 per User / Month | Flat €249.90 / Month |
| Cost for 50 Users | €475–€850 / Month | €249.90 / Month |
| Cost for 200 Users | €1,900–€3,400 / Month | €249.90 / Month |
| SSO (Okta/Azure AD/Google, Zitadel by default if needed) | Business Tier only | |
| Granular ACLs / Policies | Business Tier only | |
| Dedicated Gateway / Relay | Extra charge (e.g. +$40/mo) | |
| Data Sovereignty | US Cloud | Your Private Instance (DE/US/UAE) |
Save between €2,700 and €7,200 per year compared to market leaders.
A dedicated, fully managed instance just for your company. No shared resources.
We handle updates, security patches, and 24/7 monitoring of the control plane and relays.
Includes 20 TB of traffic per month. Enough for heavy file transfers, RDP, and video calls. P2P traffic does NOT count!
Default: Germany (GDPR compliant). Also available in other regions on request:
Connect your Okta, Azure AD, Google Workspace, or Keycloak. If you have no IdP, we deploy Zitadel by default. We help with the setup.
No artificial license limits. We recommend this plan for up to 500 active clients for optimal performance.
Automated backups of your configuration and policies.
Fully Managed NetBird incl. Setup, SSO, Monitoring, Updates & Support.
Cancel anytime
12 months term
Pay only 9 months (effectively €187.43/month)
Save €749.70/year vs. monthly
* B2B only. Offer valid until Dec 24.
No subscription, no credit card. Credentials via email in <24h.
Moving from Tailscale, OpenVPN, or IPsec? We support your rollout.
NetBird runs alongside your old VPN during the transition. No downtime.
Deploy via MDM (Intune, Jamf) or simple install scripts.
Works behind NATs and Firewalls without complex port forwarding (thanks to WireGuard NAT traversal).

At WZ-IT, we operate and manage over 30 NetBird instances for customers across various industries – from startups to mid-sized enterprises. We handle everything: installation, SSO integration, monitoring, updates, and support.
How does NetBird stack up against other VPN solutions? Our detailed comparisons:
All comparisons and more in our VPN Hub
Topics
For growing companies tired of rising per-seat VPN costs. Ideal for teams of 15–20+ employees, remote-first companies, IT service providers, and anyone who wants to plan long-term – without costs exploding with every new hire.
NetBird is a modern Mesh VPN based on WireGuard. Unlike traditional VPNs (hub-and-spoke), a Mesh VPN connects all devices directly – without a central server bottleneck. This means: lower latency, higher resilience, and no single point of failure. NetBird combines this with zero-trust principles, granular access rules, and a modern dashboard.
We operate the entire NetBird infrastructure for you: management server, dashboard, signal server, and relay. Updates, security patches, and 24/7 monitoring are included. You don't have to worry about anything – except connecting your devices and defining access rules.
No. You get your own fully isolated NetBird instance – hosted on dedicated resources. No shared databases, no shared logs, no neighbors. Your data, your rules, your infrastructure.
No. This is B2B infrastructure: Identity/SSO, policies, rollout, site-to-site/routes, operations/monitoring – for enterprise networks, not consumer privacy VPN.
Remote work & home office, site-to-site connectivity, hybrid cloud (AWS/Azure/GCP + on-prem), partner/contractor access with granular rules, admin access to servers/DB/backoffice without VPN gateway sprawl.
By default in Germany – in an ISO 27001-certified datacenter. Other locations are available on request (EU, USA, UAE, or on-premise at your location).
Yes. Hosted in Germany, no data transfer to third countries (unless you choose a different location), data processing agreement (DPA) available. Perfect for companies with strict compliance requirements.
Yes – standard for B2B and included by default. This is often a decisive point in the procurement process.
No. With WireGuard-based setups, traffic remains end-to-end encrypted. Private keys stay on devices. Even relay servers can only forward traffic, not decrypt it.
All common identity providers: Okta, Azure AD (Entra ID), Google Workspace, Keycloak, Authentik, and other OIDC/SAML-compatible systems. If you don't have an IdP yet, we deploy Zitadel as the default solution – at no extra cost.
Yes, depending on the NetBird edition. SCIM enables automatic user and group synchronization with your identity provider – new employees are automatically created, departing ones immediately deactivated. In the self-hosted version we operate for you, this is available.
Policies control who can access which resources (principle: least privilege). This is the difference between "VPN on/off" and real access control – essential for B2B compliance and security.
With IdP Sync, permissions are automatically revoked as soon as the account is deactivated in the identity provider. No manual cleanup needed – important for offboarding compliance.
No. NetBird uses NAT traversal and UDP hole punching – works behind most firewalls and NATs without port forwarding. In rare cases (e.g., carrier-grade NAT), the relay automatically kicks in.
No! Most traffic runs peer-to-peer (P2P), directly between devices – encrypted with WireGuard. Only signaling (connection setup) goes through our servers. The relay is only used when direct P2P traffic isn't possible.
Yes. With NetBird you can route entire subnets – ideal for connecting offices, datacenters, or cloud VPCs. A router peer forwards traffic to the local network.
Windows, macOS, Linux, iOS, Android – plus Docker and Kubernetes. The clients are open source and easy to deploy (MSI, PKG, APT, etc.).
Yes – hybrid is a standard scenario. Routing peers in the cloud and on-prem enable seamless connections between all environments (admin access, internal services, private subnets).
P2P connections are usually fastest (no gateway bottleneck). Relay fallback is slower but reliable. Actual performance depends on NAT/firewall and routing – we optimize this with you.
NetBird is based on WireGuard – significantly faster, lighter, and more modern than OpenVPN or IPsec. Add to that the mesh principle (no central bottleneck), zero-trust policies, and a modern management dashboard. No certificate chaos, no complicated configs.
All three are good products – but with per-seat pricing that quickly gets expensive for growing teams. Our flatrate stays the same whether you have 20 or 200 users. Plus: dedicated instance (no shared SaaS), hosting in Germany, and personal support instead of ticket queues. Detailed comparisons available at VPN Hub: /en/blog/vpn/
Yes, absolutely. NetBird can run alongside your existing VPN. You can migrate gradually – first individual teams or use cases, then the rest. No big-bang switch required.
Not quite. Zero Trust is a security concept (identity, policies, least privilege). A mesh VPN can be part of it – but doesn't replace IAM or endpoint security. NetBird combines both: mesh architecture with zero-trust policies.
Often just a few days – depending on SSO integration, routing/site-to-site requirements, and internal approvals. A pilot with 10–20 users is usually live in 1–2 days.
Yes – we plan the rollout so IT doesn't have to manually touch each device. Deployment via MDM, install scripts, or manual as needed.
Unclear groups/policies (who really needs access?), subnet routing without clean network docs, restrictive firewalls/NAT without relay plan, missing offboarding automation. We help you avoid these pitfalls.
Yes – operations without monitoring is unrealistic in an enterprise context. We set this up by default and proactively notify you of issues.
Regular and predictable – including maintenance window logic when required. Critical security patches are applied promptly.
Yes – no call center, but direct contact. You can reach us via email, chat, or phone.
You get 14 days access to your own demo platform where you can test NetBird with your team. No payment information required, no subscription commitment. Just try it out – and if it fits, we start with the production setup.
Correct. We don't charge per seat. For optimal performance, we recommend this package for up to 500 simultaneously connected devices. Need more? We have larger cluster setups available.
20 TB is the monthly relay traffic limit – traffic that does NOT run directly P2P. In practice, most teams use only a fraction of this because most traffic flows directly between devices. If you exceed the limit: Each additional TB costs only €1. We won't just cut you off.
Yes. Monthly cancellation possible, no vendor lock-in. Your data belongs to you – we'll even help with export if you want to switch.
Because we don't charge per seat and don't have to burn VC millions. We run efficient infrastructure, use open-source software (NetBird), and pass the cost savings on to you. Simple as that.
Your dedicated instance is ready within 24 hours of order confirmation. We do the SSO integration together in a short call. Client rollout can be prepared in parallel.
You pay €2,249.10 once for 12 months (equals 9 paid months, effectively €187.43/month). The benefit remains regardless of user/device count. This saves €749.70 compared to the monthly plan.
Yes. The trial is without subscription and without credit card. After the 14-day trial, we switch to monthly or annual plan on request.
You can renew before expiration (monthly or annual). We'll remind you in time. No automatic renewal without your consent.
Rough user/device count, your SSO/IdP (Azure AD, Okta, Google, Keycloak…), whether site-to-site/subnet routing is needed, and if EU/DE hosting is desired. With that, we can give a recommendation in 15 minutes.
Start with the Enterprise VPN Flatrate — no per-device fees, full control.
Whether a specific IT challenge or just an idea – we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
CEOs of WZ-IT
NetBird is a product of NetBird GmbH. WZ-IT is not affiliated with or endorsed by NetBird GmbH.
