Stop per-seat VPN costs.
Fully Managed NetBird (WireGuard mesh) for businesses. SSO/policies, ops & updates included.
Hosted in Germany or location of your choice.
Non-binding inquiry
Just your work email - we'll get back to you with an assessment.
Hosted in Germany • ISO 27001 & BSI C5 Datacenter • GDPR compliant
Your own NetBird Dashboard

Full control over peers, policies, and access rules - no DevOps overhead
A VPN solution for your business that doesn't punish growth.
With traditional VPN providers, costs rise with every new employee and device. Our flatrate stays the same - whether you have 10 or 100 users.
We run the infrastructure. You control the network.
A dedicated, fully managed instance just for your company. No shared resources.
Fully Managed Operations
We handle updates, security patches, and 24/7 monitoring of the control plane and relays.
High-Performance Relay
Includes 20 TB of traffic per month. Enough for heavy file transfers, RDP, and video calls. P2P traffic does NOT count!
Flexible Hosting Locations
Default: Germany (GDPR compliant). Also available in other regions on request:
SSO Integration
Connect your Okta, Azure AD, Google Workspace, or Keycloak. If you have no IdP, we deploy Zitadel by default. We help with the setup.
Unlimited Users & Devices
No artificial license limits. We recommend this plan for up to 500 active clients for optimal performance.
Daily Backups
Automated backups of your configuration and policies.
Request Individual Offer
Fully Managed NetBird incl. setup, SSO, monitoring, updates & support. Fixed price, no per-user fees.
Migration made easy.
Moving from Tailscale, OpenVPN, or IPsec? We support your rollout.
Parallel Operation
NetBird runs alongside your old VPN during the transition. No downtime.
Easy Rollout
Deploy via MDM (Intune, Jamf) or simple install scripts.
Firewall Friendly
Works behind NATs and Firewalls without complex port forwarding (thanks to WireGuard NAT traversal).

Managed NetBird for production business networks
We set up NetBird as a dedicated, managed VPN platform and take care of ongoing operations: installation, SSO integration, monitoring, updates, and support.
- 24/7 monitoring & alerting for all instances
- Regular updates & security patches
- Personal support instead of ticket queues
- Experience with complex SSO integrations (Okta, Azure AD, Keycloak)
NetBird Compared
How does NetBird stack up against other VPN solutions? Our detailed comparisons:
All comparisons and more in our VPN Hub
Frequently Asked Questions
Topics
General
For growing companies tired of rising per-seat VPN costs. Ideal for teams of 25-30+ employees, remote-first companies, IT service providers, and anyone who wants to plan long-term - without costs exploding with every new hire.
NetBird is a modern Mesh VPN based on WireGuard. Unlike traditional VPNs (hub-and-spoke), a Mesh VPN connects all devices directly - without a central server bottleneck. This means: lower latency, higher resilience, and no single point of failure. NetBird combines this with zero-trust principles, granular access rules, and a modern dashboard.
We operate the entire NetBird infrastructure for you: management server, dashboard, signal server, and relay. Updates, security patches, and 24/7 monitoring are included. You don't have to worry about anything - except connecting your devices and defining access rules.
No. You get your own fully isolated NetBird instance - hosted on dedicated resources. No shared databases, no shared logs, no neighbors. Your data, your rules, your infrastructure.
No. This is B2B infrastructure: Identity/SSO, policies, rollout, site-to-site/routes, operations/monitoring - for enterprise networks, not consumer privacy VPN.
Remote work & home office, site-to-site connectivity, hybrid cloud (AWS/Azure/GCP + on-prem), partner/contractor access with granular rules, admin access to servers/DB/backoffice without VPN gateway sprawl.
Hosting & Compliance
By default in Germany - in an ISO 27001 and BSI C5 certified datacenter. Other locations are available on request (EU, USA, UAE, or on-premise at your location).
Yes. Hosted in Germany, no data transfer to third countries (unless you choose a different location), data processing agreement (DPA) available. Perfect for companies with strict compliance requirements.
Yes - standard for B2B and included by default. This is often a decisive point in the procurement process.
No. With WireGuard-based setups, traffic remains end-to-end encrypted. Private keys stay on devices. Even relay servers can only forward traffic, not decrypt it.
SSO & Identity
All common identity providers: Okta, Azure AD (Entra ID), Google Workspace, Keycloak, Authentik, and other OIDC/SAML-compatible systems. If you don't have an IdP yet, we deploy Zitadel as the default solution - at no extra cost.
Yes - with one clear note on licensing. SCIM synchronizes users and groups automatically with your identity provider: new employees are created, departing ones deactivated immediately. When self-hosting, SCIM is not part of the free Community Edition but of the commercial licence (Commercial Starter, €2,000 per year for up to 50 users, as of July 2026). We clarify before the build whether you actually need SCIM - for many setups group sync via the JWT claim is enough, and that works in the Community Edition too.
Policies control who can access which resources (principle: least privilege). This is the difference between "VPN on/off" and real access control - essential for B2B compliance and security.
With IdP Sync, permissions are automatically revoked as soon as the account is deactivated in the identity provider. No manual cleanup needed - important for offboarding compliance.
Technology & How It Works
No. NetBird uses NAT traversal and UDP hole punching - works behind most firewalls and NATs without port forwarding. In rare cases (e.g., carrier-grade NAT), the relay automatically kicks in.
No! Most traffic runs peer-to-peer (P2P), directly between devices - encrypted with WireGuard. Only signaling (connection setup) goes through our servers. The relay is only used when direct P2P traffic isn't possible.
Yes. With NetBird you can route entire subnets - ideal for connecting offices, datacenters, or cloud VPCs. A router peer forwards traffic to the local network.
Windows, macOS, Linux, iOS, Android - plus Docker and Kubernetes. The clients are open source and easy to deploy (MSI, PKG, APT, etc.).
Yes - hybrid is a standard scenario. Routing peers in the cloud and on-prem enable seamless connections between all environments (admin access, internal services, private subnets).
P2P connections are usually fastest (no gateway bottleneck). Relay fallback is slower but reliable. Actual performance depends on NAT/firewall and routing - we optimize this with you.
Comparison with Alternatives
NetBird is based on WireGuard - significantly faster, lighter, and more modern than OpenVPN or IPsec. Add to that the mesh principle (no central bottleneck), zero-trust policies, and a modern management dashboard. No certificate chaos, no complicated configs.
All three are good products - but with per-seat pricing that quickly gets expensive for growing teams. Our flatrate stays the same whether you have 20 or 200 users. Plus: dedicated instance (no shared SaaS), hosting in Germany, and personal support instead of ticket queues. Detailed comparisons available at VPN Hub: /en/blog/vpn/
Yes, absolutely. NetBird can run alongside your existing VPN. You can migrate gradually - first individual teams or use cases, then the rest. No big-bang switch required.
Not quite. Zero Trust is a security concept (identity, policies, least privilege). A mesh VPN can be part of it - but doesn't replace IAM or endpoint security. NetBird combines both: mesh architecture with zero-trust policies.
Migration & Rollout
Often just a few days - depending on SSO integration, routing/site-to-site requirements, and internal approvals. A pilot with 10-20 users is usually live in 1-2 days.
Yes - we plan the rollout so IT doesn't have to manually touch each device. Deployment via MDM, install scripts, or manual as needed.
Unclear groups/policies (who really needs access?), subnet routing without clean network docs, restrictive firewalls/NAT without relay plan, missing offboarding automation. We help you avoid these pitfalls.
Operations & Support
Yes - operations without monitoring is unrealistic in an enterprise context. We set this up by default and proactively notify you of issues.
Regular and predictable - including maintenance window logic when required. Critical security patches are applied promptly.
Yes - no call center, but direct contact. You can reach us via email, chat, or phone.
Pricing & Contract
Correct. The Standard plan supports up to 200 devices, Premium up to 1,000 devices. Need more? Contact us for custom cluster setups.
20 TB is the monthly relay traffic limit - traffic that does NOT run directly P2P. In practice, most teams use only a fraction of this because most traffic flows directly between devices. If you exceed the limit: Each additional TB costs only €1. We won't just cut you off.
Yes. Monthly cancellation possible, no vendor lock-in. Your data belongs to you - we'll even help with export if you want to switch.
Because we don't charge per seat and don't have to burn VC millions. We run efficient infrastructure, use open-source software (NetBird), and pass the cost savings on to you. Simple as that.
Your dedicated instance is ready within 24 hours of order confirmation. We do the SSO integration together in a short call. Client rollout can be prepared in parallel.
Standard (on request) is ideal for teams up to 200 devices with 1 Gbit/s NIC. Premium (on request) offers 10 Gbit/s NIC, up to 1,000 devices, priority support, dedicated infrastructure, custom relay locations, SLA guarantee and a dedicated account manager.
Yes. In a short call we show you the setup, clarify your requirements and put together a fitting offer - non-binding and with no credit card.
Yes, anytime. We migrate your instance seamlessly to Premium infrastructure.
Rough user/device count, your SSO/IdP (Azure AD, Okta, Google, Keycloak…), whether site-to-site/subnet routing is needed, and if EU/DE hosting is desired. With that, we can give a recommendation in 15 minutes.






















