VPN · Shield · ZTNA

Private network for people — VPN and Shield

0trust.services is the private access plane: always-on VPN for devices, and Shield for privacy DNS and secure egress. Identity and passkeys live on 0trust.cloud.

VPNvpn.0trust.services·Shield DoHdns.0trust.services·ZTNA/access

VPN

Always-on L3 for people and devices. Clients dial published PoPs.

Always on

Warm resume after sleep, network change, or radio blip so private routes stay ready.

🔐

Passkey + device bind

Human login on 0trust.cloud. Session tickets tied to the device, not a pasteable cookie alone.

🌍

Dial published PoPs

Clients dial known endpoints. Control plane at vpn.0trust.services.

📜

Policy at open

Grants and routes apply when the VPN session opens — entitlements follow identity.

Works with 0TrustOS

Node policy agent enforces grants on the host while VPN carries L3.

🛡

Pairs with Shield

Use VPN for private routes; use Shield for encrypted DNS and egress on the same identity.

  Control  https://vpn.0trust.services\n  Identity https://0trust.cloud  (passkeys)\n  Data     regional PoPs — client dials only

Shield

Privacy DNS and optional secure CONNECT egress through the services edge — session gated, not an open resolver.

🔎

DNS-over-HTTPS

https://dns.0trust.services/dns-query — private mesh labels plus public recursion.

🚪

Secure egress

HTTP CONNECT through the edge so apps leave on an encrypted path.

🛡

Device-bound

Passkey + DBSC required for production DoH and CONNECT — not a public open relay.

Shield setup

Endpoints, client tips, and status for privacy DNS and egress.

Zero-trust app access

Policy-gated HTTP paths for private apps — same identity as VPN and Shield.

🛡

App proxy

Reach private apps through policy-gated paths with the control-plane identity stack.

🔒

Device-bound sessions

Human traffic requires passkey login and a device-bound session before proxying.

⌨️

SSH and Kubernetes

Operator protocol paths on the same identity and policy model.

Identity from cloud

OIDC and WebAuthn on 0trust.cloud. Services enforces — it does not re-issue identity.

📡

Private names

Resolve mesh-accessible names while you stay on the private plane (via Shield DoH).

One identity, private access

Get a 0Trust accountVPNShield setup