Skip to main content
P

Pangolin

Pangolin provides a Zero Trust Access Platform that uses outbound‑only WireGuard connectors to create secure tunnels into remote networks without requiring inbound firewall rules. It integrates with existing identity providers for role‑based, device‑posture aware access, offering clientless browser access for public services and a cross‑platform client for private resources, all managed through a centralized policy engine with audit logging.

Founded 20256700+ followers
Updated 3 months ago

Funding

$4.7M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

C
Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

Enterprises and service providers rely on traditional VPNs or ad‑hoc bastion hosts that require open inbound ports, manual firewall changes, and per‑device credential management. This model creates a large attack surface, hampers scalability, and makes it difficult to enforce identity‑based, context‑aware access policies.

Solution

Pangolin delivers a Zero Trust Access Platform built on WireGuard that establishes outbound‑only tunnels from lightweight connectors (called sites) into remote networks. Users authenticate through existing identity providers, and the platform enforces granular, resource‑level policies that consider user role, device posture, and location. Public web applications are exposed via an identity‑aware reverse proxy, while private services such as databases or SSH hosts are accessed through a dedicated client on Windows, macOS, Linux, iOS, or Android. All traffic remains encrypted end‑to‑end, and the control plane provides real‑time audit logs and activity reports. The solution can be run as a managed cloud service or self‑hosted for full data sovereignty. Integration hooks (API, Blueprint YAML, and Docker labels) enable automation and CI/CD pipelines.

Target Audience

The platform is aimed at enterprise IT, security, and engineering teams that need secure, scalable remote access to internal applications and infrastructure. It also serves managed service providers seeking a repeatable, multi‑tenant solution for delivering zero‑trust connectivity to their clients.

Features

  • Outbound‑only WireGuard connectors (sites) that require no inbound firewall rules and can be deployed on any host or edge device.
  • Identity provider integration (SSO, MFA) with role‑based access control and optional device‑posture verification.
  • Dual access model: clientless browser access for public resources and a cross‑platform client for private resources (SSH, databases, internal APIs).
  • Centralized policy engine with declarative configuration (Blueprints, YAML, API) and comprehensive audit logging for compliance.
  • Multi‑tenant organization support and extensible REST API for automation, custom branding, and third‑party integrations.
This profile is AI-generated and may contain inaccuracies.