Skip to content

Remote Access You Control, Recorded and Revocable.

SinonVPN is a self-hosted remote-access platform combining three VPN protocols (WireGuard, IKEv2/IPsec and OpenVPN) with an identity-aware SSH and RDP bastion. It records every session, brokers just-in-time credentials, and revokes access the moment risk crosses a line.

Self-host or SinonTech-hosted. Session recording. Air-gap capable.

Request Access See the Features

Desktop & Mobile Apps

Native SinonVPN clients. The macOS and Linux desktop apps are available now in alpha; Windows, iOS and Android are on the way. Contact us to join the alpha.

🖥

macOS

Alpha
🐧

Linux

Alpha
🪟

Windows

Coming Soon
📱

iOS

Coming Soon
🤖

Android

Coming Soon

Platform at a Glance

3

VPN Protocols

WireGuard, IKEv2/IPsec and OpenVPN, each driving its real system daemon from one control plane.

2

Bastion Protocols

SSH and clientless, browser-based RDP/VNC, with every session recorded and replayable.

59

Schema Migrations

A mature data model behind identity, JIT access, DLP, audit and multi-tenancy.

31

API Modules

REST API across VPN, bastion, JIT, DLP, posture, identity, audit and administration.

6

Deployment Modes

Bare metal, Docker, Kubernetes, cloud VMs, virtual environments, and fully air-gapped.

Three VPNs and a Real Bastion

Most tools give you one VPN protocol or one access model. SinonVPN gives you all three major VPN protocols and a full privileged-access bastion, managed together, with a common audit trail.

🔒

Three VPN Protocols

WireGuard, IKEv2/IPsec (strongSwan) and OpenVPN, all genuinely implemented against their real daemons. Users get self-service client profiles and enrolment.

🖥

SSH & RDP/VNC Bastion

An identity-aware SSH proxy with host-key pinning, plus clientless RDP and VNC in the browser, so nobody needs a VPN client or a thick RDP client to reach a jump target.

🎥

Session Recording

Every bastion session is recorded (asciinema for terminals, full stream for RDP/VNC) and hashed, so you can replay exactly what happened during any access.

Just-in-Time Access

Access is requested, approved, consumed and expired. Each session is brokered a fresh, ephemeral SSH credential that is revoked the moment the session ends — no standing keys.

📛

SSH Certificate Authority

A built-in SSH CA mints short-lived user certificates instead of distributing long-lived keys, with a key revocation list published automatically.

🗄

Credential Vaulting

Secrets are protected with per-tenant envelope encryption (libsodium), with an optional hardware security module for the master key.

Access That Watches Itself

The difference between a VPN and a security control is what happens during and after the session. SinonVPN scores risk live, inspects content inline, and records everything to a tamper-evident log.

📊

Live Risk Scoring

Sessions are scored as they happen, and the SSH bridge enforces a revoke threshold in real time. A session that turns risky is cut, not just logged for later.

🛡

Inline DLP

Data-loss prevention on bastion sessions blocks risky pastes and watches outbound content, so a jump host does not become an exfiltration channel.

Tamper-Evident Audit

Every action lands in a hash-chained audit log with cryptographic anchoring, so the record of who did what cannot be quietly rewritten.

🔑

Identity & MFA

Single sign-on via OIDC with SCIM provisioning, TOTP multi-factor and step-up authentication for sensitive access.

📡

SIEM Forwarding

Access events forward to your SIEM, so remote-access activity sits alongside the rest of your security telemetry.

🌐

Egress & Firewall Control

Per-tenant egress policies and an nftables firewall layer govern what a connected user can actually reach.

Technical Specifications

VPN protocolsWireGuard, IKEv2/IPsec (strongSwan), OpenVPN — with self-service client profiles and enrolment
BastionIdentity-aware SSH proxy (host-key pinning), clientless browser RDP and VNC, session recording (asciinema + full stream), SSH certificate authority
Privileged accessJust-in-time access with approval workflow, ephemeral per-session SSH credentials, credential vaulting (per-tenant envelope encryption, optional HSM)
Session securityLive risk scoring with auto-revoke, inline DLP (paste-block + outbound content), device posture inputs
IdentityOIDC single sign-on, SCIM provisioning, TOTP MFA and step-up authentication
Network controlPer-tenant egress policies, nftables firewall layer, gateway enrolment and mesh coordination
AuditHash-chained audit log with cryptographic anchoring; SIEM forwarding
DatabasesPostgreSQL 16 (59 migrations), Redis 7
API31 route modules, 215 endpoints
Multi-tenancyOrganisation → tenant → sub-tenant; application-enforced isolation; per-tenant data keys
Host requirementsLinux host with the WireGuard kernel module, strongSwan and OpenVPN, and elevated network capabilities
Backend stackTypeScript on Node.js, Express, PostgreSQL, Redis, BullMQ workers, libsodium crypto
Frontend stackReact 18 with TypeScript, Vite, a web terminal (xterm), browser RDP/VNC (Guacamole), asciinema playback
DeploymentBare metal (systemd), Docker Compose, Kubernetes (Helm), cloud VMs, virtual environments, air-gapped

Frequently Asked Questions

What is SinonVPN?

A self-hosted remote-access platform. It runs three VPN protocols (WireGuard, IKEv2/IPsec and OpenVPN) and an identity-aware SSH and RDP/VNC bastion in one place. Every bastion session is recorded, access is granted just-in-time with ephemeral credentials, and the whole thing writes to a tamper-evident audit log. It runs on PostgreSQL and Redis on your own infrastructure.

Are all three VPN protocols actually implemented?

Yes. WireGuard, IKEv2/IPsec (via strongSwan) and OpenVPN each drive their real system daemon. The platform renders native configuration and applies it, rather than stubbing one and listing the others. You choose the protocol that fits each use case, and users get self-service client profiles for it.

How is the bastion different from just giving people SSH?

Nobody holds a standing key. Access is requested and approved, the session is brokered a fresh SSH credential that is revoked when it ends, the whole session is recorded and replayable, and risk is scored live so a session can be cut mid-stream. Inline DLP blocks risky pastes and watches outbound content. RDP and VNC run clientless in the browser, so there is nothing to install to reach a jump target.

What does it need to run on?

A Linux host with the WireGuard kernel module, strongSwan and OpenVPN available, and elevated network capabilities, because it manages real VPN daemons and network interfaces. It deploys on bare metal, Docker, Kubernetes, virtual environments and air-gapped networks.

Can it run air-gapped?

Yes. There is an offline bundle packager and air-gap installer. Internal VPN access, the bastion, session recording, JIT approval and the audit log all function with no route to the internet — which is exactly the environment where controlled, recorded privileged access matters most.

What stage is SinonVPN at?

Closed beta. It is a working platform: three real VPN stacks, a full SSH/RDP/VNC bastion, 59 database migrations and 215 API endpoints, covered by unit tests across its crypto, config rendering and policy code. Request access and we will walk you through the architecture and a deployment plan before you commit anything.

Control Your Remote Access

SinonVPN is in closed beta. Request access for deployment documentation, an architecture walkthrough, and priority onboarding.

Remote Access on Your Terms.

Talk to an engineer about running your remote access on infrastructure you own, or let us host it for you and still own every byte.

0141 536 0433  ·  info@sinontech.co.uk

Contact Us