Kaligon Mesh — secure overlay fabric

Private overlay networks for the cellular edge, one per tenant.

Every tenant gets its own overlay network — its own certificate authority, its own lighthouses and relays. Isolation is structural, not firewall rules. Built on the open-source Nebula data plane, operated by Kaligon on its own hardware.

01 / why mesh

Isolation you can point at, not policy you have to trust.

STRUCTURAL ISOLATION

An entire private overlay per tenant

Each tenant runs its own CA and its own lighthouse, relay and ingest instances. There is no shared fabric to firewall — another tenant's network isn't a rule you audit, it's a different network entirely.

OWNED INFRASTRUCTURE

Built on Nebula, operated by Kaligon

The data plane is Nebula — the MIT-licensed overlay proven at scale. Kaligon builds the control plane above it — enrollment, certificates, config — and runs the whole stack on its own hardware, not a hyperscaler.

CELLULAR EDGE

Made for devices on carrier networks

Hole-punching and relays for carrier-grade NAT, automatic enrollment for hardware-backed device identities, and a certificate lifecycle designed for fleets you can't walk over to.

02 / how it works

From bare device to encrypted overlay in three steps.

Register

A device identity and its bootstrap credential are registered to your tenant — at the staging bench, before the device ever ships.

Auto-enroll

In the field, the device authenticates through the fabric gateway and receives its certificate and network config from your tenant's stack. No hand-provisioning.

Connect

Traffic rides the encrypted overlay, end to end. Devices, groups and certificates are managed from the mesh.sc console.

03 / request access

Get on the list.

Kaligon Mesh is opening up to its first tenants. Tell us a little about your fleet and we'll be in touch.

prefer email? hello@kaligon.com