Back to work
Kaligon Platform

Kaligon Mesh

The device layer — a private, secure overlay network per tenant, for devices on carrier networks.

mesh.sc

Every tenant gets its own overlay network: its own certificate authority, its own lighthouses and relays. There is no shared fabric to firewall — another tenant’s network is not a rule you audit, it is a different network entirely. Isolation is structural, not policy you have to trust.

It is built for hardware you cannot walk over to. Devices are registered at the staging bench before they ship; in the field they authenticate through the fabric gateway and receive their certificate and network configuration automatically, with hole-punching and relays for carrier-grade NAT. No hand-provisioning.

The data plane is Nebula, the MIT-licensed overlay proven at scale. Kaligon builds the control plane above it — enrollment, certificates, configuration — and runs the whole stack on its own hardware rather than a hyperscaler.

Adport runs on it. Dozens of SB1 and X1 smart billboards report back over Kaligon Mesh, live in the field. Units are managed, not just deployed — they stay under control after they ship.

Every layer

Nebula data planeKaligon control planeed25519 certificatesCellular edge