How it works

Enforce boundaries that move with workloads.

PacketSpear Node agents carry the user-space enforcement boundary with every process. Enterprise Gate agents (managers) spin up the network intent model and apply enforcement at the wire.

1

Deploy Node agents

Ship the Node agent to each endpoint with the standard installer. Nodes use mTLS to authenticate to PacketSpear Core and begin exposing rich flow telemetry and process context.

2

Define policy-as-code

Express network boundaries in structured JSON. The policy engine evaluates decisions in real time, auto-prioritized: Deny rules first, then Allow, then the global default.

3

Enforce at the Gate

Enterprise Gate agents on managers execute enforcement (nftables on Linux, sandboxed rootless Gate CLI on macOS) using policy bundles signed by Core.

4

Observe & iterate

PacketSpear Command (Overwatch, Scope, Watch surfaces) gives operators full visibility into flows, telemetry, alerts, and audit trails — all in a single interface.

Visibility only

Free tier shows every connection, process, and TLS fingerprint with zero cost. Unlimited devices, free forever.

Fully enforced

Pro tier unlocks full L3/L4/L7 enforcement with JIT access, eBPF deep probes, and L7 TLS fingerprinting.

Command UI

One plane. Every endpoint.

PacketSpear Command gives operators one place to define boundaries, observe flows, enforce policy, and validate rollout across endpoints, workloads, gateways, and relays. Overwatch, Scope, and Watch provide observability, exploration, and live operational pulse.

Deployment & Control

Self-hosted. Always yours.

PacketSpear runs on your hardware, in your network. No cloud dependency, no data exfiltration. You own the CA, the keys, the flows, and the audit trail.

PacketSpear Core

Policy and API server. Single binary with embedded static dashboard, OpenAPI spec, and systemd/launchd service files.

  • REST API + HMAC webhook signing
  • Ed25519-signed policy bundles
  • PostgreSQL persistence
  • mTLS for Node connectivity

PacketSpear Node

Endpoint agent that carries the boundary. Ships with the standard installer on macOS and Linux.

  • mTLS-encrypted to Core
  • eBPF process probe on Linux
  • Visibility-only on macOS (no breakage)
  • Prometheus /metrics exposed

PacketSpear Gate

Enterprise enforcement agent running on network managers (Linux).

  • nftables enforcement on Linux
  • Node-supplied rules, Core-verifiable
  • Dry-run and apply workflows
  • CLI: gate apply, gate clear

PacketSpear Relay

Background worker for remote access paths and JIT grants.

  • JIT firewall grants with TTL expiry
  • Multi-factor auth: TOTP, Duo, OIDC, RADIUS
  • Wildcard relay enforcement
  • Alarm relay & shared identity management

Security & Provenance

Built for serious operators.

Every security decision in PacketSpear is signed, verifiable, and auditable.

mTLS everywhere

All inter-component communication is mutual TLS with a self-managed internal CA. Certificate chains and identity binding enforce true peer confidence.

Ed25519 signatures

Policy bundles and license entitlements are cryptographically signed by Core. Nodes verify every bundle before applying enforcement rules.

Self-hosted by design

No cloud dependency. All telemetry stays on your infrastructure. Phone-home is opt-in and limited to install ID, version, and device count only.

HMAC webhook verification

All webhook payloads include HMAC-SHA256 signatures for integrity verification. Scope per-policy, per-device, or per-account.

Audit & provenance

Prometheus metrics ship with the standard installer. Grafana dashboards and AlertManager rules are included out of the box. Policy bundles are versioned, signed, and tracked.

Zero-brick invariant

Visibility is never disabled by licensing logic. Grace periods degrade to visibility_only mode only — never to full deny, preserving baseline monitoring.

Pricing

Start free. Enforce when ready.

Free visibility forever. Add enforcement, JIT, and enterprise features as your needs grow.

Free

$0 /month
Unlimited devices
Full TCP/UDP/Process visibility
TLS fingerprinting
Command dashboard with Overwatch
Prometheus /metrics
Community support
Start free

Enterprise

Custom
Everything in Pro
MSSP multi-tenancy
SOC 2 readiness
Dedicated support + SLA
Custom integrations
On-prem / air-gapped deploy
Contact sales

Ready to pierce lateral movement?

Download PacketSpear, deploy Nodes across your fleet, and start building policy-as-code today.

Get started free View on GitHub Download white paper