Turn hostile traffic into controlled paths.
PacketSpear delivers precision defense for every packet path. Self-hosted microsegmentation with visibility, enforcement, and policy-as-code — from mobile to server.
PacketSpear delivers precision defense for every packet path. Self-hosted microsegmentation with visibility, enforcement, and policy-as-code — from mobile to server.
How it works
PacketSpear Node agents carry the user-space enforcement boundary with every process. Enterprise Gate agents (managers) spin up the network intent model and apply enforcement at the wire.
Ship the Node agent to each endpoint with the standard installer. Nodes use mTLS to authenticate to PacketSpear Core and begin exposing rich flow telemetry and process context.
Express network boundaries in structured JSON. The policy engine evaluates decisions in real time, auto-prioritized: Deny rules first, then Allow, then the global default.
Enterprise Gate agents on managers execute enforcement (nftables on Linux, sandboxed rootless Gate CLI on macOS) using policy bundles signed by Core.
PacketSpear Command (Overwatch, Scope, Watch surfaces) gives operators full visibility into flows, telemetry, alerts, and audit trails — all in a single interface.
Free tier shows every connection, process, and TLS fingerprint with zero cost. Unlimited devices, free forever.
Pro tier unlocks full L3/L4/L7 enforcement with JIT access, eBPF deep probes, and L7 TLS fingerprinting.
Command UI
PacketSpear Command gives operators one place to define boundaries, observe flows, enforce policy, and validate rollout across endpoints, workloads, gateways, and relays. Overwatch, Scope, and Watch provide observability, exploration, and live operational pulse.
Deployment & Control
PacketSpear runs on your hardware, in your network. No cloud dependency, no data exfiltration. You own the CA, the keys, the flows, and the audit trail.
Policy and API server. Single binary with embedded static dashboard, OpenAPI spec, and systemd/launchd service files.
Endpoint agent that carries the boundary. Ships with the standard installer on macOS and Linux.
Enterprise enforcement agent running on network managers (Linux).
Background worker for remote access paths and JIT grants.
Security & Provenance
Every security decision in PacketSpear is signed, verifiable, and auditable.
All inter-component communication is mutual TLS with a self-managed internal CA. Certificate chains and identity binding enforce true peer confidence.
Policy bundles and license entitlements are cryptographically signed by Core. Nodes verify every bundle before applying enforcement rules.
No cloud dependency. All telemetry stays on your infrastructure. Phone-home is opt-in and limited to install ID, version, and device count only.
All webhook payloads include HMAC-SHA256 signatures for integrity verification. Scope per-policy, per-device, or per-account.
Prometheus metrics ship with the standard installer. Grafana dashboards and AlertManager rules are included out of the box. Policy bundles are versioned, signed, and tracked.
Visibility is never disabled by licensing logic. Grace periods degrade to visibility_only mode only — never to full deny, preserving baseline monitoring.
Pricing
Free visibility forever. Add enforcement, JIT, and enterprise features as your needs grow.
Download PacketSpear, deploy Nodes across your fleet, and start building policy-as-code today.