Own your network.
Own your traffic.
qnigma is a small hardware VPN device for private, self-hosted networking. Open firmware. Bring your own keys. No phone-home.
Plug it in. Done.
One Ethernet cable, one USB-C for power. The device boots into its provisioning mode with your keys already burned in before shipping.
- No cloud account required
- Local web UI on first boot
- Pre-provisioned per order
Hardware root of trust.
A dedicated secure element holds identity and session keys. The boot chain is measured and signed. Tamper-evident enclosure.
- Secure element for key storage
- Measured, signed boot
- No shared or factory-default secrets
Your keys. Your network.
Open protocols, flat configuration, no proprietary lock-in. Rotate keys, add peers, manage routes from the local UI or a plain config file.
WireGuard
Modern, minimal, auditable. Handshakes in microseconds, keys under 50 bytes.
IPsec / IKEv2
Broad compatibility with existing infrastructure. Site-to-site, road warrior, split tunnels.
Shell-scriptable
Plain text config, SSH access. Export and re-import anywhere. No vendor database holding your state.
Open. Reproducible.
Firmware source lives on git.qnig.ma. Builds are reproducible — verify the binary on your device matches the source commit.
- Fully open source firmware
- Reproducible build pipeline
- Signed, verifiable updates
In stock. Ready to ship.
Boards are assembled, provisioned, and waiting. Online ordering opens soon — reach out directly in the meantime.