Direct when it can be
TonD attempts an authenticated peer-to-peer path before it asks a relay to carry the session.
Secure access infrastructure
TonD creates on-demand, authenticated paths to remote systems for example SSH, RDP, WinRM, and your own approved services.
Remote access should be deliberate, visible, and temporary. TonD gives teams a practical route from operator to endpoint without turning every machine into a public-facing service.
The platform
TonD attempts an authenticated peer-to-peer path before it asks a relay to carry the session.
When networks cannot connect directly, a dedicated SSH relay keeps access available without changing how operators work.
Access SSH, RDP, WinRM, HTTP, HTTPS, and approved custom ports through a local endpoint.
Security by design
Devices are registered to an organization, prove possession of their key, and receive only the access path required for the requested session.
Discuss your security modelKnown device identity and nonce signatures before a session is accepted.
Fresh session credentials and automatic relay process expiry.
No remote shell, exec, or PTY access through the relay layer.
Clients, endpoints, and customer relay nodes stay within their organization.
Your network, your relay
Run a customer SSH node in your environment. TonD uses it only when a direct connection is unavailable, with central relay fallback when it is offline.
In environment where P2P connections are not allowed or problemmatic the customer has the option to run their on SSH node relay service.
PUBLIC_HOST=relay.example.com
RELAY_PORT_START=1337
RELAY_PORT_END=2337
MAX_SESSIONS=10
./ssh-node
Compare TonD
See how TonD's direct-first, temporary access model differs from leading access, support, and zero-trust networking platforms.
Start a conversation
Tell us about your remote estate, access requirements, and operational constraints.
Talk to TonD