Privacy Ratings

Open-source mesh VPNs and private networks

7 mesh VPNs and private networks whose code is public under an OSI-approved license, rated for privacy with evidence. Picks first, then by score.

  1. Headscale Grade B Our pick

    Self-hosted, open-source implementation of the Tailscale coordination server, letting official Tailscale clients join a private network without using Tailscale's hosted service.

    BSD-3-Clause. Source code

  2. innernet Grade B

    Open-source private network system built on WireGuard, with a self-hosted server that manages peers, CIDR-based groups and access rules.

    MIT. Source code

  3. tinc Grade B

    Long-running open-source VPN daemon that builds an encrypted mesh between nodes, sending traffic directly to its destination where possible, with no central server.

    GPL-2.0 or later. Source code

  4. ionscale Grade B

    Open-source, self-hosted Tailscale control server with support for multiple tailnets, OIDC login, ACLs and DNS, used with the official Tailscale clients.

    BSD-3-Clause. Source code

  5. Nebula Grade C

    Overlay networking tool originally built at Slack that connects hosts over mutually authenticated, encrypted tunnels using its own certificate authority and firewall rules, with self-hosted lighthouse nodes for discovery.

    MIT. Source code

  6. NetBird Grade C

    WireGuard-based mesh VPN and zero-trust access platform with open-source clients and a management server that can be self-hosted or used as NetBird's hosted service.

    BSD-3-Clause for the clients and AGPL-3.0 for the management, signal and relay servers. Source code

  7. OpenZiti Grade D

    Open-source zero-trust networking platform from NetFoundry that connects apps and devices through an overlay of self-hosted routers and a controller, with tunneler apps and SDKs.

    Apache-2.0. Source code

Compare all 17 mesh VPNs and private networks, open source or not.