The next-generation VPN, sovereign by design.
TxHub is a sovereign mesh VPN, operated for you in fully isolated regions. Connect every device with the TxHub app over WireGuard, and keep the entire control plane — keys, policy, and identity — held in-region on your behalf.
- ::WireGuard peer-to-peer
- ::Native apps
- ::Configurable SSO
- ::Sovereign by design
Two sovereign instances. Zero shared dependencies.
TxHub runs as independently-operated instances, each fully self-contained. Your network lives entirely within one jurisdiction — its control plane, keys, and identity never cross a border.
Completely isolated to Iceland
Runs on bare-metal in an Icelandic datacenter, operated by TxHub. No cloud services, no SaaS, no third-party control planes. Data and control never leave the country.
- Infrastructure
- Bare-metal, Icelandic datacenter
- External dependencies
- None
- Data & control plane
- Never leaves Iceland
- Operated by
- Independent Icelandic instance
US data residency on AWS
A separate, independently-operated instance running in AWS US-East (Virginia) — for US customers and data-residency requirements, isolated from every other region.
- Infrastructure
- AWS US-East (Virginia)
- Data residency
- United States
- Control plane
- Isolated per region
- Operated by
- Separate US instance
No cross-region replication. No shared control plane. Sovereignty is the architecture, not a setting.
Everything a modern mesh needs — and nothing it doesn't.
A complete control plane built on proven primitives, with the operational surface trimmed to what matters.
WireGuard mesh
Encrypted peer-to-peer tunnels between every device, coordinated automatically. No hub to bottleneck your traffic.
Private TxNets
Carve isolated networks — each with its own devices, users, and policy — from a single control plane.
Native apps
First-party TxHub apps for Windows, macOS and Linux. Install, sign in, and you are on your network — no configuration.
ACL policy control
Declarative rules decide exactly who reaches what. Fail-closed by default — access is granted, never assumed.
Device & user management
Approve devices, manage users, and see your entire fleet at a glance from one dashboard.
MagicDNS
Reach every machine by name. Automatic, private DNS resolves across your whole TxNet.
DERP relay
In-region relays keep peers connected through strict NATs and firewalls — with no public cloud in the path (Iceland).
OIDC sign-in
Authenticate with your identity provider. Microsoft Entra ID supported out of the box.
Sovereign by design
TxHub runs the entire control plane in-region — Iceland or US. Nothing phones home, nothing leaves your jurisdiction.
Install the app. We run the sovereign control plane.
The TxHub app connects to a control plane we operate in your chosen region. Nothing to deploy, nothing to self-host.
- 01
Choose your sovereign region
Pick where your network lives — fully isolated Iceland or AWS US-East (Virginia). TxHub operates the control plane there for you; nothing to deploy.
- 02
Install the TxHub client
Install the TxHub app on Windows, macOS or Linux and sign in. One command on servers — the app already knows where your region is.
- 03
Your private mesh is live
Devices authenticate via OIDC, exchange WireGuard keys, and form an encrypted peer-to-peer mesh — keys, policy, and identity all held in-region by TxHub, managed from the dashboard.
Sovereignty isn't a setting you toggle. It's where the keys live, where the policy runs, and where your data stays — held in-region, on your behalf.
Sovereign networking, operated for you.
Pick your region, connect your first devices, and see the mesh form in minutes.
Prefer to talk first? info@txhub.is