← Offers & operationsPRIVATE BUSINESS ACCESS

Your office is
wherever you are.

Reach your project portal, files and internal tools. At the office, at home or on the move. We set up a private access network and give your team access to the applications it needs.

Calculate setup costs
Your teamOffice · Home · On the move
Sign-in & permissionsOnly agreed destinations and ports
Project portal Files Administration · blocked
An example role. Each group receives its own access matrix.

Specific permissions

Together, we define which group can reach which destination on which ports. Allowed and blocked access are tested and documented.

The right route for each destination

Connect private devices directly or reach existing networks through a router. Regular internet traffic can still take a direct route. For SaaS domains, we assess a suitable Tailscale app connector separately.

Ready for your own operations

You receive the configuration, an operations handbook and an introduction. With Headscale, you also control the coordination server. Ongoing support can be agreed separately.

YOUR ACCESS · YOUR SCOPE

Start small.
Expand with purpose.

Up to five people and ten devices. Three entries are included; every additional entry is configured and tested individually.

1. Who operates the coordination server?

An entry is an application at one destination address with up to three TCP/UDP ports, or an explicitly agreed network route, each with one access group. Additional destination addresses or different access groups count separately. Permitted ports remain limited for network routes too.

Included in Business access with Headscale

  • One business network, up to 5 people, 10 devices and 3 application entries
  • Connect an existing OIDC sign-in service or set up an agreed registration process
  • One Linux access router, DNS and role-based permissions following a documented access matrix
  • Positive and negative permission tests, revocation of a test account and documented acceptance
  • Operations handbook, configuration, rollback plan and a 60-minute remote introduction
  • One Headscale instance with TLS, a backup concept and tested recovery on provided infrastructure
Requirements and service limits

One site, a suitable existing Linux environment and supported clients. No device management, site migration or 24/7 on-call cover. Additional people, devices and sites require a proposal. Runtime environment, domain, internet connection and ongoing maintenance are separate. Setup does not replace a web filter, DLP or the full Zscaler security platform. An entry is an application at one destination address with up to three TCP/UDP ports, or an explicitly agreed network route, each with one access group. Additional destination addresses or different access groups count separately. Permitted ports remain limited for network routes too. Headscale has no software licence fee; self-hosting requires a named operator. Private IP/subnet routes; dynamic SaaS domain connectors are not included in this package. Headscale does not replicate every feature of the Tailscale service.

A ZSCALER ALTERNATIVE FOR A SPECIFIC NEED

What security does
your daily work need?

If you need private access to a few business applications, a focused access network may be a good fit. Before replacing a service, we check which features you actually use today.

What we cover

  • Encrypted connections to private applications
  • Permissions by group, destination and port
  • Set up, revoke and hand over access with clear records
  • Optional: a second subnet router with tested failover behaviour

Assess separately

  • Web filtering, content inspection and data loss prevention
  • Browser isolation, device controls and comprehensive SIEM
  • Multiple sites, specific evidence requirements and SLAs
  • Domain-based SaaS routing, shared IP addresses and access from outside the network

This solution does not replace the entire Zscaler platform. Routing alone does not block public SaaS access: the application must support suitable access restrictions. We calculate any savings from your existing licences, new infrastructure and support needs.

Understand failure points and redundancy

Transparent technology and costs

Tailscale explicitly describes Personal as non-commercial. A business plan is agreed directly with the provider. Headscale uses the BSD-3-Clause licence and has a narrower feature set. We check client, authentication and version compatibility before setup.

Technical information as of 9 October 2026. Provider products and terms may change. NeuroFunken offers an independent setup service; this does not imply a provider partnership.

A good place to start.

neurofunken knowledge assistant

Hello! What would you like to improve? I can explain our services and help you find a useful next step.

Replies from our editorial knowledge base.

Please do not enter confidential information. Privacy