Specific permissions
Together, we define which group can reach which destination on which ports. Allowed and blocked access are tested and documented.
Reach your project portal, files and internal tools. At the office, at home or on the move. We set up a private access network and give your team access to the applications it needs.
Calculate setup costsTogether, we define which group can reach which destination on which ports. Allowed and blocked access are tested and documented.
Connect private devices directly or reach existing networks through a router. Regular internet traffic can still take a direct route. For SaaS domains, we assess a suitable Tailscale app connector separately.
You receive the configuration, an operations handbook and an introduction. With Headscale, you also control the coordination server. Ongoing support can be agreed separately.
Up to five people and ten devices. Three entries are included; every additional entry is configured and tested individually.
An entry is an application at one destination address with up to three TCP/UDP ports, or an explicitly agreed network route, each with one access group. Additional destination addresses or different access groups count separately. Permitted ports remain limited for network routes too.
One site, a suitable existing Linux environment and supported clients. No device management, site migration or 24/7 on-call cover. Additional people, devices and sites require a proposal. Runtime environment, domain, internet connection and ongoing maintenance are separate. Setup does not replace a web filter, DLP or the full Zscaler security platform. An entry is an application at one destination address with up to three TCP/UDP ports, or an explicitly agreed network route, each with one access group. Additional destination addresses or different access groups count separately. Permitted ports remain limited for network routes too. Headscale has no software licence fee; self-hosting requires a named operator. Private IP/subnet routes; dynamic SaaS domain connectors are not included in this package. Headscale does not replicate every feature of the Tailscale service.
If you need private access to a few business applications, a focused access network may be a good fit. Before replacing a service, we check which features you actually use today.
This solution does not replace the entire Zscaler platform. Routing alone does not block public SaaS access: the application must support suitable access restrictions. We calculate any savings from your existing licences, new infrastructure and support needs.
Understand failure points and redundancyTailscale explicitly describes Personal as non-commercial. A business plan is agreed directly with the provider. Headscale uses the BSD-3-Clause licence and has a narrower feature set. We check client, authentication and version compatibility before setup.
Technical information as of 9 October 2026. Provider products and terms may change. NeuroFunken offers an independent setup service; this does not imply a provider partnership.