Peer-to-peer first
Client and home devices use WireGuard and NAT traversal to establish a direct peer-to-peer path when network conditions allow it. WireGuard private keys are generated on the devices and are not transmitted to HomeTunnel.
Relay fallback
CGNAT, restrictive firewalls, or other network conditions can block a direct path. In that case, packets can be forwarded through the open-source NetBird relay. The traffic remains end-to-end WireGuard-encrypted, and the relay cannot decrypt it.
Per-home isolation
The Portal creates separate NetBird groups, policies, routes, and route distribution for each home and owner. No cross-home routes or shared paths are provisioned, and homes with identical LAN ranges can coexist.