Peer-to-peer first

Client and home devices use WireGuard and NAT traversal to establish a direct peer-to-peer path when network conditions allow it. WireGuard private keys are generated on the devices and are not transmitted to HomeTunnel™.

Relay fallback

CGNAT, restrictive firewalls, or other network conditions can block a direct path. In that case, packets can be forwarded through the open-source NetBird relay. The traffic remains end-to-end WireGuard-encrypted, and the relay cannot decrypt it.

Per-home isolation

The Portal creates separate NetBird groups, policies, routes, and route distribution for each home and owner. No cross-home routes or shared paths are provisioned, and homes with identical LAN ranges can coexist.