Peer-to-peer first
Client and home devices use WireGuard and NAT traversal to establish a direct peer-to-peer path when network conditions allow it. WireGuard private keys are generated on the devices and are not transmitted to HomeTunnel™.
Relay fallback
CGNAT, restrictive firewalls, or other network conditions can block a direct path. In that case, packets can be forwarded through the open-source NetBird relay. The traffic remains end-to-end WireGuard-encrypted, and the relay cannot decrypt it.
Per-home isolation
The Portal creates separate NetBird groups, policies, routes, and route distribution for each home and owner. No cross-home routes or shared paths are provisioned, and homes with identical LAN ranges can coexist.