Private, zero-trust AI you can build, verify, and own.
The protections Zscaler and Microsoft charge for — as an open package on your own hardware. See why it makes sense, pick your setup, and build it yourself. Four steps, one page.
1
Why not just buy the vendors?
Same protections — theirs is rented, yours is owned
Security layer
Zscaler / Microsoft
Your open version
Identity per agent/device
VendorsEntra Agent ID / ZPA
YouZiti identity (mTLS)
Hidden from the internet
VendorsPrivate endpoints / connectors
YouDark services — no open ports
Least privilege
VendorsConditional Access policies
YouZiti service policies
Where traffic goes
VendorsThrough their cloud
YouStraight to your machine
Cost & lock-in
VendorsPer-seat licensing, contracts
YouFree & open — you own it
2
The package & what you pay for
Free to build · pay only to keep it improving
Build it yourself
Free
Fully documented and reproducible. Follow the guide, own it.
Keep it current
Subscription
We keep it improving — new models, patches, hardening. The only thing you pay for.
Want it hosted?
Managed
Prefer not to run it? We set you up on managed Ziti — no infra.
3
Pick your build
Every option runs privately on your hardware
4
Build it & prove it
Don't take our word — verify it yourself
One command sets it all up:
./make-it-work.sh
Or follow the step-by-step guide to build each piece by hand and confirm it works exactly as advertised. Reproducible is trustworthy — which is the one thing the big vendors won't let you do.