Secure remote access without the stack of point products

Tobogganing gives staff and contractors safe access to exactly the systems they need and nothing else, replaces separate VPN, firewall, and security-monitoring tools with one open source platform you can actually run, and keeps a clear record of who reached what and when. Built on WireGuard, with DNS security merging in next.

Highlights

Enterprise-grade routing and traffic visibility

VRF segmentation and OSPF dynamic routing keep large, multi-region networks organized, while mirrored traffic feeds Suricata, Zeek, and Arkime for deep packet inspection — all configured from the same web portal as everything else.

Prove it's really you — and your device

Access requires both a trusted device and a verified identity, not just a password anyone could type in.

Built-in threat protection

Suspicious traffic is automatically inspected and blocked as part of the platform — no separate security appliances to buy, install, and maintain.

One network across cloud and on-prem

Headends register as clusters labeled by region and datacenter, so the same WireGuard overlay and access rules cover a public cloud region, your own datacenter, and Kubernetes pods — all under one policy, not a separate setup per environment.

Works wherever your team works

Simple native apps for Mac, Windows, Linux, and mobile — connecting takes one click, not a support ticket.

See performance, secure your DNS

Built-in monitoring shows how your network is really performing for the people using it, and Squawk DNS security is merging in next.

Built for real deployments

Tobogganing is licensed under AGPL-3.0 for personal and internal use; commercial use requires a commercial license from Penguin Technologies Inc. Companies employing an official contributor receive a perpetual GPL-2.0 grant to community features for the versions that contributor worked on.

The Community tier has no artificial limits on clients or headends — WireGuard VPN connectivity, basic firewall rules, and certificate management are free and open source from day one.

Current release: v1.2.0. Core API: Python (async, Quart, penguin-dal). Headend: Go, WireGuard. Portal: React 18 + TypeScript (Vite 5), TailwindCSS 4.

v1.2.0Current release
AGPL-3.0Open source license
3License tiers

See it in action