In private build. The installer goes live soon.
Install NetWatch with: curl -fsSLhttps://netwatch.sh| sh
Put any device online, reachable from anywhere, without opening a single port.
NetWatch is a small agent and a secure cloud relay. Install it on a Raspberry Pi, a rack controller or hardware you build yourself, then reach it from your browser, your terminal or your own app.
How a device gets from your bench to your browser
The device only ever dials out. Nothing listens on your network, so there is no router setup, no dynamic DNS and no VPN to maintain.
- Install the agentOne command fetches a signed binary for your platform and creates a key that never leaves the device.
- Connect over secure MQTTThe device holds a single outbound connection on port 443, authenticated with its own certificate.
- Start a session on demandWhen you ask for access, a short-lived microVM brokers it. When you leave, it stops, so idle devices cost nothing.
- Serve it at the edgeTraffic reaches you through a global CDN with HTTPS on every address.
- Use it from anywhereOpen the device's web page, a shell or your own app, with access limited to the people you choose.
A handful of commands you'll actually remember
Like a package manager for reachability: install once, then everything is one verb away.
- netwatch login
- Link this device to your account with a short code.
- netwatch status
- Check the connection, region and latency at a glance.
- netwatch expose 8080
- Give a local port a private HTTPS address.
- netwatch ssh lounge-pi
- Open a shell on another device, with no port forwarding.
- netwatch exec lounge-pi -- uptime
- Run one command remotely and get the output back.
- netwatch update
- Update the agent in place from a signed release.
Secure by how it's built, not by settings you have to find
Remote access is only useful if you can trust it. These are defaults, not upgrades.
No open ports
Devices connect out. There is nothing on your network for a scanner to find.
A key per device
Each device has its own certificate, so revoking one never touches the rest.
Private unless you say so
Every address requires sign-in by default. Making one public is a deliberate flag.
Short-lived sessions
Access is brokered per session and expires on its own, rather than living forever.
Signed releases
The installer and every update are verified before they run.
Encrypted end to end in transit
TLS on the device link and at the edge, with modern ciphers only.
Be first to run the installer
We're opening access in small batches. Leave your email and we'll send your invite when your batch is ready.