netwatch.sh Join the waitlist

In private build. The installer goes live soon.

Install NetWatch with: curl -fsSLhttps://netwatch.sh| sh

Put any device online, reachable from anywhere, without opening a single port.

NetWatch is a small agent and a secure cloud relay. Install it on a Raspberry Pi, a rack controller or hardware you build yourself, then reach it from your browser, your terminal or your own app.

Join the waitlist

How a device gets from your bench to your browser

The device only ever dials out. Nothing listens on your network, so there is no router setup, no dynamic DNS and no VPN to maintain.

  1. Install the agentOne command fetches a signed binary for your platform and creates a key that never leaves the device.
  2. Connect over secure MQTTThe device holds a single outbound connection on port 443, authenticated with its own certificate.
  3. Start a session on demandWhen you ask for access, a short-lived microVM brokers it. When you leave, it stops, so idle devices cost nothing.
  4. Serve it at the edgeTraffic reaches you through a global CDN with HTTPS on every address.
  5. Use it from anywhereOpen the device's web page, a shell or your own app, with access limited to the people you choose.

A handful of commands you'll actually remember

Like a package manager for reachability: install once, then everything is one verb away.

netwatch login
Link this device to your account with a short code.
netwatch status
Check the connection, region and latency at a glance.
netwatch expose 8080
Give a local port a private HTTPS address.
netwatch ssh lounge-pi
Open a shell on another device, with no port forwarding.
netwatch exec lounge-pi -- uptime
Run one command remotely and get the output back.
netwatch update
Update the agent in place from a signed release.

Cloud access built into the products you make

Embed the agent in your firmware and your customers get remote access out of the box. You skip building and running the cloud side yourself.

  • Your brand on every addressDevices appear under your own domain, so customers see your product, not ours.
  • Identity from the factoryProvision each unit's certificate at manufacture, tied to its serial number.
  • Works on customer networks as they areOutbound 443 only, so installs don't need IT to open ports or change firewall rules.
  • Pay for sessions, not idle unitsA unit sitting in a cupboard for a year costs next to nothing to keep connected.
#include <netwatch.h>

nw_config cfg = nw_default_config();
cfg.product_id = "acme-amp-x200";
cfg.serial     = read_serial();

nw_client *nw = nw_start(&cfg);

// Your device's web UI, reachable from your app
nw_expose(nw, 80, "web-ui");

// Commands your cloud can send to the unit
nw_on_command(nw, "reboot", handle_reboot);

Preview of the planned SDK and API. Names may change before launch.

Secure by how it's built, not by settings you have to find

Remote access is only useful if you can trust it. These are defaults, not upgrades.

No open ports

Devices connect out. There is nothing on your network for a scanner to find.

A key per device

Each device has its own certificate, so revoking one never touches the rest.

Private unless you say so

Every address requires sign-in by default. Making one public is a deliberate flag.

Short-lived sessions

Access is brokered per session and expires on its own, rather than living forever.

Signed releases

The installer and every update are verified before they run.

Encrypted end to end in transit

TLS on the device link and at the edge, with modern ciphers only.

Be first to run the installer

We're opening access in small batches. Leave your email and we'll send your invite when your batch is ready.

We only use your email to send your invite and launch news. Reply to any email to be removed.