v1.0.0-rc2 controlled field release

Private networking should feel invisible.

VeloraMesh is a low-latency private mesh VPN for games, remote desktop, file transfer, and personal devices.

Direct P2P by default. No relay in v1. No public cloud. Simple, fast, and under your control.

Client platforms

Windows / macOS / Linux / Android

Field result

RDP, LAN discovery, and large file transfer validated

Release state

Packaged as RC with checksums and legal files

The problem is not networking; it is access design.

Reach RDP and SSH services through your own private network without exposing those services to the public internet.

Stuck behind CGNAT?

Reach your Raspberry Pi, home server, or office PC over a private mesh when port forwarding is not available.

Avoid public RDP/SSH exposure?

Keep internal services off the public internet and expose them only to authorized VeloraMesh devices.

Need LAN games over the internet?

Classic LAN discovery flows can meet inside one virtual network for low-latency game sessions.

Built to feel like the same LAN

VeloraMesh hides the networking complexity while your devices meet inside one secure virtual LAN.

Gaming LAN discovery

Low-latency virtual LAN behavior for Counter-Strike, FlatOut, and classic LAN games.

Remote desktop

Reach your PC, Mac, and Android devices by private IP for RDP and local services.

Personal infrastructure

Access servers, homelab devices, media boxes, and dev machines from one private network.

Real-world flows

The value is simple: stop caring where the device is and connect to it directly.

Mobile data -> Raspberry Pi

  • Phone
  • CGNAT mobile data
  • VeloraMesh
  • Raspberry Pi
  • SSH

Mac -> Windows RDP

  • MacBook
  • VeloraMesh
  • Windows PC
  • Remote Desktop

LAN games with friends

  • Counter-Strike / FlatOut
  • VeloraMesh
  • LAN discovery
  • Low-latency play

How it works

01

Create a network

The server operator creates the network name and join secret; the control plane manages only the derived public verifier, members, and endpoint freshness.

02

Join devices

Windows, macOS, Linux, or Android clients join once and keep running as a service or VPN.

03

Build a P2P tunnel

Peers talk over encrypted UDP directly; when possible, data traffic never crosses the server.

How it works - VeloraMesh

Secure defaults, simple design

VeloraMesh uses modern cryptography, server-signed membership, and short-lived sessions/tickets to build private mesh access with secure defaults.

TLS 1.3 control plane
Request-proof verification before route or body access
Client-local join secrets with public verifier storage
Ed25519 device identity
X25519 + HKDF-SHA256 peer handshake
Opaque peer-hello and discovery packets
XChaCha20-Poly1305 data-plane AEAD
Replay protection and short-lived membership tickets
DPAPI / Android Keystore / restricted local secret storage

Planned roadmap

Not part of the current RC; planned after the core matures.

Planned iOS client
Planned Native desktop tray/GUI
Planned Exit node / internet gateway
Planned Private DNS / mesh hostname resolution
Planned Optional self-hosted relay
Planned Signed installers and releases
Planned Independent security audit and pentest
Planned 64/100/255 peer field validation

Short answers

Is this a cloud VPN?

No. VeloraMesh v1 runs with your own Ubuntu control plane and is designed for direct P2P data paths.

Is relay supported?

v1 is direct-only. A future relay is planned only as optional self-hosted support for extreme NAT cases.

Is the source code public?

Not yet. Packages are distributed with EULA, privacy, security, and third-party notice files.

Can I reach devices behind CGNAT?

Yes, on networks that permit a direct UDP path. Devices in the same VeloraMesh network can reach RDP, SSH, and HTTP services through virtual IPs. Connectivity depends on NAT and firewall policy; v1 uses direct P2P.

Is business setup support available?

Yes. Pilot networks, Ubuntu API/edge separation, firewall guidance, and client rollout support are available through WhatsApp or email.

What if someone shares a panel password?

If the service is reachable only over VeloraMesh private IPs, access also requires an authorized device and active mesh membership.