Keser Security Operations

Not a VPN.
Infrastructure.

KeserNet is zero-trust mesh networking, continuous traffic monitoring, behavioral analytics, and fail-closed egress. Fully managed, continuously watched, available at any scale.


The Difference

Consumer VPN vs. KeserNet

Capability Consumer VPN KeserNet
Client required on every device ✓ (always) ✗ (remote access only — LAN devices covered via entry node)
Works on unmanageable devices
IoT, game consoles, employer-managed
✓ (entry node covers entire LAN segment)
Traffic encryption
Egress location control ✓ (shared pools) ✓ (dedicated, per-account)
Fail-closed on disconnect ✗ (usually) ✓ (enforced at kernel level)
DNS-level protection Varies ✓ (configurable blocklists)
Traffic monitoring ✓ (Zeek on all egress)
Beacon / C2 detection ✓ (RITA behavioral analytics)
Monthly threat report
LAN enforcement (all devices) ✓ (hardware entry node)
Dual-ISP failover ✓ (hardware node)
Automated cloud failover ✓ (AWS EC2 standby)

Architecture

Entry nodes. Exit nodes.
Two distinct roles.

KeserNet separates the on-premises network component from the internet egress point. This lets you mix and match configurations to match your security requirements and budget.

▣ Entry Node

LAN side: your premises

The entry node sits on your local network and routes LAN traffic into the KeserNet mesh. Think of it as the on-ramp. Your ISP connections are your responsibility; Keser manages the node configuration and monitoring.

  • Routes all connected devices; no per-device client required
  • Dual WAN uplink support for ISP redundancy
  • On-site Zeek sensor for local traffic visibility
  • Ansible-managed; remote update capability
  • Compact x86 mini PC (Ryzen 7+); can use customer hardware

Hardware add-on: $350 one-time setup + $50/mo management (included in Business tier and above)

▣ Exit Node

Internet side: your choice

The exit node is where your traffic leaves the KeserNet mesh and reaches the internet. It determines your effective egress location and IP. Four options:

KeserNet Physical PoP

Dedicated managed node at a Keser facility. NorCal · Pachuca MX · St. Louis MO. Spain PoP planned Q1–Q2 2027.

Client-Hosted

Runs on your existing infrastructure. Keser manages config and monitoring. KeserNet PoP available as automatic failover standby.

AWS: Your Account

Deployed in your AWS account. Full data sovereignty. Any AWS region globally.

AWS: KeserNet-Hosted

Turnkey. No AWS account required. Any region globally. Also serves as automated failover target for hardware entry nodes.


What We Watch

Continuous monitoring.
Not a dashboard you check.

Most "monitored" products give you a dashboard. We give you a practitioner actively reviewing what the platform sees and telling you when something matters.

▣ Traffic Analysis

Zeek

Protocol analysis and logging on all egress traffic. Every connection logged, every protocol decoded, every anomaly surfaced for review.

▣ Behavioral Analytics

RITA + ClickHouse

Beacon detection and C2 identification. Long-connection analysis, periodic callback patterns, and suspicious traffic profiling. The signals most tools miss.

▣ Runtime Security

Falco

Host-level anomaly detection on KeserNet infrastructure. Syscall monitoring, unexpected process execution, privilege escalation. Caught before it propagates.

▣ DNS Protection

Resolver-level filtering

Malicious domains blocked before they resolve. Custom blocklists available on Team tier and above. No malware download starts if the domain never resolves.

▣ Monthly Reports

Human-readable threat summaries

What we saw, what we flagged, what it means. Every monthly report has an executive summary and a technical appendix. You get both.

▣ Real-Time Alerting

Email on high-confidence detections

High-confidence detections trigger immediate email notification. You're not waiting for the monthly report to find out something happened.


Who It's For

KeserNet is built for
specific problems.

Remote workers and travelers

You work from airports, hotels, and co-working spaces. Consumer VPNs give you a different IP. KeserNet gives you monitored infrastructure that fails closed, protects your DNS, and tells you if something on your device is phoning home.

Privacy-conscious professionals

Legal, medical, financial, and journalist clients who handle sensitive matters and need documented, managed infrastructure. Not a promise from a company whose business model depends on your data.

Small businesses

Your office network exits to the internet through a consumer router with no visibility into what's happening. KeserNet Business gives you managed network infrastructure with monitoring. No network engineer required.

International organizations

Multi-site deployments, workers across borders, traffic that needs to appear to originate from specific locations. KeserNet runs in production across two countries today, with PoPs in three locations and AWS exit nodes globally.


Get Connected

Your network.
Our infrastructure.

Individual, team, or business: KeserNet scales to your size. Start with a conversation about your architecture.

Talk to Us See Pricing