Selective egress for business networks

Selected services.Chosen gateways.

Keep ordinary internet traffic on its normal route. Send only the services that need another region through a gateway you choose — without installing EgressLane software on user devices.

  • No client software on user devices
  • No TLS interception
  • Customer-owned infrastructure

Business release candidate · controlled pilot

A narrow lane, not a full-tunnel detour

PILOT
Ordinary trafficNormal office route
Selected service
01Office Edge
02 · REGIONRegional Gateway
03SaaS destination

DNS policy and virtual addresses identify managed destinations. TLS and QUIC remain end-to-end.

What changes — and what does not

Give a service the right exit without moving the whole office.

EgressLane is software for customer-controlled networks. The Office Edge answers managed DNS names with virtual addresses, then routes those flows over an encrypted overlay to the selected gateway. Everything else stays on the office route.

Endpoint
No EgressLane client, agent or CA certificate
Data path
TCP 80/443 and HTTP/3
Addressing
IPv4 and optional IPv6
Policy
Exact and longest-suffix domain matching

How it works

Four deliberate steps. One selective path.

01

Identify

Office clients use the Edge as DNS, or the existing DNS forwards selected zones to it.

02

Map

A managed name receives a stable virtual address. Unmanaged answers pass through normally.

03

Route

The Edge translates and policy-routes only the matching TCP or UDP flow into the encrypted tunnel.

04

Egress

The chosen gateway applies an allow-list and sends the flow to the public service from its region.

Product surfaces

Built as software, deployed on infrastructure you control.

01

Office Edge

DNS policy, virtual addresses, route health, multi-gateway policy and local operational metadata.

02

Customer Gateway

A regional gateway you deploy and operate on infrastructure you control.

03

Managed Gateway

An optional regional gateway operated by EgressLane, subject to availability.

04

Service Catalog

Maintained domain groups that customers may install. Catalog updates never choose or overwrite a customer route policy.

Deployment choices

Start with your own nodes. Add a managed exit when it helps.

01

Customer-managed

Run Office Edge and regional Gateway on customer-owned Ubuntu virtual machines, IP addresses and bandwidth.

Maximum infrastructure control

Security and privacy

The lane sees routing metadata, not your conversations.

EgressLane does not terminate TLS, install a trusted CA, or inspect encrypted application content. TLS and QUIC remain between the client and the destination service.

Service Catalog

Curated domain knowledge, local policy ownership.

Install a maintained service group, review exact and suffix rules, then decide locally which route policy it uses. Parent and child domains follow most-specific-match precedence, and overlaps are shown before activation.

Policy stays at the customer Edge

Pricing

Pricing follows the capacity you need.

Pricing is based on concurrent managed flows and the number of Gateway connections. Contact us for a proposal tailored to your deployment.

Contact us

Tell us which services need a different lane.

We will review the office network, target regions and deployment ownership before proposing a controlled pilot.

Prefer email? Write tocontact@egresslane.com

Pilot scope

Controlled pilots are engineering-assisted and do not carry a general-availability SLA. Third-party regional access and service availability are not guaranteed. EgressLane Managed Gateway service is not offered for mainland China.