- Deployment
- Private Cloud · On-Prem · Edge · Hybrid
Overview
Functional · IPsec Overlay Security
The encrypted network fabric protecting internal communication.
HexShield uses HexTrust for keying, HexDNS for naming, HexIdentity for policy, on HexCloud infra.
HexShield protects internal routes, service traffic, machine communication, and site links through an encrypted overlay fabric built for controlled infrastructure.
HexShield gives your ecosystem a controlled overlay fabric for secure internal and site-to-site traffic.
Core capabilities
Overlay networking
Site-to-site connectivity
Device onboarding
Policy-based routing
Zero-trust segmentation
Depends on
Enabled
HexPulse
VYRA
DARSHAN
Secure internal services
The problem
Unprotected Internal Traffic
Private systems still need encrypted service-to-service communication.
Complex Site Links
Secure environments need controlled connectivity between sites and systems.
Weak Network Boundaries
Perimeter control requires encrypted routes and policies.
Communication Without Governance
Traffic needs visibility, identity, and controlled pathways.
Capabilities
IPsec overlay
Encrypted tunnels
Secure routing
Private network fabric
Perimeter control
Site-to-site communication
Machine-to-machine security
Network governance
The system at work
HexIdentity
Policy Layer
Overlay Fabric
Encrypted Tunnels
Secure Routes
Service Communication
Monitoring Hooks
Perimeter Control
Built for
Private networks
On-prem infrastructure
Edge environments
Site-to-site systems
Secure service mesh
Air-gapped deployments
Institutional networks
Enterprise perimeter control
Frequently asked questions
What is HexShield?
HexShield is Hexmon’s encrypted overlay security fabric for private system communication.
What does HexShield secure?
It secures internal routes, service-to-service communication, machine traffic, and site links.
What products does HexShield support?
HexShield supports monitoring, VYRA, DARSHAN, internal applications, and secure service communication.
Hex Shield Architecture
Start / Secure Network Boundary
Define the protected network perimeter for private systems, services, and sites.
HexCloud & HexCluster Foundation
Use private compute and runtime layers as the base for encrypted communication. Connection: HexCloud · HexCluster Private compute foundation and runtime layer where HexShield's protected routes and services operate.
Identity & Policy Context
Attach user, service, role, and policy context before communication is allowed. Connection: HexIdentity Identity, RBAC, roles, and access governance for allowed communication policies.
Trust / Certificate Integration
Bind overlay endpoints to trusted certificates and internal service identity. Connection: HexTrust Certificate authority and TLS lifecycle for trusted overlay endpoints and services.
Private Endpoint Registration
Register machines, services, sites, and workloads into the protected overlay fabric. Connection: HexDNS Private DNS and service discovery for endpoints inside the encrypted overlay fabric.
Overlay Tunnel Establishment
Create encrypted tunnels between approved systems, services, and locations.
Route & Policy Enforcement
Control which services can communicate and how traffic moves inside the fabric.
Encrypted Service-to-Service Traffic
Protect internal API, application, machine, and microservice communication.
Site-to-Site / Edge Link Protection
Secure communication between private sites, edge systems, and restricted networks.
Monitoring, Alerts & Threat Signals
Track tunnel health, traffic patterns, policy events, failures, and security signals. Connection: HexPulse Monitors tunnel health, traffic signals, alerts, logs, failures, and operational visibility.
Ecosystem Secure Communication
Provide trusted encrypted connectivity to Hexmon products and internal platforms. Connection: VYRA · DARSHAN AI intelligence and digital signage services consume protected connectivity for secure workflows.
Rotation, Recovery & Continuity
Maintain tunnels, rotate keys, recover links, and keep secure communication stable. Connection: HexVault Stores configuration backups, policy history, audit evidence, and recovery data securely.