Access only what you need
No standing access. Every connection is checked and approved individually — nobody gets broad network access just for being 'inside.'
Tobogganing gives staff and contractors safe access to exactly the systems they need and nothing else, replaces separate VPN, firewall, and security-monitoring tools with one open source platform you can actually run, and keeps a clear record of who reached what and when. Built on WireGuard, with DNS security merging in next.
No standing access. Every connection is checked and approved individually — nobody gets broad network access just for being 'inside.'
Access requires both a trusted device and a verified identity, not just a password anyone could type in.
Suspicious traffic is automatically inspected and blocked as part of the platform — no separate security appliances to buy, install, and maintain.
The same access and security rules apply whether your team is on a laptop, in the office, or running inside Kubernetes.
Simple native apps for Mac, Windows, Linux, and mobile — connecting takes one click, not a support ticket.
Built-in monitoring shows how your network is really performing for the people using it, and Squawk DNS security is merging in next.
Tobogganing is licensed under AGPL-3.0 for personal and internal use; commercial use requires a commercial license from Penguin Technologies Inc. Companies employing an official contributor receive a perpetual GPL-2.0 grant to community features for the versions that contributor worked on.
The Community tier has no artificial limits on clients or headends — WireGuard VPN connectivity, basic firewall rules, and certificate management are free and open source from day one.
Current release: v1.2.0. Core API: Python (async, Quart, penguin-dal). Headend: Go, WireGuard. Portal: React 18 + TypeScript (Vite 5), TailwindCSS 4.