One Dedicated Node Per VPN
Each VPN you deploy gets its own dedicated VPN node and its own static IP address. Dev traffic never touches the Accounting node - they are completely separate at the infrastructure level.
PrivyNet lets your organisation deploy a separate dedicated VPN for each team - Engineering, DevOps, Finance, HR, Contractors, and more. Every VPN runs on its own node with its own static IP address. Teams are completely isolated from one another at the infrastructure level. Users keep the same credentials across every VPN they have access to - switching teams is as simple as selecting a different profile on their device.
Each team gets a fully isolated dedicated VPN - managed together from a single admin view
Each VPN you deploy gets its own dedicated VPN node and its own static IP address. Dev traffic never touches the Accounting node - they are completely separate at the infrastructure level.
Every VPN your organisation deploys is visible and controllable from a single admin dashboard. Provision a new team VPN, manage users, or revoke access - all in one place.
Users keep the same credentials across every VPN they have access to. The only difference between profiles on their device is the DNS endpoint - switching teams is as simple as selecting a different VPN profile.
You decide which users have access to which VPNs. A developer can be on the Dev and DevOps VPNs simultaneously. An accountant has no access to either - only the Finance VPN.
Each department gets its own isolated node, its own static IP, and access scoped to exactly what that team needs
Developers connect through the Engineering VPN - accessing source control, internal APIs, staging environments, and cloud infrastructure. No other team can reach these resources.
The DevOps VPN provides access to deployment pipelines, monitoring systems, and production infrastructure. Isolated from development to enforce a clean separation of environments.
Finance teams connect through their own VPN with its own static IP - whitelisted in accounting platforms, payroll systems, and financial data sources. No other team shares this IP.
Support staff access CRM systems, helpdesk tools, and customer data through a dedicated VPN. Their traffic and access are fully isolated from engineering and finance.
HR data is highly sensitive. A dedicated HR VPN restricts access to HR systems and personal data to only the people who need it - no other team has a path to these resources.
Spin up a dedicated contractor VPN with access scoped to exactly what they need. When the engagement ends, revoke access on that VPN without touching any other team's configuration.
Same credentials everywhere - the only difference between VPN profiles is the DNS endpoint
The admin assigns the user to one or more VPNs from the dashboard. Each VPN the user has access to generates a profile they can configure on their device.
The user sets up a VPN profile for each team they belong to. Credentials are the same for every profile - only the DNS server address (the VPN endpoint) differs between them.
To connect to a different team's network, the user simply selects the relevant VPN profile on their device. No new credentials, no re-authentication - just switch and connect.
A user with access to three VPNs - Engineering, DevOps, and Contractors - has three profiles on their device. Each profile connects to a different isolated node. Credentials are identical across all three. Switching takes seconds.
Segmenting your network by team is one of the most effective ways to contain the impact of a security incident
A user on the Finance VPN cannot route traffic to Engineering infrastructure - not because of a firewall rule, but because they are on an entirely different network node.
Each team VPN has its own static IP. Finance systems can whitelist the Finance VPN IP only. Engineering tools whitelist the Engineering VPN IP only. Clean, precise access control.
Access logs are scoped per VPN. Engineering connection records are kept separate from Finance - clean attribution with no cross-team contamination.
If a credential on one team's VPN is compromised, the attacker can only reach that team's resources. They cannot pivot to another team's node - the infrastructure stops them.
Common questions about deploying multiple VPNs per team with PrivyNet
A tenant can deploy multiple VPNs - one per team, department, or use case. Each VPN gets its own dedicated node and static IP. Contact us to discuss the right configuration for your organisation's size and structure.
No. A user's credentials are the same across every VPN they have been granted access to. The only difference between VPN profiles on their device is the DNS endpoint - the server address that identifies which team's node they are connecting to.
Users configure a VPN profile for each team they have access to on their device. Switching between teams is as simple as selecting a different profile - the same credentials work across all of them.
Yes. An admin can grant a single user access to multiple VPNs. A developer who also does DevOps work can have profiles for both the Engineering VPN and the DevOps VPN, for example.
Each VPN is a physically separate dedicated node with its own network path and its own static IP. It is not a VLAN or a firewall policy applied to shared infrastructure - the teams are on different machines entirely.
Revoke their access to the contractor VPN from the admin dashboard. Their session is terminated immediately and their credential is invalidated for that VPN. Your other team VPNs are completely unaffected.
Deploy a dedicated VPN for each department. Full isolation, one dashboard, and the same simple credentials your users already know.