Airfy MeshNode
Encrypted by default. Works behind any NAT. No VPN concentrator, no port forwarding. Connect homes, sites, devices, partners — one private network. Multi-tenant for ISPs, hardware option included, open source under the hood.
The Airfy alternative to Tailscale, with the missing pieces — hardware, multi-tenancy, WiFi mesh.

Meshnode in the operator console

Every node, one screen.
Meshnode runs in every site. This is how you see them all, live.
Mesh in production at
What MeshNode does
Tailscale gives you encrypted overlay networking and stops there. MeshNode adds the four things service providers and consumer ISPs needed but never got: hardware, multi-tenancy, WiFi mesh integration, and per-AP pricing.

Connect offices, branches, factories, remote sites. Every node talks directly to every other node. No central VPN concentrator, no single point of failure.

ISP-shipped consumer mesh, three nodes per house, every room covered, seamless roaming. Same MeshNode firmware, packaged for end users.

Works behind carrier-grade NAT, double NAT, restrictive firewalls. No port forwarding, no DDNS, no VPN concentrator to manage.

The differentiator over Tailscale and ZeroTier. ISP-grade tenant hierarchy, audit log, per-customer policy domains. Built into the platform.

Run MeshNode software on many supported router boards. Or buy our Meshnode hardware ready-configured. Tailscale ships software only — we ship both.

WireGuard core, open-source firmware, signed updates you can audit. Self-hostable control plane. Independent of Airfy after delivery.
Same product, three audiences

Ship MeshNode as the consumer router. Whole-home mesh out of the box, federated to your subscriber footprint. Every house becomes a managed site.
See the operator console
Connect every office, factory, warehouse, and remote site through one mesh. Zero-trust by default. Per-site policy. SLA-grade telemetry.
Enterprise platform
Three nodes per house. WiFi 6 mesh, every room covered. One-tap pause, schedules per child, personal passwords. Same firmware, different package.
Family productvs the alternatives
Same WireGuard primitive underneath. Different audience, different packaging. Pick what fits your team.
| Capability | Airfy MeshNode | Tailscale | Raw WireGuard | ZeroTier |
|---|---|---|---|---|
| Encrypted overlay (WireGuard core) | ||||
| NAT traversal without manual config | — | |||
| Multi-tenant ISP-grade hierarchy | — | — | — | |
| Hardware product line, not just software | — | — | — | |
| Whole-home WiFi mesh integration | — | — | — | |
| Self-hostable control plane | Yes (Headscale) | Limited | ||
| Open source | ||||
| EU + US data residency | DIY | |||
| Priced per-AP for partners (not per-node) | — | DIY | — |
The hardware Tailscale doesn't have
Most overlay-network products are software-only. You bring the hardware. We ship both. Pre-paired mesh sets for homes, ceiling-mount APs for offices and hotels, industrial boards for factories. Or run MeshNode software on the many supported router boards you can source from any OEM globally.
Browse the hardwareThree nodes for up to 250m². Pre-paired. Plug in, online in 60 seconds. Most homes pick this.
Six nodes for up to 500m². Multi-floor coverage, garden, terrace. ISP-shippable.
Ceiling-mount, PoE, 4x4 MU-MIMO. For offices, hotels, retail. Joins the mesh by default.
Industrial temperature range, dual-radio WiFi 6. For factories, outdoor sites, harsh environments.
Three lines to a mesh
Mesh that survives carrier-grade NAT. Hardware that ships under your brand. A control plane you can run yourself. Talk to us about a 30-day pilot — single tenant, real traffic, your existing CPE.