Invisible origins
Public scanners should not find your servers.
Rizoma keeps origin infrastructure on private addresses and exposes only governed service paths through controlled ingress.
- No exposed admin ports
- Private service identity
Rizoma unifies secure networking, hosting, CMS, storage, Git, identity, edge routing, and operations into one private mesh core. No public exposure. No vendor zoo. Full operator control.
Private-origin architecture
Mesh is the private fabric, but the product is the ecosystem built on it: hosting, CMS, storage, Git, identity, edge routing, and operations — all sharing one security model.
Invisible origins
Rizoma keeps origin infrastructure on private addresses and exposes only governed service paths through controlled ingress.
Governed public ingress
Websites, APIs, panels, Git, and storage can be served through controlled entry points without making every server publicly reachable.
Post-quantum by design
Encryption, identity, and key policy are architectural defaults across the platform using hybrid X25519 + ML-KEM-768 and AES-GCM.
Product ecosystem
Each product answers the same question: how do we deliver useful digital services while keeping the real infrastructure private, sovereign, and operable?
Rizoma Mesh
Private network core
Agents, MeshCA, ACLs, Magic DNS, relays, ingress, and telemetry.
Webpanel
Mesh hosting control plane
Workloads, domains, mail, files, databases, and operations.
Rizoma CMS
Mesh-protected websites
WordPress-style site building with publishing gates and secure mesh hosting.
Rizoma Router
Linux security gateway
WAN/LAN, firewall, NAT, DNS, VPN, IDS, rollback, and diagnostics.
Rizoma Git
Self-hosted Git forge
Repos, PRs, issues, CI custody, packages, releases, and audit evidence.
S3 Object Storage
Mesh-only buckets
S3-compatible buckets and objects inside the private mesh network.
Password Manager
Passwords + OTP
Unified password and 2FA management with mesh-synced credentials.
Security architecture
Rizoma Mesh brings WAF, mesh firewall, antivirus posture, ACL policy, identity, and traffic control into one operating layer for critical infrastructure. Teams do not stitch security together from a vendor zoo.
View security model ->Built-in protection layers
WAF signals, antivirus posture, identity checks, ingress control, and telemetry are part of the mesh operating model, not separate appliances bolted on after deployment.
Mesh firewall and ACL policy
Teams define who can reach which service, from which node, over which path. ACLs and mesh firewall rules turn network access into explicit policy.
Fewer vendors, lower cost
One security environment replaces overlapping VPN, firewall, WAF, endpoint protection, and access-control tools, reducing licensing and integration overhead.
Architecture review
Bring your websites, APIs, admin panels, storage, Git, and edge requirements. We will identify what can move behind the private fabric first.
7
Product surfaces
Mesh, Webpanel, CMS, Router, Git, S3 storage, and Passmanager as one operating model.
0
Required public origins
Designed so servers do not need direct public reachability to serve public workloads.